Analysis of an organization's computer network activity is a key component of early detection and mitigation of insider threat, a growing concern for many organizations. Raw system logs are a prototypical example of streaming data that can quickly scale beyond the cognitive power of a human analyst. As a prospective fi…
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
ADSAGE detects anomalies in graph edge sequences for insider threat detection.
Insider threat detection is getting an increased concern from academia, industry, and governments due to the growing number of malicious insider incidents. The existing approaches proposed for detecting insider threats still have a common shortcoming, which is the high number of false alarms (false positives). The chal…
Better methods to detect insider threats need new anticipatory analytics to capture risky behavior prior to losing data. In search of the best overall classifier, this work empirically scores 88 machine learning algorithms in 16 major families. We extract risk features from the large CERT dataset, which blends real net…
Enhanced network threat detection using KG, LLM, and imbalanced learning.
This paper uses deep learning to improve network threat detection in finance.
ACE explains security anomaly detection models through feature contributions.
TinyML models detect RF and cyber threats in spacecraft with low latency.
XGBoost detects unlawful insider trading with high accuracy.
A novel unified Bayesian framework for network detection is developed, under which a detection algorithm is derived based on random walks on graphs. The algorithm detects threat networks using partial observations of their activity, and is proved to be optimum in the Neyman-Pearson sense. The algorithm is defined by a …
We present a new machine learning and text information extraction approach to detection of cyber threat events in Twitter that are novel (previously non-extant) and developing (marked by significance with respect to similarity with a previously detected event). While some existing approaches to event detection measure …
Performance of nuclear threat detection systems based on gamma-ray spectrometry often strongly depends on the ability to identify the part of measured signal that can be attributed to background radiation. We have successfully applied a method based on Principal Component Analysis (PCA) to obtain a compact null-space m…
Preventing organizations from Cyber exploits needs timely intelligence about Cyber vulnerabilities and attacks, referred as threats. Cyber threat intelligence can be extracted from various sources including social media platforms where users publish the threat information in real time. Gathering Cyber threat intelligen…
Network analysis detects insider trading by flagging coordinated trades.
Method detects insider trading using trading data and dimensionality reduction.
Illegal insider trading of stocks is based on releasing non-public information (e.g., new product launch, quarterly financial report, acquisition or merger plan) before the information is made public. Detecting illegal insider trading is difficult due to the complex, nonlinear, and non-stationary nature of the stock ma…
Automates detection of electric devices in 3D x-ray images of luggage.
Insider trading is one of the numerous white collar crimes that can contribute to the instability of the economy. Traditionally, the detection of illegal insider trades has been a human-driven process. In this paper, we collect the insider tradings made available by the US Securities and Exchange Commissions (SEC) thro…
Study uses random forest to detect unlawful insider trading in financial data.
We present an extension of sparse Canonical Correlation Analysis (CCA) designed for finding multiple-to-multiple linear correlations within a single set of variables. Unlike CCA, which finds correlations between two sets of data where the rows are matched exactly but the columns represent separate sets of variables, th…
Study introduces UEBA framework using Deep Autoencoders for anomaly detection.
Scientific fields such as insider-threat detection and highway-safety planning often lack sufficient amounts of time-series data to estimate statistical models for the purpose of scientific discovery. Moreover, the available limited data are quite noisy. This presents a major challenge when estimating time-series model…
Gradient boosting detects insider purchases predicting abnormal returns in microcap stocks.
Two machine learning methods detect insider trading from investor activity data.
This paper proposes a generic classification system designed to detect security threats based on the behavior of malware samples. The system relies on statistical features computed from proxy log fields to train detectors using a database of malware samples. The behavior detectors serve as basic reusable building block…
Study detects unlawful insider trading using SHAP and CF, identifying key features.
Active authentication is the problem of continuously verifying the identity of a person based on behavioral aspects of their interaction with a computing device. In this study, we collect and analyze behavioral biometrics data from 200subjects, each using their personal Android mobile device for a period of at least 30…
Insiders camouflage trading to balance wealth and stealth, avoiding legal penalties.
The use of machine learning and intelligent systems has become an established practice in the realm of malware detection and cyber threat prevention. In an environment characterized by widespread accessibility and big data, the feasibility of malware classification without the use of artificial intelligence-based techn…
Researchers develop method to protect against 'weight poisoning' attacks on pre-trained models.
MALCOM generates fake comments to fool fake news detectors.
GraphShield uses dynamic graph learning to detect and visualize financial risks.
We discuss corks, and introduce new objects which we call plugs. Though plugs are fundamentally different objects, they also detect exotic smooth structures in 4-manifolds like corks. We discuss relation between corks, plugs and rational blow-downs. We show how to detect corks and plugs inside of some exotic manifolds.…
Confidential Guardian prevents model abstention from being used to discriminate.
Deep learning detects APT attacks with high accuracy and low false positives.
Adversarial attacks have always been a serious threat for any data-driven model. In this paper, we explore subspaces of adversarial examples in unitary vector domain, and we propose a novel detector for defending our models trained for environmental sound classification. We measure chordal distance between legitimate a…
Paper introduces privacy-preserving few-shot learning for images.
This paper surveys ML applications in SG for cyberattacks.
Three methods detect informed trading on prediction markets, each focusing on different aspects.
Purveyors of malicious network attacks continue to increase the complexity and the sophistication of their techniques, and their ability to evade detection continues to improve as well. Hence, intrusion detection systems must also evolve to meet these increasingly challenging threats. Machine learning is often used to …
Paper studies autoencoder-based anomaly detectors' robustness to adversarial poisoning attacks.
Study detects and mitigates stealthy DDoS attacks in IoT networks.
This work develops agents to learn generalizable policies for dynamic network environments.
Recent changes to greenhouse gas emission policies are catalyzing the electric vehicle (EV) market making it readily accessible to consumers. While there are challenges that arise with dense deployment of EVs, one of the major future concerns is cyber security threat. In this paper, cyber security threats in the form o…
Malware currently presents a number of serious threats to computer users. Signature-based malware detection methods are limited in detecting new malware samples that are significantly different from known ones. Therefore, machine learning-based methods have been proposed, but there are two challenges these methods face…
RS-Del provides robustness for sequence classifiers against edit distance attacks.
It is well-known that many machine learning models are susceptible to adversarial attacks, in which an attacker evades a classifier by making small perturbations to inputs. This paper discusses how industrial copyright detection tools, which serve a central role on the web, are susceptible to adversarial attacks. We di…
New method improves robustness of OOD detection models.