Analysis of an organization's computer network activity is a key component of early detection and mitigation of insider threat, a growing concern for many organizations. Raw system logs are a prototypical example of streaming data that can quickly scale beyond the cognitive power of a human analyst. As a prospective fi…
AnyThreat detects insider threats with minimal false positives.
problem High false positives in detecting insider threats.
method Opportunistic knowledge discovery system with four components: feature engineering, oversampling, class decomposition, and classification.
result Detects 87.5% of malicious insider threats with minimal false positives.
This study improves detection of insider threats using machine learning.
problem Detecting insider threats with anticipation and accuracy.
method Empirically tested 88 machine learning algorithms on CERT dataset, focusing on employee sentiment.
result Random forest algorithms offer the best overall performance, with high accuracy and interpretable rules.
ADSAGE detects anomalies in graph edge sequences for insider threat detection.
problem Detecting insider threats in fine-grained audit logs using graph and text features.
method Anomaly detection at edge level, supporting numeric, categorical, and text attributes.
result ADSAGE detects anomalies in authentications and email communications effectively.
Framework detects cyber threats from Twitter tweets.
problem Time-consuming manual extraction of cyber threat intelligence.
method Novelty detection model trained on CVE data.
result F1-score of 0.643 for classifying cyber threat tweets.
Enhanced network threat detection using KG, LLM, and imbalanced learning.
problem Challenges in network threat detection due to complex attack patterns and limited historical data.
method Integrated framework combining Knowledge Graph, Imbalanced Learning, and Large Language Model.
result Improved threat capture rate by 3%-4% and increased interpretability of risk predictions.
Paper introduces privacy-preserving few-shot learning for images.
problem Privacy risk in few-shot learning systems.
method Discrete embedding vectors and one-way hash functions.
result Achieves computational pan privacy without storing embeddings.
We improve image perturbation defenses using a better-defined Wasserstein threat model.
problem Real-world image perturbations are not pixel-independent, unlike ℓp threat models. method We rectify flaws in the Wasserstein threat model and explore stronger attacks and defenses.
result Current Wasserstein-robust models are ineffective against real-world perturbations.
This paper analyzes privacy threats in federated matrix factorization.
problem Privacy threats in federated matrix factorization models.
method Categorizes federated matrix factorization into three types and analyzes privacy threats.
result This is the first study of privacy threats in federated matrix factorization.
New method defends against unseen threat models using perceptual adversarial training.
problem Lack of precise mathematical characterization of human perception in adversarial attacks.
method Adversarial training against the set of all imperceptible adversarial examples approximated by deep neural networks.
result Perceptual Adversarial Training (PAT) achieves state-of-the-art robustness against multiple diverse adversarial attacks.
This article reviews recent advances in secure distributed and decentralized inference and learning against Byzantine threats.
problem Securing distributed and decentralized inference and learning against malicious attacks.
method Review of recent algorithmic approaches under Byzantine threat model.
result A plethora of robust algorithmic approaches have been developed.
This paper uses deep learning to improve network threat detection in finance.
problem Detecting unknown threats in large-scale data applications.
method Uses deep learning for advanced threat detection.
result Improves protective measures in the financial industry.
Research creates a taxonomy to bridge AI security and regulatory gaps.
problem Disciplinary disconnect between technical and legal teams in AI risk assessment.
method Developed an AI System Threat Vector Taxonomy with 9 domains and 53 sub-threats.
result Empirically validated and aligned with ISO/IEC 42001 controls and NIST AI RMF functions.
New approach detects and ranks novel and developing cyber threats in Twitter.
problem Detecting and ranking novel and developing cyber threats in Twitter streams.
method Unsupervised machine learning approach focusing on novelty and trendiness.
result Ranking of cyber threat events based on importance score using extracted terms.
Scientific fields such as insider-threat detection and highway-safety planning often lack sufficient amounts of time-series data to estimate statistical models for the purpose of scientific discovery. Moreover, the available limited data are quite noisy. This presents a major challenge when estimating time-series model…
Study defenses against data poisoning attacks in online learning.
problem Data poisoning attacks on machine learning models.
method Rigorous study of four standard defenses in both a powerful and a realistic threat model.
result The effectiveness of defenses depends on the ease of the learning problem.
