GAN-Based Augmentation for Imbalanced Insider Threat Detection
摘要
Insider threats are characterized by their strong covertness and significant destructiveness. Furthermore, conventional detection methods often fail because internal attackers naturally possess access to sensitive data and assets. Insider threat detection is challenged by a severe data imbalance problem, as malicious activities are inherently rare compared to normal operations. Traditional classification models tend to overfit the majority class patterns, leading to poor generalization ability on the minority insider threat events. To address this, we propose a novel Collaborative Adversarial Training Framework based on a Generative Adversarial Network for synthetic data augmentation, specifically targeting imbalanced insider threat detection. Experimental results on the benchmark insider threat dataset CERT r6.2 show that our method achieves an improvement of up to 98.3% AUC compared to traditional oversampling methods SMOTE, ADASYN. The proposed framework offers a promising direction for adaptive and data-efficient insider threat detection.