paper-with-me

Papers

Attention to Patterns is all you need for Insider threat detection

2024-10-26 · International Conference on Artificial Intelligence, Metaverse and Cybersecurity (ICAMAC) 2024 10 · Priya Tiwary, Akshayraj Madhubalan, Amit Gautam, Raj Darji

Insider threats pose a significant and often underestimated risk to organizations. Traditional anomaly detection methods relying on simplistic patterns and lacking temporal awareness struggle to capture the nuances of user behavior, leading to missed detections and false alarms. This research proposes a novel approach that leverages the power of deep learning models to capture complex, hierarchical patterns in user behavior, enabling the early detection of malicious insider activity. The proposed approach introduces two distinct architectures: Time-Distributed Deep Learning Architecture (TD-CNN-LSTM) and Contextually Aware Attention-Based Architecture (TD-CNN-Attention). These architectures combine CNNs with LSTMs or attention mechanisms to extract both spatial and temporal features from user access data, capturing intricate patterns across different timescales. Additionally, they incorporate user information such as psychometrics and organizational data, providing a holistic view of user behavior and context. Through extensive evaluation, both architectures demonstrate significant improvements in accuracy and F1 score compared to existing insider threat detection solutions. The attention-based model in particular emerges as a state-of-the-art approach with superior performance capabilities. This research marks a significant step forward in the field of insider threat detection, paving the way for organizations to better secure their critical assets and safeguard their future in the ever-changing cybersecurity landscape.

📄 PDF Abstract BibTeX

Code (0)

등록된 구현이 없습니다.

Tasks

AllAnomaly DetectionClassification

Methods 이 논문이 사용한 방법론

Softmax The Softmax output function transforms a previous layer's output into a vector of probabilities. It is commonly used for multiclass classification. Given an input vector $x$…
Attention 설명 없음
AWARE We propose to theoretically and empirically examine the effect of incorporating weighting schemes into walk-aggregating GNNs. To this end, we propose a simple, interpretable, and…

Similar Papers 제목 키워드 기반

MV-Gate: Insider Threat Detection via Multi-View Behavioral Statistics and Semantic Modeling

2026-05-18 · Kaichuan Kong, Dongjie Liu, Xiaobo Jin, Guanggang Geng arxiv

Insider threats often reveal early anomalies through disruptions in behavioral statistics-such as altered recurrence patterns or short-versus long-term frequency shifts-rather than changes in event semantics. Yet, as the…

Deep Learning for Insider Threat Detection: Review, Challenges and Opportunities

2020-05-25 · Shuhan Yuan, Xintao Wu

Insider threats, as one type of the most challenging threats in cyberspace, usually cause significant loss to organizations. While the problem of insider threat detection has been studied for a long time in both security…

BIG-bench Machine LearningDeep LearningFeature Engineering

An Ethically Grounded LLM-Based Approach to Insider Threat Synthesis and Detection

2025-09-08 · Haywood Gelman, John D. Hastings, David Kenley arxiv

Insider threats are a growing organizational problem due to the complexity of identifying their technical and behavioral elements. A large research body is dedicated to the study of insider threats from technological, ps…

Image-Based Feature Representation for Insider Threat Classification

2019-11-13 · Gayathri R G, Atul Sajjanhar, Yong Xiang

Insiders are the trusted entities in the organization, but poses threat to the with access to sensitive information network and resources. The insider threat detection is a well studied problem in security analytics. Ide…

ClassificationGeneral Classificationimage-classificationImage Classification

FedAT: Federated Adversarial Training for Distributed Insider Threat Detection

2024-09-19 · R G Gayathri, Atul Sajjanhar, Md Palash Uddin, Yong Xiang

Insider threats usually occur from within the workplace, where the attacker is an entity closely associated with the organization. The sequence of actions the entities take on the resources to which they have access righ…

Federated Learning