Papers › Attention to Patterns is all you need for Insider threat detection

Attention to Patterns is all you need for Insider threat detection

26 Oct 2024International Conference on Artificial Intelligence, Metaverse and Cybersecurity (ICAMAC) 2024 10archive 2025-07-28

Priya Tiwary, Akshayraj Madhubalan, Amit Gautam, Raj Darji

Insider threats pose a significant and often underestimated risk to organizations. Traditional anomaly detection methods relying on simplistic patterns and lacking temporal awareness struggle to capture the nuances of user behavior, leading to missed detections and false alarms. This research proposes a novel approach that leverages the power of deep learning models to capture complex, hierarchical patterns in user behavior, enabling the early detection of malicious insider activity. The proposed approach introduces two distinct architectures: Time-Distributed Deep Learning Architecture (TD-CNN-LSTM) and Contextually Aware Attention-Based Architecture (TD-CNN-Attention). These architectures combine CNNs with LSTMs or attention mechanisms to extract both spatial and temporal features from user access data, capturing intricate patterns across different timescales. Additionally, they incorporate user information such as psychometrics and organizational data, providing a holistic view of user behavior and context. Through extensive evaluation, both architectures demonstrate significant improvements in accuracy and F1 score compared to existing insider threat detection solutions. The attention-based model in particular emerges as a state-of-the-art approach with superior performance capabilities. This research marks a significant step forward in the field of insider threat detection, paving the way for organizations to better secure their critical assets and safeguard their future in the ever-changing cybersecurity landscape.

PaperPDF

Code

No code repository is listed for this paper in the archive or in Syntology's graph.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

AllAnomaly DetectionClassification

Results from the paper archive 2025-07-28

TaskDatasetModelMetricValueRank at snapshotLeaderboardReport
Classification Insider Threat Test Dataset TD-CNN- Attention F1 score 99.71 #1 of 1 Archive leaderboard report

Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.

Methods

AWAREAttentionSoftmax

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections