Papers › Attention to Patterns is all you need for Insider threat detection
Attention to Patterns is all you need for Insider threat detection
Priya Tiwary, Akshayraj Madhubalan, Amit Gautam, Raj Darji
Insider threats pose a significant and often underestimated risk to organizations. Traditional anomaly detection methods relying on simplistic patterns and lacking temporal awareness struggle to capture the nuances of user behavior, leading to missed detections and false alarms. This research proposes a novel approach that leverages the power of deep learning models to capture complex, hierarchical patterns in user behavior, enabling the early detection of malicious insider activity. The proposed approach introduces two distinct architectures: Time-Distributed Deep Learning Architecture (TD-CNN-LSTM) and Contextually Aware Attention-Based Architecture (TD-CNN-Attention). These architectures combine CNNs with LSTMs or attention mechanisms to extract both spatial and temporal features from user access data, capturing intricate patterns across different timescales. Additionally, they incorporate user information such as psychometrics and organizational data, providing a holistic view of user behavior and context. Through extensive evaluation, both architectures demonstrate significant improvements in accuracy and F1 score compared to existing insider threat detection solutions. The attention-based model in particular emerges as a state-of-the-art approach with superior performance capabilities. This research marks a significant step forward in the field of insider threat detection, paving the way for organizations to better secure their critical assets and safeguard their future in the ever-changing cybersecurity landscape.
Code
No code repository is listed for this paper in the archive or in Syntology's graph.
Code Syntology ran Syntology
Not run by Syntology. Nothing on this page verifies that the listed code works.
Tasks
Results from the paper archive 2025-07-28
| Task | Dataset | Model | Metric | Value | Rank at snapshot | Leaderboard | Report |
|---|---|---|---|---|---|---|---|
| Classification | Insider Threat Test Dataset | TD-CNN- Attention | F1 score | 99.71 | #1 of 1 | Archive leaderboard | report |
Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.
Methods
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections