Privacy-Preserving AI for Insider Threat Detection: A Federated Graph Learning Approach Using Behavioral Analytics
Abstract
Detection of insiders is challenging due to potential abuses of authorised access. In this work, a privacy-preserving approach to the analysis of enterprise event logs leveraging behavioural attributes, graph-based relations between user activities, anomaly detection and federated learning is proposed. The proxy target feature is calculated based on the log severity feature; to avoid direct target leakage, the severity attribute is stripped out before pre-processing, training and evaluation. Graph centrality scores and Isolation Forest scores are used along with Random Forest, Extra Trees, XGBoost, Logistic Regression and Support Vector Machine classifiers. The best ROC-AUC and PR-AUC were obtained by XGBoost with values of 0.9669 and 0.8378 respectively, whereas the best F1-score was reached by the Random Forest classifier (0.7836). A four-client non-IID federated learning experiment tests the performance, communication costs and Gaussian differential privacy with varying privacy budget values.