English
Related papers

Related papers: LAC : LSTM AUTOENCODER with Community for Insider …

200 papers

We describe the motivation and design for esINSIDER, an automated tool that detects potential persistent and insider threats in a network. esINSIDER aggregates clues from log data, over extended time periods, and proposes a small number of…

Cryptography and Security · Computer Science 2019-04-09 M. Arthur Munson , Jason Kichen , Dustin Hillard , Ashley Fidler , Peiter Zatko

Energy communities consist of decentralized energy production, storage, consumption, and distribution and are gaining traction in modern power systems. However, these communities may increase the vulnerability of the grid to cyber threats.…

Cryptography and Security · Computer Science 2025-02-27 Zeeshan Afzal , Giovanni Gaggero , Mikael Asplund

An insider is a team member who covertly deviates from the team's optimal collaborative strategy to pursue a private objective while still appearing cooperative. Such an insider may initially behave cooperatively but later switch to selfish…

Optimization and Control · Mathematics 2026-04-01 Gehui Xu , Kaiwen Chen , Zhong-Ping Jiang , Thomas Parisini , Andreas A. Malikopoulos

Insider threat is one of the most pressing threats in the field of information security as it leads to huge financial losses by the companies. Most of the proposed methods for detecting this threat require expensive and invasive equipment,…

Cryptography and Security · Computer Science 2020-05-07 Azamat Sultanov , Konstantin Kogos

Log-based insider threat detection (ITD) detects malicious user activities by auditing log entries. Recently, large language models (LLMs) with strong common sense knowledge have emerged in the domain of ITD. Nevertheless, diverse activity…

Cryptography and Security · Computer Science 2024-08-20 Chengyu Song , Linru Ma , Jianming Zheng , Jinzhi Liao , Hongyu Kuang , Lin Yang

Insider threat detection is difficult because malicious behavior is rare, irregular, and buried in long periods of inactivity. In enterprise audit data, most windows contain little activity, while attacks appear intermittently and range…

Cryptography and Security · Computer Science 2026-05-01 Hayden Beadles , Jericho Cain

Automated intrusion-style workflows require LLM agents to reason over partial observations, tool outputs, and executable artifacts under bounded budgets. A single LLM instance often compresses evidence extraction, planning, execution, and…

Cryptography and Security · Computer Science 2026-05-12 Minfeng Qi , Tianqing Zhu , Zijie Xu , Congcong Zhu , Qin Wang , Wanlei Zhou

Insider threat detection aims to identify malicious user behavior by analyzing logs that record user interactions. Due to the lack of fine-grained behavior-level annotations, detecting specific behavior-level anomalies within user behavior…

Cryptography and Security · Computer Science 2025-08-18 Yang Wang , Yaxin Zhao , Xinyu Jiao , Sihan Xu , Xiangrui Cai , Ying Zhang , Xiaojie Yuan

User and Entity Behaviour Analytics (UEBA) is a broad branch of data analytics that attempts to build a normal behavioural profile in order to detect anomalous events. Among the techniques used to detect anomalies, Deep Autoencoders…

Cryptography and Security · Computer Science 2025-10-31 Jose Fuentes , Ines Ortega-Fernandez , Nora M. Villanueva , Marta Sestelo

The widespread adoption of Large Language Models (LLMs) in critical applications has introduced severe reliability and security risks, as LLMs remain vulnerable to notorious threats such as hallucinations, jailbreak attacks, and backdoor…

Cryptography and Security · Computer Science 2026-04-07 Shide Zhou , Kailong Wang , Ling Shi , Haoyu Wang

Insider threats are a growing concern for organizations due to the amount of damage that their members can inflict by combining their privileged access and domain knowledge. Nonetheless, the detection of such threats is challenging,…

Cryptography and Security · Computer Science 2022-11-29 Simon Bertrand , Nadia Tawbi , Josée Desharnais

This paper addresses the problem of detecting possible intruders in a group of autonomous robots, which coexist in a shared environment and interact with each other according to a set of "social behaviors", or common rules. Such rules…

Robotics · Computer Science 2011-01-13 Adriano Fagiolini , Gianluca Dini , Antonio Bicchi

An increasing number of sensors on mobile, Internet of things (IoT), and wearable devices generate time-series measurements of physical activities. Though access to the sensory data is critical to the success of many beneficial applications…

Machine Learning · Computer Science 2018-06-13 Mohammad Malekzadeh , Richard G. Clegg , Hamed Haddadi

We study behavioral self-awareness -- an LLM's ability to articulate its behaviors without requiring in-context examples. We finetune LLMs on datasets that exhibit particular behaviors, such as (a) making high-risk economic decisions, and…

Computation and Language · Computer Science 2025-01-22 Jan Betley , Xuchan Bao , Martín Soto , Anna Sztyber-Betley , James Chua , Owain Evans

Insider threats are a particularly tricky cybersecurity issue, especially in zero-trust architectures (ZTA) where implicit trust is removed. Although the rule of thumb is never trust, always verify, attackers can still use legitimate…

Cryptography and Security · Computer Science 2026-01-13 Gaurav Sarraf

Intrusion detection has become one of the most critical tasks in a wireless network to prevent service outages that can take long to fix. The sheer variety of anomalous events necessitates adopting cognitive anomaly detection methods…

Signal Processing · Electrical Eng. & Systems 2018-03-19 Nistha Tandiya , Ahmad Jauhar , Vuk Marojevic , Jeffrey H. Reed

Most enterprise applications use logging as a mechanism to diagnose anomalies, which could help with reducing system downtime. Anomaly detection using software execution logs has been explored in several prior studies, using both classical…

Machine Learning · Computer Science 2023-11-01 Nadun Wijesinghe , Hadi Hemmati

Humans are capable of strategically deceptive behavior: behaving helpfully in most situations, but then behaving very differently in order to pursue alternative objectives when given the opportunity. If an AI system learned such a deceptive…

Insider threats are one of the most damaging risk factors for the IT systems and infrastructure of a company or an organization; identification of insider threats has prompted the interest of the world academic research community, with…

Cryptography and Security · Computer Science 2021-09-07 Vasileios Koutsouvelis , Stavros Shiaeles , Bogdan Ghita , Gueltoum Bendiab

Anomalies refer to data points or events that deviate from normal and homogeneous events, which can include fraudulent activities, network infiltrations, equipment malfunctions, process changes, or other significant but infrequent events.…

Machine Learning · Computer Science 2023-03-20 Ahmed Shoyeb Raihan , Imtiaz Ahmed