A Deep Ensemble Learning Method to Detect Insider Threats

Document Type : Research Article

Authors

Computer Engineering Department, University of Mazandaran, Babolsar, Mazandaran, Iran

Abstract
Insider threats pose a critical cybersecurity challenge, causing damage that extends beyond immediate financial harm to include reputational erosion, diminished customer confidence, legal ramifications, and loss of stakeholder trust. Mitigating such threats requires a multifaceted approach that combines technological safeguards with a deep understanding of human behavior. Deep Learning (DL) and stacked generalization techniques have emerged as promising solutions for detecting these complex attacks. This paper proposes a deep ensemble Intrusion Detection System (IDS) designed to accurately detect insider threats by leveraging DL-based stacked generalization. The proposed approach transforms raw tabular data into an image-based format and applies a stacking ensemble strategy comprising three base learners, a Convolutional Neural Network (CNN), a Convolutional Autoencoder (CAE), and a CNN-LSTM. evaluated on two versions of the CERT insider threat dataset (r4.2 and r5.2). To address class imbalance in the training data, the Synthetic Minority Oversampling Technique (SMOTE) was applied, and a Deep Neural Network (DNN) was employed as the meta-classifier within the stacked generalization framework. The proposed system achieved high performance on both dataset versions, attaining a Precision of 99.98%, Recall of 99.98%, and an AUC of 100% on r4.2, and a Precision of 99.98%, Recall of 99.98%, and an AUC of 99.69% on r5.2. These results demonstrate that integrating image-based data transformation with deep ensemble learning and stacked generalization yields a robust and highly accurate IDS for insider threat detection, with future work directed toward broader dataset generalization and the incorporation of behavioral analytics to further enhance detection capabilities.

