@inproceedings{8e9974265c49432d957a034a1f5650de,
title = "Few-shot Insider Threat Detection",
abstract = "Insiders cause significant cyber-security threats to organizations. Due to a very limited number of insiders, most of the current studies adopt unsupervised learning approaches to detect insiders by analyzing the audit data that record information about employees' activities. However, in practice, we do observe a small number of insiders. How to make full use of these few observed insiders to improve a classifier for insider threat detection is a key challenge. In this work, we propose a novel framework combining the idea of self-supervised pre-training and metric-based few-shot learning to detect insiders. Experimental results on insider threat datasets demonstrate that our model outperforms the existing anomaly detection approaches by only using a few insiders.",
keywords = "cyber-security, few-shot learning, insider threat detection",
author = "Shuhan Yuan and Panpan Zheng and Xintao Wu and Hanghang Tong",
note = "This work was supported in part by NSF (1564250, 1946391) and the Department of Energy (DE-OE0000779).; 29th ACM International Conference on Information and Knowledge Management, CIKM 2020 ; Conference date: 19-10-2020 Through 23-10-2020",
year = "2020",
month = oct,
day = "19",
doi = "10.1145/3340531.3412161",
language = "English (US)",
series = "International Conference on Information and Knowledge Management, Proceedings",
publisher = "Association for Computing Machinery",
pages = "2289--2292",
booktitle = "CIKM 2020 - Proceedings of the 29th ACM International Conference on Information and Knowledge Management",
address = "United States",
}