arXiv:2508.11472cs.CRcs.AI2025-08被引 1

用弱监督提升行为级内鬼检测准确率

RMSL: Weakly-Supervised Insider Threat Detection with Robust Multi-sphere Learning

  • 用序列级标签替代行为级标注,降低标注成本
  • 多超球体模型捕捉正常行为模式,提升区分能力
  • 适合缺乏精细标注的内鬼检测场景

内鬼威胁检测旨在通过分析记录用户交互的日志识别恶意行为。由于缺乏细粒度的行为级标注,从用户行为序列中检测特定行为级异常极具挑战。无监督方法因正常与异常行为的内在模糊性,常出现高误报率和漏报率。本文引入行为序列的弱标签(训练标签为序列级而非行为级),以较低标注成本增强对行为级异常的检测能力。提出一种名为鲁棒多球体学习(RMSL)的新框架,利用多个超球体表示行为的正常模式。首先构建单类分类器作为无异常监督的起始点;随后基于模型预测置信度,采用多实例学习和自训练去偏策略,进一步优化超球体和特征表示。该方法显著提升了模型区分正常与异常行为的能力。大量实验表明,RMSL在行为级内鬼检测上性能明显优于现有方法。

原文摘要 · Abstract (English)

Insider threat detection aims to identify malicious user behavior by analyzing logs that record user interactions. Due to the lack of fine-grained behavior-level annotations, detecting specific behavior-level anomalies within user behavior sequences is challenging. Unsupervised methods face high false positive rates and miss rates due to the inherent ambiguity between normal and anomalous behaviors. In this work, we instead introduce weak labels of behavior sequences, which have lower annotation costs, i.e., the training labels (anomalous or normal) are at sequence-level instead of behavior-level, to enhance the detection capability for behavior-level anomalies by learning discriminative features. To achieve this, we propose a novel framework called Robust Multi-sphere Learning (RMSL). RMSL uses multiple hyper-spheres to represent the normal patterns of behaviors. Initially, a one-class classifier is constructed as a good anomaly-supervision-free starting point. Building on this, using multiple instance learning and adaptive behavior-level self-training debiasing based on model prediction confidence, the framework further refines hyper-spheres and feature representations using weak sequence-level labels. This approach enhances the model's ability to distinguish between normal and anomalous behaviors. Extensive experiments demonstrate that RMSL significantly improves the performance of behavior-level insider threat detection.

内鬼检测弱监督多超球体序列级标签

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。