<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume></Volume>
				<Issue>Articles in Press</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>03</Month>
					<Day>26</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Lateral Movement Attack Detection using Variational Autoencoders</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage></FirstPage>
			<LastPage></LastPage>
			<ELocationID EIdType="pii">242099</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2026.242099</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Mostafa</FirstName>
					<LastName>Shabani</LastName>

						<AffiliationInfo>
						<Affiliation>Department of Industrial Engineering, Iran University of Science and Technology, Tehran, Iran.</Affiliation>
						</AffiliationInfo>

						<AffiliationInfo>
						<Affiliation>ICT Security Faculty, ICT Research Institute (ITRC), Tehran, Iran.</Affiliation>
						</AffiliationInfo>

</Author>
<Author>
					<FirstName>Tala</FirstName>
					<LastName>Tafazoli</LastName>
<Affiliation>ICT Security Faculty, ICT Research Institute (ITRC), Tehran, Iran.</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
		<Abstract>Lateral movement, a sophisticated cyberattack strategy, enables adversaries to stealthily infiltrate networks following an initial breach. Detecting such maneuvers is exceptionally challenging, as they are designed to seamlessly blend with legitimate system operations and network traffic, rendering traditional signature-based defenses ineffective. Supervised machine learning approaches, while promising, are constrained by their dependence on pre-labeled datasets of known attack patterns. To overcome these limitations, this study introduces a novel hybrid deep learning framework that integrates a Variational Autoencoder (VAE) for robust feature extraction, coupled with a supervised classifier to identify lateral movement. Through meticulous feature engineering on the LMD dataset, the VAE is trained exclusively on normative system and network behavior, constructing a probabilistic representation of legitimate activity. Anomalies, detected via reconstruction error, signal potential malicious intrusions. Empirical evaluation demonstrates the framework’s superior performance, achieving a detection time of 00:00:02:54 and an AUC of 99.6983%, reflecting exceptional class separation and computational efficiency. This hybrid architecture delivers a scalable, high-accuracy solution, establishing the VAE as a pivotal tool for combating advanced persistent threats with unparalleled precision and operational viability. </Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Lateral Movement Attack</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Variational Auto Encoder</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Hybrid Learning</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Anomaly Detection</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_242099_008719d1f4782b1073152f781ed5e64f.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
