Skip to content
Open access

A PRIVACY-PRESERVING FRAMEWORK FOR INSIDER THREAT DETECTION USING PROCESS MINING, MACHINE LEARNING, AND DIFFERENTIAL PRIVACY

Sep 2026 · International Journal of Science and Research Archive · 0 citations

Abstract

Insider threats remain one of the most damaging and difficult-to-detect cybersecurity risks, as malicious actors already possess legitimate access privileges. This paper presents a privacy-preserving detection framework that combines per-user process mining with differential privacy, rigorously evaluated on the official Carnegie Mellon CERT r4.2 ground-truth dataset containing 70 confirmed malicious users across three threat scenarios. By shifting from population-wide to per-user Heuristics Miner discovery, the framework overcomes the well-known flower-model degeneration and extracts highly discriminative fitness and sequence-variant features. Operating at user-week granularity (67 298 windows, 0.48 % malicious prevalence), the full feature set achieves a Random Forest AUC-ROC of 0.990 and PR-AUC of 0.232—more than twice the performance of a strong behavioural-only baseline. At a practical privacy budget of ε=1.0, differential privacy incurs an AUC-ROC cost of only 0.001 while still delivering a PR-AUC 56 times higher than random guessing. Aggregating weekly scores to the user level yields an AUC-ROC of 0.923, enabling identification of 80 % of confirmed insiders at a false-positive rate below 25 %. Complementary process-prediction tasks further demonstrate an AUC of 0.776 for next risky-activity forecasting and an R2of 0.714 for one-week-ahead risk-score regression. These results establish that formal (ε,δ)-differential privacy and operationally effective insider-threat detection can be achieved simultaneously when process mining is performed at the appropriate (per-user) granularity.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.