[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-438420-105":59,"doc-detail-438420-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","xapt-explainable-anomaly-driven-prediction-of-threat-stages-in-apt-campaigns","XAPT - Explainable Anomaly-Driven Prediction of Threat Stages in APT Campaigns -","","Advanced Persistent Threats (APTs) are long-lived, targeted cyberattacks that progress through multiple stages and exhibit strong stealth and intent. To enable accurate and interpretable stage-level prediction, XAPT introduces an anomaly-driven, explainable framework centered on calibrated anomaly scoring, Bayesian Network multiclass inference, and SHAP-based feature attribution. Experiments on two public datasets demonstrate high stage-level detection accuracy together with actionable explanations for operational analysis and interpretability of kill-chain progression.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/xapt-explainable-anomaly-driven-prediction-of-threat-stages-in-apt-campaigns/438420/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/xapt-explainable-anomaly-driven-prediction-of-threat-stages-in-apt-campaigns/438420.png","ImageObject",300,407,{"name":92,"@type":93},"pixelkiddo","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-30","2026-09-29",true,{"@type":102,"interactionType":103,"userInteractionCount":8},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"What is XAPT designed to do in APT campaign analysis?","Question",{"text":112,"@type":113},"XAPT focuses on interpretable, stage-level prediction for advanced persistent threats by inferring progress across cyber-kill-chain stages using anomaly-driven evidence.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"How does XAPT turn anomaly information into stage inference features?",{"text":117,"@type":113},"XAPT derives PCA-based reconstruction errors and converts them into calibrated probabilistic anomaly scores, which quantify event abnormality in a principled way.",{"name":119,"@type":110,"acceptedAnswer":120},"How are predictions made interpretable to support analysts?",{"text":121,"@type":113},"XAPT uses SHAP-based feature attribution to explain how anomaly scores and other features contribute to classification decisions, aligning outcomes with analysts’ interpretive needs.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},438420,1790766897,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":8,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":144,"read_time":145},962090883892,"https://ap-avatar.wpscdn.com/avatar/e00115db34f3e0f11b?x-image-process=image/resize,m_fixed,w_180,h_180&k=1790152879550218658","Author Manuscr ipt Author Manuscr ipt Author Manuscr ipt Author Manuscript  \n\n| | HHS Public Access\u003Cbr>Author manuscript\u003Cbr>IEEE Access. Author manuscript; available in PMC 2026 January 06. |\n| --- | --- |\n\nPublished in final edited form as:  \nIEEE Access. 2025 ; 13: 199737–199756. doi:10 . 1109/access.2025.3636501.  \nXAPT: Explainable Anomaly-Driven Prediction of Threat Stages in APT Campaigns  \nWEI LU 1 [Senior Member, IEEE], ISSA TRAORÉ2 [Senior Member, IEEE], ISAAC WOUNGANG3 [Senior Member, IEEE], ERIC BROWN4 [Member, IEEE], MARCELO LUIZ BROCARDO5 [Senior Member, IEEE], QIAOYAN YU6 [Senior Member, IEEE], ORNELLA LUCRESSE SOH2 [Member, IEEE]  \n1 Department of Computer Science, Keene State College, Keene, NH 03431, USA  \n2 Department of Electrical and Computer Engineering, University of Victoria, Victoria, BC V8P 5C2, Canada  \n3 Department of Computer Science, Toronto Metropolitan University, Toronto, ON M5B 2K3, Canada  \n4 Department of Computer Science, Dartmouth College, Hanover, NH 03755, USA  \n5Santa Catarina State University (UDESC), Florianópolis, Santa Catarina 88035-901, Brazil  \n6 Department of Electrical and Computer Engineering, University of New Hampshire, Durham, NH 03824, USA  \nAbstract  \nAdvanced Persistent Threats (APTs) are long-lived, targeted cyberattacks that progress through multiple stages, characterized by strong stealth and intent. To achieve accurate and interpretable stage-level prediction, we propose XAPT, an eXplainable, anomaly-driven framework for APT campaign analysis. XAPT is centered on three key innovations. First, we derive PCA-based reconstruction errors and transform them into calibrated probabilistic anomaly scores, enabling principled quantification of the event abnormality. Second, these calibrated scores are incorporated into a Bayesian Network-based multiclass classifier for cyber-kill-chain stage inference, capturing uncertainty and inter-feature dependencies. Third, SHAP-based feature attribution reveals how anomaly scores and other features contribute to classification outcomes, offering transparent and analytically friendly explanations. Evaluation of two public datasets shows that XAPT achieves high stage-level detection accuracy while producing actionable feature-level interpretations that support operational analysis. By unifying calibrated anomaly scoring, Bayesian inference, and SHAP explanation, XAPT offers a comprehensive and interpretable solution for advanced threat detection.  \nThis work is licensed under a Creative Commons Attribution 4.0 License. For more information, see [https://creativecommons.org/](https://creativecommons.org/)[ ](https://creativecommons.org/)[licenses/by/4.0/](licenses/by/4.0/)  \nCorresponding author: Wei Lu ([wlu@usnh.edu](wlu@usnh.edu)).  \nThe associate editor coordinating the review of this manuscript and approving it for publication was Jiawei Yang.  \nAuthor Manuscr ipt Author Manuscr ipt Author Manuscr ipt Author Manuscript  \nLU et al. Page 2  \nINDEX TERMS  \nAdvanced persistent threats; anomaly detection; score calibration; Bayesian networks; explainable AI  \nI. INTRODUCTION  \nAdvanced Persistent Threats (APTs) are highly targeted long-term cyberattacks orchestrated by well-funded adversaries with strategic objectives such as sabotage or data exfiltration  \n[1], [2], [3] . Their persistence, stealth, and adaptability allow them to unfold as a series of seemingly benign events that, when considered in isolation, appear harmless but collectively form a damaging campaign. Traditional Intrusion Detection Systems (IDS) and Intrusion Response Systems (IRS), optimized for short-term and opportunistic attacks, often fail against APTs because they rely on homogeneous data sources and cannot capture distributed or time-delayed stages. Consequently, accurate attribution of these stages becomes essential for a timely response, containment, and forensic investigation. However, the long-term, low-and-slow traffic patterns and polymorphic toolchains used ","cbCaiiwkcF4O8p2L","https://ap.wps.com/l/cbCaiiwkcF4O8p2L","pdf",2624316,65,"English","# Introduction\n## Challenges in APT stage-level prediction\n## Related work and limitations\n## Proposed XAPT framework","[{\"question\":\"What is XAPT designed to do in APT campaign analysis?\",\"answer\":\"XAPT focuses on interpretable, stage-level prediction for advanced persistent threats by inferring progress across cyber-kill-chain stages using anomaly-driven evidence.\"},{\"question\":\"How does XAPT turn anomaly information into stage inference features?\",\"answer\":\"XAPT derives PCA-based reconstruction errors and converts them into calibrated probabilistic anomaly scores, which quantify event abnormality in a principled way.\"},{\"question\":\"How are predictions made interpretable to support analysts?\",\"answer\":\"XAPT uses SHAP-based feature attribution to explain how anomaly scores and other features contribute to classification decisions, aligning outcomes with analysts’ interpretive needs.\"}]","XAPT - Explainable Anomaly-Driven Prediction of Threat Stages in APT Campaigns - | PDF",1790685327,164]