Current neural network-based classifiers are susceptible to adversarial examples even in the black-box setting, where the attacker only has query access to the model. In practice, the threat model for real-world systems is often more restrictive than the typical black-box model where the adversary can observe the full …
ACE explains security anomaly detection models through feature contributions.
problem Understanding which features contribute to security anomalies.
method Regression framework to locally approximate anomaly scores.
result Identifies correct contributing features in synthetic data and real data.
Survey on security and privacy in decentralized federated learning.
problem New threats in decentralized federated learning due to the removal of the server.
method Thorough security analysis and overview of defense mechanisms.
result Challenges and threats in decentralized federated learning.
New snooping attacks exploit deep RL without access to environment.
problem Security vulnerabilities in deep reinforcement learning.
method Proposes snooping threat models and attacks on RL agents.
result Adversaries can launch attacks without interacting with the environment.
Most of the existing solutions to enterprise threat management are preventive approaches prescribing means to prevent policy violations with varying degrees of success. In this paper we consider the complementary scenario where a number of security violations have already occurred, or security threats, or vulnerabiliti…
TinyML models detect RF and cyber threats in spacecraft with low latency.
problem Detecting cyber-RF threats in autonomous spacecraft with low latency.
method Analysis of classical models (RF, LR, SVM, MLP) for latency-accuracy trade-offs.
result Logistic Regression achieves microsecond-level inference with minimal accuracy loss.
CCAT improves model robustness to various adversarial attacks.
problem Robustness to adversarial attacks does not generalize to unseen threat models.
method CCAT biases models towards low confidence predictions on adversarial examples.
result CCAT increases robustness against multiple adversarial attack norms and types.
Article evaluates AI security threats and proposes multiple measures.
problem Threats to AI integrity and security.
method Literature review, analysis of AI supply chain, discussion of mitigations.
result Multiple protective measures are necessary for AI security.
Study shows Skorokhod insider outperforms forward insider in logarithmic utility maximization.
problem Maximizing logarithmic utility for an insider with different anticipating techniques.
method Comparison of Russo-Vallois forward and Skorokhod integrals.
result Skorokhod insider outperforms forward insider in logarithmic utility maximization.
Active authentication is the problem of continuously verifying the identity of a person based on behavioral aspects of their interaction with a computing device. In this study, we collect and analyze behavioral biometrics data from 200subjects, each using their personal Android mobile device for a period of at least 30…
Bayesian model assesses criminal threat escalation.
problem Evaluate threats posed by potential violent criminals.
method Customised three-level Bayesian hierarchical model.
result Model calibrates to expert judgments and updates in real time.
Survey on threats to federated learning models.
problem Vulnerabilities in federated learning protocols.
method Taxonomy of threat models and attacks.
result Important future research directions.
Network analysis detects insider trading by flagging coordinated trades.
problem Detecting insider trading due to limited labelled data.
method Data-driven network approach using SEC trade data.
result Algorithm identifies insider trading clusters with high accuracy.
Study insider trading benefits in a market with high transaction costs.
problem Super--replication of European contingent claims in illiquid markets.
method Model insider information and quadratic transaction costs, analyze scaling limits.
result Scaling limit gives the value of insider information.
Bayesian system helps identify and thwart terrorist plans.
problem Identifying and thwarting terrorist plans before they occur.
method Develops a Bayesian decision support system to integrate member and group activities.
result Estimates the combined threat posed by a terrorist group.
This work introduces a new threat model for adversarial attacks using perceptual metrics.
problem Insufficient threat models for capturing imperceivable adversarial examples.
method Leverage quantitative perceptual metrics (LPIPS, SSIM) to define a novel threat model.
result Combined attacks retain perceptual distortion but induce higher misclassification rates.
The exponential increase in dependencies between the cyber and physical world leads to an enormous amount of data which must be efficiently processed and stored. Therefore, computing paradigms are evolving towards machine learning (ML)-based systems because of their ability to efficiently and accurately process the eno…
Study risk-averse insider's behavior in dynamic signal asset pricing.
problem Analyzing risk-averse insider's dynamic signal in asset pricing.
method Employing a weak conditioning methodology to construct a Schrödinger bridge, deriving necessary conditions for equilibrium.
result Derive explicit closed-form solutions for important cases.
