• Home
  • Search
  • Robust Anomaly-Based Insider Threat Detection Using Graph Neural Network
  • Cite Icon34
  • https://doi.org/10.1109/tnsm.2022.3222635Copy DOI Icon

Robust Anomaly-Based Insider Threat Detection Using Graph Neural Network

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Misuse or malicious access to critical assets of information systems by insiders usually causes significant loss to organizations. The issue of insider threat detection for information systems has received many researchers’ attention in both security and data mining fields, and a lot of related research results were presented. However, there are still many challenges in capturing the behavior difference between malicious insiders and normal users accurately, such as lack of labeled insider threats, the subtle and adaptive nature of insider threats, complexity, heterogeneity, sparsity of the underlying data, etc. To detect insider threats with large and complex audit data, a Multi-Edge Weight Relational Graph Neural Network method (MEWRGNN) for robust anomaly detection is proposed in this paper. Unlike most existing approaches, the MEWRGNN adopts several graph neural networks to capture the contextual relationship of user behaviors over a period of time, which is a critical factor for achieving accurate anomaly identification. The MEWRGNN achieves a certain degree of interpretability through ranking the contribution of different edge-representation features. Evaluation experimental results demonstrate that the MEWRGNN can learn a model from limited sample data sets, and achieve quick and accurate insider threat detection performance. In addition, other feature ranking results allow providing security analysts with understandable insights for investigating the detected insider threats.

Similar Papers
  • Conference Article
  • Citations2

Personalized User Profiles-based Insider Threat Detection for Distributed File System

  • Dec 01, 2022
  • Wu Xin +5
  • Research Article
  • Citations77

A new intelligent multilayer framework for insider threat detection

  • Nov 22, 2021
  • Computers and Electrical Engineering
  • Mohammed Nasser Al-Mhiqani +6
  • Preprint Article

Leveraging Graph Neural Networks for Enhanced Insider Threat Detection in Enterprise Systems

  • Jun 04, 2025
  • Hemanth Ravipati
  • Conference Article
  • Citations10

GRU and Multi-autoencoder based Insider Threat Detection for Cyber Security

  • Oct 01, 2021
  • Fanzhi Meng +5
  • Research Article
  • Citations124

Anomaly Detection for Insider Threats Using Unsupervised Ensembles

  • Apr 09, 2021
  • IEEE Transactions on Network and Service Management
  • Duc C Le +1
  • Research Article
  • Citations26

An efficient pattern-based approach for insider threat classification using the image-based feature representation

  • Jan 20, 2023
  • Journal of Information Security and Applications
  • Krunal Randive +2
  • Research Article
  • Citations22

Deep Learning and Dempster-Shafer Theory Based Insider Threat Detection

  • Oct 09, 2020
  • Mobile Networks and Applications
  • Zhihong Tian +6
  • Research Article
  • Citations34

Insider threat detection in cyber-physical systems: a systematic literature review

  • Jul 26, 2024
  • Computers and Electrical Engineering
  • Mohammed Nasser Al-Mhiqani +5
  • Research Article

Predictive Analytics for Insider Threats Using Multimodal Data (Log + Behavioural + Physical Security)

  • Nov 21, 2025
  • American Journal of Interdisciplinary Research and Innovation
  • Kh Said Al Mamun +6
  • Research Article

Game Theory for Insider Threat Detection and Mitigation: A Review

  • Oct 01, 2024
  • International Journal of Advances in Engineering and Management
  • Olajide O Ogunbodede +3
  • PDF
  • Research Article
  • Citations117

Impact and Key Challenges of Insider Threats on Organizations and Critical Businesses

  • Sep 07, 2020
  • Electronics
  • Neetesh Saxena +5
  • Research Article
  • Citations4

Insider threat mitigation through human intelligence and counterintelligence: A case study in the shipping industry

  • Mar 02, 2024
  • Defense and Security Studies
  • Anastasios-Nikolaos Kanellopoulos
  • Book Chapter

Hybrid AI Architectures Combining ML and DL for Insider Threat Detection S.

  • Nov 18, 2025
  • S Sivakumar +2
  • Book Chapter
  • Citations1

Detection of Malicious Insider in Cloud Environment based on behavior Analysis

  • Apr 12, 2022
  • G Padmavathi +2
  • Conference Article
  • Citations16

Exploring Adversarial Properties of Insider Threat Detection

  • Jun 01, 2020
  • Duc C Le +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.