TARU PUBLICATIONS
 Journal of Statistics and Management Systems cover
Open Access ·Peer-reviewed·ISSN (Online): 2169-0014·ISSN (Print): 0972-0510
Powered by:Powered by

The Journal of Statistics and Management Systems (JSMS) is a world leading journal publishing high quality, rigorously peer-reviewed original research on theoretical and applied statistics and management systems since 1998. The scope is intentionally broad, but papers must make a novel contribution to the field to be considered for publication. Topics include, but are not limited to, the following: • Statistics • Applied Statistics • Industrial Statistics • Statistical Inference • Interdisciplinary role of Statistics • Actuarial Sciences • Decision Sciences • Managerial Aspects • Management Sciences • Management Information Systems

Issues up to 2022 co-published with and available at:Taylor & Francis Online
submissions@tarupublications.com
Open Access Research Article

LSTM autoencoders for novel insider threat detection : A psychometric and temporal feature based approach

* , ,

* Corresponding author · click or hover a name for details

pp. 1331–1353Vol. 28Issue 7October 2025DOI: 10.47974/JSMS-1556XML
Received:
10 Jun 2025
Published Online:
30 Oct 2025
Article type:
Research Article
Language:
EN
Article no.:
JSMS-1556
Pages:
1331–1353

Abstract

Insider threats are becoming one of the most serious challenges in cybersecurity, causing heavy financial and operational damage to organizations. Traditional rule-based detection methods often fail because they cannot recognize complex or new patterns of malicious behavior. To address this gap, we propose a hybrid insider threat detection model that combines Long Short-Term Memory (LSTM) autoencoders with both temporal activity logs and psychometric (behavioral) features, using the CERT CMU Insider Threat Dataset v6.2. Our data pipeline enabled large-scale feature engineering, allowing the model to learn normal user behavior and detect anomalies linked to malicious insiders. Experimental results show that adding psychometric features to technical and temporal data significantly improved accuracy, with our LSTM autoencoder achieving a precision of 0.89, recall of 0.83, F1-score of 0.86, and an AUC-ROC of 0.91. These results outperformed benchmark methods such as Isolation Forest and One-Class SVM. Overall, our findings demonstrate that fusing behavioral science with deep learning provides a more effective and scalable way to detect insider threats, offering practical value for strengthening cyber defense and guiding future research.

Keywords

Subject Classifications

68T0768M25

References

[1] S. Yuan and X. Wu, “Deep learning for insider threat detection: Review, challenges and opportunities,” Computers & Security, vol. 104, pp. 102221 (2021). [Online]. Available: https://doi.org/10.1016/j.cose.2021.102221.
[2] Verizon, 2023 Data Breach Investigations Report (2023).
[3] Ponemon Institute, Cost of Insider Threats Global Report (2022).
[4] B. B. Sarhan and N. Altwaijry, “Insider threat detection using machine learning approach,” Applied Sciences, vol. 13, no. 1, pp. 259 (2022). [Online]. Available: https://doi.org/10.3390/app13010259
[5] M. N. Al-Mhiqani, S. Abd Razak, M. Anbar, S. Manickam, Z. R. Alashhab, A. Y. A. Al-Dubai, and K. A. Bakar, “A review of insider threat detection,” Applied Sciences, vol. 10, no. 15, pp. 5208 (2020). [Online]. Available: https://doi.org/10.3390/app10155208
[6] CERT, “CERT insider threat dataset,” (2024). [Online]. Available: https://www.cert.org/insider-threat/tools/
[7] A. Wahid, John G. Breslin, and M. I. Ali, “Prediction of machine failure in Industry 4.0: A hybrid CNN-LSTM framework,” Applied Sciences, vol. 12, no. 9, pp. 4221 (2022). [Online]. Available: https://doi.org/10.3390/app12094221
[8] R. Nasir, Z. Khan, R. Hussain, A. Almogren, I. U. Din, and M. Guizani, “Behavioral based insider threat detection using deep learning,” IEEE Access, vol. 9, pp. 143266–143277 (2021). [Online]. Available: https://doi.org/10.1109/ACCESS.2021.3118297
[9] J. Lee, J. Park, Y. Kim, and P. Kang, “Insider threat detection using deep autoencoder and feature bagging ensemble,” in Proc. Int. Conf. Machine Learning and Cybernetics (ICMLC) (2021).
[10] F. L. Greitzer, L. J. Kangas, C. F. Noonan, C. R. Brown, and T. A. Ferryman, “Psychosocial modeling of insider threat risk based on behavioral and word use analysis,” E-Service Journal, vol. 9, no. 1, pp. 106–131 (2013). [Online]. Available: https://doi.org/10.2979/eservicej.9.1.106
[11] D. Li, X. Wu, Y. Liu, and J. Zhang, “Image-based insider threat detection via geometric transformation,” arXiv preprint arXiv:2108.10567 (2021). [Online]. Available: https://arxiv.org/abs/2108.10567
[12] R. G. Gayathri, A. Sajjanhar, and Y. Xiang, “Hybrid deep learning model using SPCAGAN augmentation for insider threat analysis,” arXiv preprint arXiv:2203.02855 (2022). [Online]. Available: https://arxiv.org/abs/2203.02855
[13] A. Barredo Arrieta, N. Díaz-Rodríguez, J. del Ser, A. Bennetot, S. Tabik, A. Barbado, S. Garcia, S. Gil-Lopez, D. Molina, R. Benjamins, R. Chatila, and F. Herrera, “Explainable Artificial Intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI,” Information Fusion, vol. 58, pp. 82–115 (2020). [Online]. Available: https://doi.org/10.1016/J.INFFUS.2019.12.012
[14] S. M. Lundberg, P. G. Allen, and S.-I. Lee, “A unified approach to interpreting model predictions,” arXiv preprint arXiv:1705.07874. [Online]. Available: https://doi.org/10.48550/arXiv.1705.07874
[15] A. Vaswani, G. Brain, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” arXiv preprint arXiv:1706.03762 (2023). [Online]. Available: https://doi.org/10.48550/arXiv.1706.03762.

Views: 149Downloads: 9Citations: 0