Organizations/academic

Zhongguancun Laboratory

2 records2 defense
Sep 30, 2026
APTInvestBench finds autonomous investigators lose citation support when telemetry changes
DefenseBenchmarkZhongguancun Laboratory

Zhongguancun Laboratory researchers introduce APTInvestBench, built from report-informed attack reconstructions under varied log-collection conditions. In their ten-scenario comparison of eleven models, agents acquire sufficient evidence for 44.3% of recoverable attack actions on average, but their formal citations support 25.0%; similar aggregate scores conceal losses in which actions remain supported. These are controlled benchmark investigations, not measurements of deployed SOC performance.

Sep 26, 2026
CyberClear benchmarks LLM agents on reconstructing APT attack chains from long defender logs
DefenseBenchmarkHong Kong Polytechnic University, OpenClaw, Southeast University

Chen and colleagues (arXiv v1, under review for ICLR 2027) introduce CyberClear, 450 instances built from public APT log datasets in which an agent must turn long defender logs, without prior attack clues, into a provenance graph with ATT&CK-mapped steps. References were generated by an LLM and passed automatic verification and expert review; scoring compares graph code with five LLM-judge dimensions. They also propose CyberProvenance, a multi-agent harness that reproduces predicted attack steps in isolated lab environments and refines the graph, and report it best on most semantic metrics while the highest Strict score remains 0.6477 out of 1.