← all papers · overview

ISFL-AE: Insider-Specific Feature Learning Autoencoder for Lightweight Insider Threat Detection

Abstract

Malicious insiders who possess system access and security expertise are notoriously difficult to detect and can inflict severe financial damage. While recent advances in deep learning have demonstrated impressive accuracy in detecting insider threats, these models often assume the presence of well-defined or previously known anomalies. In practical organizational environments, however, threats may manifest as novel, subtle, or context-dependent behaviors that are not captured by existing patterns. Detecting such anomalies necessitates the extraction and analysis of rich behavioral features from large-scale insider activity data—an approach that, while effective, often leads to increased model complexity and computational burden. This, in turn, impedes real-time responsiveness and operational viability, potentially resulting in delayed threat mitigation and financial losses. Therefore, there is a pressing need for lightweight yet robust insider threat detection frameworks that can ensure timely and efficient deployment without compromising detection performance. To address this challenge, this paper proposes the Insider-Specific Feature Learning Autoencoder (ISFL-AE), a model designed to achieve high detection accuracy and fast processing speed. Unlike traditional reconstruction-based anomaly detection models—which use a single set of model parameters to reconstruct normal behavior for all insiders regardless of their role, authority level, or other attributes—ISFL-AE tailors its feature learning to insider-specific characteristics. ISFL-AE operates with the same number of parameters as a conventional autoencoder (AE), maintaining comparable processing speed while significantly improving detection performance. We evaluated ISFL-AE using the CERT r4.2 and r6.2 datasets. The results show that, while processing data at the same speed as a standard AE, ISFL-AE delivered markedly higher detection accuracy. Furthermore, it outperformed other machine learning models in detection accuracy and processing speed. Furthermore, our empirical results demonstrate that integrating insider-specific feature learning into autoencoder-based deep learning architectures significantly enhances anomaly detection performance, all while preserving real-time processing efficiency.

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).