Keywords


[1] L. Iacono, K. Wojcieszek, and G. Glass. Q3 2022 threat landscape: Insider threat, the trojan horse. Technical report, Kroll, Nov 2022. URL https://www.kroll.com/ en/insights/publications/cyber/threatintelligence-reports/q3-2022-threatlandscape-insider-threat-trojan-horse.
[2] Cybersecurity Insiders and Gurucul. 2023 insider threat report. Technical report, Gurucul, 2023. URL https://library.cyentia.com/report/ report_014103.html.
[3] Larry Ponemon. 2022 cost of insider threats global report. Technical report, Ponemon Institute and Proofpoint, 2022. URL https: //static.poder360.com.br/2022/01/pfptus-tr-the-cost-of-insider-threatsponemon-report.pdf.
[4] Cybersecurity Insiders. Insider threat report. Technical report, Fortinet, 2019. URL https://www.fortinet.com/content/dam/ fortinet/assets/threat-reports/insiderthreat-report.pdf.
[5] Cybersecurity Insiders. Insider threat report. Technical report, Cybersecurity Insiders and Gurucul, 2021. URL https://www.cybersecurity-insiders. com/wp-content/uploads/2021/06/2021Insider-Threat-Report-Gurucul-Finaldd8f5a75.pdf.
[6] Ponemon Institute and IBM Security. 2020 cost of insider threats global report. Technical report, Proofpoint, 2020. URL https://www.proofpoint.com/sites/ default/files/observeit/2020/02/2020Global-Cost-of-Insider-Threats-PonemonReport_UTD.pdf.
[7] L. Yan, Z. Ren, Y. Zhang, Z. Tao, and Y. Zhao. Constructing the public opinion crisis prediction model using cnn and lstm techniques based on social network mining. International Journal of Interactive Multimedia and Artificial Intelligence, 8(7):86–96, 2024.
[8] Tian Tian, Chen Zhang, Bo Jiang, Huamin Feng, and Zhigang Lu. Insider threat detection for specific threat scenarios. Cybersecurity, 8(1):17, 2025.
[9] W. Hongetal. A graph empowered insider threat detection framework based on daily activities. ISA Transactions, 141:84–92, 2023.
[10] Hamdi Friji. Graph neural network-based intrusion detection for secure edge networks. 2024.
[11] Zhi Qiang Wang and Abdulmotaleb El Saddik. Dtitd: An intelligent insider threat detection framework based on digital twin and selfattention based deep learning models. IEEE Access, 11:114013–114030, 2023.
[12] B. Sharma, P. Pokharel, and B. Joshi. User behavior analytics for anomaly detection using lstm autoencoder - insider threat detection. In Proceedings of the 11th International Conference on Advances in Information Technology (IAIT2020), pages 1–9, 2020.
[13] J. Lu and R. K. Wong. Insider threat detection with long short-term memory. In Proceedings of the Australasian Computer Science Week Multiconference, pages 1–10, 2019.
[14] Xingjian Zhu, Jiankuo Dong, Jin Qi, Zhenguo Zhou, Zhenjiang Dong, Yanfei Sun, and Moyu Wang. Auth: An adversarial autoencoder based unsupervised insider threat detection scheme for multisource logs. IEEE Transactions on Industrial Informatics, 20(9):10955–10965, 2024.
[15] M. N. Al-Mhiqani et al. A new intelligent multilayer framework for insider threat detection. Computers & Electrical Engineering, 97:107597, 2022.
[16] Kossi Bissadu, Gahangir Hossain, Leela Pavani Velagala, and Salleh Sonko. Analyzing insider cyber threats and human factors within the framework of agriculture 5.0. In 2024 12th International Symposium on Digital Forensics and Security (ISDFS), pages 1–5. IEEE, 2024.
[17] F. Yuan et al. Insider threat detection with deep neural network. In Proceedings of the 18th International Conference on Computational Science (ICCS 2018), pages 43–54. Springer, 2018.
[18] B. B. Sarhan and N. Altwaijry. Insider threat detection using machine learning approach. Applied Sciences, 13(1):259, 2022.
[19] Jianguo Jiang et al. Anomaly detection with graph convolutional networks for insider threat and fraud detection. In MILCOM 2019 2019 IEEE Military Communications Conference (MILCOM), 2019.
[20] A. Anju et al. Detection of insider threats using deep learning. In 2023 3rd International Conference on Pervasive Computing and Social Networking (ICPCSN), 2023.
[21] Menghua Yang, Junkai Yi, Hejun Zhu, and Lingling Tan. Cnn-lstm-based insider threat detection model. In 2025 International Conference on Electrical Automation and Artificial Intelligence (ICEAAI), pages 985–990. IEEE, 2025.
[22] Francisco Montes, J Bermejo, Luís Enrique Sanchez, JR Bermejo, and Juan Antonio Sicilia. Detecting malware in cyberphysical systems using machine learning: A survey. KSII Transactions on Internet and Information Systems (TIIS), 15(3):1119–1139, 2021.
[23] Hossein Shadabfar, Motahareh Dehghan, and Babak Sadeghian. Dsrl-apt-2023: A new synthetic dataset for advanced persistent threats. ISeCure, 17(2), 2025.
[24] Motahareh Dehghan, Babak Sadeghian, Erfan Khosravian, Alireza Sedighi Moghaddam, and Farshid Nooshi. Proapt: Projection of apts with deep reinforcement learning. ISeCure, 17(1), 2025.
[25] Xiaoling Tao, Jianxiang Liu, Yuelin Yu, Haijing Zhang, and Ying Huang. An insider threat detection method based on improved test-time training model. High-Confidence Computing, 5(1): 100283, 2025.
[26] Ali Haidar, Yu-Zheng Lin, Qinxuan Shi, Zhanglong Yang, Desmond Amadigwe, Brian Terry, Sudheer Krishna Battu, Pratik Satam, and Sicong Shao. A survey of large language models for insider threat detection. In 2025 Cyber Awareness and Research Symposium (CARS), pages 1–10. IEEE, 2025.
[27] Mohammad AL-Smadi. Multi-axis trust modeling for interpretable account hijacking detection. arXiv preprint arXiv:2603.13246, 2026.
[28] Duc C. Le and Nur Zincir-Heywood. Anomaly detection for insider threats using unsupervised ensembles. IEEE Transactions on Network and Service Management, 18(2):1152–1164, 2021.
[29] RG Gayathri, Atul Sajjanhar, and Yong Xiang. Image-based feature representation for insider threat classification. Applied Sciences, 10(14): 4945, 2020.
[30] Qingwei Chen, Xin Xing, Shumei Li, Ying Shao, Xiangjun Song, and Zhao Qi. Dynml-net: A porcine enteric virus identification network based on protein language models and a dynamic heterogeneous multi-branch architecture. 2026.
[31] G. A. Pradipta, R. Wardoyo, A. Musdholifah, I. N. H. Sanjaya, and M. Ismail. Smote for handling imbalanced data problem : A review. In Proceedings of the 2021 Sixth International Conference on Informatics and Computing (ICIC), pages 1–8. IEEE, 2021.
[32] Dmitry Duplyakin, Robert Ricci, Aleksander Maricq, Gary Wong, Jonathon Duerig, Eric Eide, Leigh Stoller, Mike Hibler, David Johnson, Kirk Webb, Aditya Akella, Kuangching Wang, Glenn Ricart, Larry Landweber, Chip Elliott, Michael Zink, Emmanuel Cecchet, Snigdhaswin Kar, and Prabodh Mishra. The design and operation of CloudLab. In Proceedings of the USENIX Annual Technical Conference (ATC), pages 1–14, July 2019. URL https://www.flux.utah.edu/ paper/duplyakin-atc19.
[33] Alok Sharma, Edwin Vans, Daichi Shigemizu, Keith A Boroevich, and Tatsuhiko Tsunoda. Deepinsight: A methodology to transform a nonimage data to an image for convolution neural network architecture. Scientific reports, 9(1): 11399, 2019.
[34] Yitan Zhu, Thomas Brettin, Fangfang Xia, Alexander Partin, Maulik Shukla, Hyunseung Yoo, Yvonne A Evrard, James H Doroshow, and Rick L Stevens. Converting tabular data into images for deep learning with convolutional neural networks. Scientific reports, 11(1):11325, 2021.