Insider Threat Detection
Insider threat detection aims to identify malicious activities by authorized personnel within organizations, leveraging machine learning to analyze user behavior and system logs. Current research focuses on developing robust and efficient detection models, including federated learning approaches to address data privacy and distribution challenges, multi-agent systems incorporating large language models for improved reasoning and explanation, and real-time detection methods operating at the level of individual user activities. These advancements are crucial for enhancing cybersecurity, mitigating the significant risks posed by insider threats, and improving the accuracy and timeliness of threat identification.
Papers
December 18, 2024
November 4, 2024
September 19, 2024
August 12, 2024
March 14, 2024
November 23, 2022
March 8, 2022