English

A Generalized Benford Framework for Threat Identification in Counter-Intelligence

Applications 2025-01-22 v1 Probability

Abstract

In this paper, we develop a framework of 'Benford models' for counter-intelligence investigations which analyze frequency data of a suspect's visits to physical locations, online websites, and communication channels. We accomplish this by establishing the Benford measure for continuous & bounded domains, generalizing the accumulated percentage differences between sites in the frequency data with the log-determinant of 'Benford Matrices,' employing an estimator to determine a 'Benford Test Statistic,' and identifying maximal values of that test statistic across all permutations of included sites in our data. This framework is intended to complement outlier analysis models by finding where hidden Benford patterns 'break' in frequency data and telling investigators which sites they should investigate.

Keywords

Cite

@article{arxiv.2501.10460,
  title  = {A Generalized Benford Framework for Threat Identification in Counter-Intelligence},
  author = {Timothy Tarter},
  journal= {arXiv preprint arXiv:2501.10460},
  year   = {2025}
}

Comments

9 pages, 5 figures

R2 v1 2026-06-28T21:09:44.652Z