GMFITD: Graph Meta-Learning for Effective Few-Shot Insider Threat Detection

被引:1
作者
Li, Ximing [1 ]
Li, Linghui [1 ]
Li, Xiaoyong [1 ]
Cai, Binsi [1 ]
Jia, Jia [1 ]
Gao, Yali [1 ]
Yu, Shui [2 ]
机构
[1] Beijing Univ Posts & Telecommun, Key Lab Trustworthy Distributed Comp & Serv, Minist Educ, Beijing 100876, Peoples R China
[2] Univ Technol Sydney, Sch Comp Sci, Ultimo, NSW 2007, Australia
基金
中国国家自然科学基金;
关键词
Threat assessment; Metalearning; Few shot learning; Image edge detection; Task analysis; Feature extraction; Data models; Insider threat; graph neural network; meta-learning; NETWORKS;
D O I
10.1109/TIFS.2024.3430106
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Insider threats represent a significant challenge in both corporate and governmental sectors. Most existing supervised learning based detection methods that rely on transforming user behavior into sequential data do not fully utilize structural information and require extensive labeled data. This reliance poses a challenge due to the scarcity of labeled data in real-world scenarios, leading to a few-shot learning situation. To address these limitations, we propose a novel Graph modularized-based Meta-learning Framework for Insider Threat Detection, named GMFITD. Specifically, GMFITD utilizes a structural reconstruction mechanism that combines a graph-based autoencoder with an attention mechanism to explore structural information and infer potential relationships between users. Additionally, we employ a graph prototype construction method coupling episodic meta-learning principle (MAML) to compute representative embeddings for few-shot learning scenarios. By leveraging MAML, the proposed method can capture prior knowledge of insider threat classification by training on similar few-shot learning tasks with few labeled samples. We further enhance the resilience of GMFITD to adversarial attacks through an edge importance estimation mechanism, which assigns higher weights to relevant edges. Extensive experiments demonstrate that our proposed GMFITD outperforms state-of-the-art methods in insider threat detection, achieving higher accuracy with fewer labeled samples and resisting adversarial attacks.
引用
收藏
页码:7161 / 7175
页数:15
相关论文
共 57 条
  • [21] Anomaly Detection with Graph Convolutional Networks for Insider Threat and Fraud Detection
    Jiang, Jianguo
    Chen, Jiuming
    Gu, Tianbo
    Choo, Kim-Kwang Raymond
    Liu, Chao
    Yu, Min
    Huang, Weiqing
    Mohapatra, Prasant
    [J]. MILCOM 2019 - 2019 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2019,
  • [22] Kipf T.N., 2017, CoRR abs/1609.02907, DOI DOI 10.48550/ARXIV.1609.02907
  • [23] VEWS: A Wikipedia Vandal Early Warning System
    Kumar, Srijan
    Spezzano, Francesca
    Subrahmanian, V. S.
    [J]. KDD'15: PROCEEDINGS OF THE 21ST ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2015, : 607 - 616
  • [24] Analyzing Data Granularity Levels for Insider Threat Detection Using Machine Learning
    Le, Duc C.
    Zincir-Heywood, Nur
    Heywood, Malcolm I.
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2020, 17 (01): : 30 - 44
  • [25] Log2vec: A Heterogeneous Graph Embedding Based Approach for Detecting Cyber Threats within Enterprise
    Liu, Fucheng
    Wen, Yu
    Zhang, Dongxue
    Jiang, Xihe
    Xing, Xinyu
    Meng, Dan
    [J]. PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'19), 2019, : 1777 - 1794
  • [26] Liu L, 2019, ADV NEUR IN, V32
  • [27] Liu XQ, 2019, ADV NEUR IN, V32
  • [28] Few-shot Node Classification on Attributed Networks with Graph Meta-learning
    Liu, Yonghao
    Li, Mengyu
    Li, Ximing
    Giunchiglia, Fausto
    Feng, Xiaoyue
    Guan, Renchu
    [J]. PROCEEDINGS OF THE 45TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '22), 2022, : 471 - 481
  • [29] Towards Locality-Aware Meta-Learning of Tail Node Embeddings on Networks
    Liu, Zemin
    Zhang, Wentao
    Fang, Yuan
    Zhang, Xinming
    Hoi, Steven C. H.
    [J]. CIKM '20: PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON INFORMATION & KNOWLEDGE MANAGEMENT, 2020, : 975 - 984
  • [30] Meta Learning With Graph Attention Networks for Low-Data Drug Discovery
    Lv, Qiujie
    Chen, Guanxing
    Yang, Ziduo
    Zhong, Weihe
    Chen, Calvin Yu-Chian
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (08) : 11218 - 11230