A novel unified Bayesian framework for network detection is developed, under which a detection algorithm is derived based on random walks on graphs. The algorithm detects threat networks using partial observations of their activity, and is proved to be optimum in the Neyman-Pearson sense. The algorithm is defined by a …
In this paper, we present a multi-period trading model in the style of Kyle (1985)'s inside trading model, by assuming that there are at least two insiders in the market with long-lived private information, under the requirement that each insider publicly discloses his stock trades after the fact. Based on this model, …
Insider trading is reduced when penalized, affecting expected penalties in a non-monotone way.
problem Reducing insider trading behavior when insiders face legal penalties.
method Characterized via a backward stochastic differential equation (BSDE) with a non-linear operator.
result The insider's expected penalties are non-monotone in the fee structure and determined by relative entropy.
Insider trading is one of the numerous white collar crimes that can contribute to the instability of the economy. Traditionally, the detection of illegal insider trades has been a human-driven process. In this paper, we collect the insider tradings made available by the US Securities and Exchange Commissions (SEC) thro…
Honest traders can outperform insiders in a Black-Scholes market with positive probability.
problem Comparing the performance of honest and insider traders in a financial market.
method Using anticipating stochastic calculus and forward integral analysis of the Doléans-Dade exponential process.
result The honest trader can achieve higher logarithmic utility and wealth than the insider with positive probability.
Study examines insider information's impact on arbitrage and utility maximization in financial portfolios.
problem Analyzing the relationship between insider information and arbitrage in financial portfolio optimization.
method Examines the utility maximization problem under different utility functions (logarithmic and CRRA) with and without no temporary-bankruptcy restriction, considering altered information flow.
result Insider information's value is bounded when arbitrage holds, and it does not always imply arbitrage.
Study examines insider trading in short-selling restricted markets.
problem Analyzing insider trading opportunities in short-selling prohibited markets.
method Introducing minimal supermartingale measure and analyzing its properties in relation to minimal martingale measure.
result Conditions under which both measures fail to exist, indicating insider information affecting market perception.
Kyle (1985) builds a pioneering and influential model, in which an insider with long-lived private information submits an optimal order in each period given the market maker's pricing rule. An inconsistency exists to some extent in the sense that the ``constant pricing rule " actually assumes an adaptive expected price…
Evaluates SHIELD's effectiveness against adaptive adversaries in various threat models.
problem Evaluating SHIELD's efficacy against adaptive adversaries in different threat models.
method Empirical analysis of SHIELD's robustness against adaptive attacks using Projected Gradient Descent (PGD) attacks in various threat models (white-box, gray-box).
result The targeted PGD attack success rate drops from 64.3% to 48.9% when models are trained from scratch instead of retrained.
Before a person can be prosecuted and convicted for insider trading, he must first execute the overt act of trading. If no sale of security is consummated, no crime is also consummated. However, through a complex and insidious combination of various financial instruments, one can capture the same amount of gains from i…
Temporal threat model defends against data poisoning with timestamps.
problem Adversaries can poison more samples than expected, rendering existing defenses ineffective.
method Leverage timestamps to define earliness and duration metrics for temporal robustness.
result Temporal aggregation provides provable temporal robustness against data poisoning.
Defense against Wasserstein adversarial attacks using randomized smoothing.
problem Certified robustness against Wasserstein adversarial attacks.
method Randomized smoothing applied to the space of flows between images, bounding Wasserstein distance by L_1 distance.
result Significantly improved accuracy under Wasserstein adversarial attacks compared to unprotected models.
We study the gain of an insider having private information which concerns the default risk of a counterparty. More precisely, the default time τis modelled as the first time a stochastic process hits a random barrier L. The insider knows this barrier (as it can be the case for example for the manager of the counterpart…
We evaluate the robustness of Adversarial Logit Pairing, a recently proposed defense against adversarial examples. We find that a network trained with Adversarial Logit Pairing achieves 0.6% accuracy in the threat model in which the defense is considered. We provide a brief overview of the defense and the threat models…