AI RESEARCH
High-Precision APT Malware Attribution with Out-of-Scope Resilience
arXiv CS.LG
•
ArXi:2606.03523v1 Announce Type: cross Early attribution of Advanced Persistent Threat (APT) activity can help defenders prioritise investigation, select countermeasures, and reduce the impact of an intrusion. Malware provides useful attribution evidence, but automated APT malware attribution remains difficult in practice. Existing approaches are typically trained and evaluated as closed-set classifiers over a limited number of known APT groups. In operational environments, however, classifiers are likely to encounter samples from groups not represented during.