PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 11, 2026Cybersecurity2 citationsOpen Access

FusionITD: enhanced cross-modal insider threat perception framework via behavior-semantic fusion

LYLu YuanXLXiaohu LiuHHHao Hu

Key Points

  • The aim is to improve insider threat detection by integrating behavioral and semantic features for more precise anomaly detection.
  • Developed a cross-modal framework that combines behavioral characteristics and semantic information.
  • Segmented and aggregated behavior data into user behavior graphs based on temporal characteristics.
  • Utilized a Graph Neural Network (GNN) to capture temporal behavioral features with an advanced loss function for data imbalance.
  • Created a semantic analysis algorithm employing cosine similarity for behavior matching and ranking.
  • Integrated outputs from behavioral and semantic analyses using an adaptive logistic regression weighting mechanism.
  • Achieved a 5% increase in AUC compared to existing methods.
  • Demonstrated a higher True Positive Rate (TPR) in detecting threats.
  • Showed a reduction in false positive rates, enhancing overall detection accuracy.

Abstract

Abstract In recent years, insider threat incidents have occurred with increasing frequency, leading to severe data breaches and substantial economic losses. Most existing insider threat detection methods rely primarily on single-modal features, such as system logs and registry data, while failing to fully exploit the rich semantic information embedded in instant messaging and email content of insider users. To address the above issues, we propose FusionITD, a cross-modal insider threat perception enhancement framework based on the fusion of behavioral and semantic features. This framework combines users’ temporal behavioral characteristics such as file operations and login device patterns with the semantic information derived from web browsing and email content. By modeling user behavior baselines from multiple dimensions, FusionITD enables more accurate anomaly detection when deviations from the baseline occur. Firstly, based on the temporal distribution of user behaviors, the behavior data is segmented and aggregated according to the time window to form a user behavior graph. We propose WR-GNN based on graph representation learning to capture temporal behavioral features, and introduce the Focal MSE loss function to address the data imbalance problem caused by sparse abnormal behavior data. Secondly, we propose a retrieval-augmented generation-based semantic analysis algorithm. We use cosine similarity to perform semantic matching and ranking between behavioral contents and historical behaviors. We extract features such as emotion, intention, and focus to achieve fine-grained anomaly detection for user behavior. Finally, we designed an adaptive weighting mechanism based on logistic regression to dynamically integrate the outputs of the previous two parts, enhancing the generalization ability for different threat scenarios. Experimental results conducted on the CERT datasets show that FusionITD outperforms other methods by achieving a 5% increase in AUC, a higher TPR, and a lower false positive rate.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Yuan et al. (2026) studied this question.

synapsesocial.com/papers/698c1c8e267fb587c655f1f3https://doi.org/10.1186/s42400-026-00555-w
Ask AI
Helpful
Bookmark
Share
View Full Paper