BiTTP: Bidirectional Consistency-Enhanced Framework for Low-Resource APT Tactic and Technique Attribution
Attributing advanced persistent threat (APT) activity to tactics and techniques in the MITRE ATT&CK knowledge base supports threat hunting and incident response, but annotated attack data are scarce. We present BiTTP, a consistency-verified self-training framework for low-resource APT tactic and technique attribution. An annotator labels unlabeled audit-trace subgraphs, and a pseudo-label is retained only when it passes consensus, confidence, and cross-view consistency gates. The last gate compares the encoded input subgraph with the encoded ATT&CK definition of the predicted technique in a bidirectionally aligned space. Bidirectional data generation, dual-view alignment, retrieval-grounded decoding, and a learned attention aggregator support this loop. On a generated benchmark and a controlled-environment audit-trace benchmark derived from TREC, BiTTP reaches a technique F1 of 0.960 and a tactic micro-F1 of 0.939. Under cross-dataset transfer, it maintains a tactic micro-F1 of 0.912. The largest gains occur under severe label scarcity: with 100 seed examples per tactic, BiTTP exceeds the F1 of strong fine-tuning with 300 seeds. Cross-view consistency is also an effective open-set rejection signal for a withheld technique and its semantically adjacent neighbor.
Authors
- Gang Yang (ORCID: https://orcid.org/0000-0002-2732-3622)
- Lin Ni
- Xiang Peng
Institutions
- National University of Defense Technology (CN)
Publication Details
- Journal
- Electronics
- Published
- 2026-10-09
- DOI
- https://doi.org/10.3390/electronics15204601
- Primary Topic
- Network Security and Intrusion Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00