RECAL claims up to 105x fewer false alarms
Authors self-report: on three DARPA E3 datasets, RECAL cuts average false-positive rate 4-105x versus the lowest baseline, with F1 up to 99.99%.
重要度局所的証拠E2 未複製
The unsupervised framework RECAL cut average false-positive rate by roughly 105x, 4x and 41x versus the baseline reporting the lowest FPR on three DARPA E3 datasets, with F1 of 99.99%, 99.93% and 99.99%.
Prior provenance-based intrusion detection (PIDS) methods skewed toward high-frequency relations and were prone to false positives and misses; the authors say relation frequencies in CADETS differ by about 140,000x. RECAL first does relation-balanced masked graph learning, then calibrates reconstruction error against each relation's benign error distribution.
Those figures are self-reported by Lijie Zheng, Mauro Conti and colleagues, without peer review or independent reproduction, and cannot be taken as real-world performance; the preprint was submitted to arXiv on September 15 and updated to v2 on the 17th, as arXiv:2609.16462.