{"id":"W2887799638","doi":"10.1109/spw.2018.00043","title":"Evaluating Insider Threat Detection Workflow Using Supervised and Unsupervised Learning","year":2018,"lang":"en","type":"article","venue":"","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":65,"is_retracted":false,"has_abstract":true,"ca_institutions":"Dalhousie University","funders":"","keywords":"Insider threat; Workflow; Anomaly detection; Computer science; Unsupervised learning; Insider; Artificial intelligence; Supervised learning; Machine learning; Hidden Markov model; Set (abstract data type); Database; Artificial neural network","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.006810318,0.001638413,0.001145681,0.003650899,0.0009933988,0.001654519,0.001625211,0.0012814,0.0005783455],"category_scores_gemma":[0.0176409,0.0003708595,0.001142437,0.001654216,0.0008408272,0.001703306,0.0009978053,0.001284081,0.0007676815],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.002058446,"about_ca_system_score_gemma":0.003144578,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.01534485,"about_ca_topic_score_gemma":0.02088961,"domain_scores_codex":[0.995451,0.00131969,0.0005445371,0.001254726,0.001129317,0.0003006371],"domain_scores_gemma":[0.9800725,0.01031863,0.001492322,0.002034451,0.005175598,0.0009064654],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001544119,0.002916001,0.08754926,0.0005634521,0.000564964,0.0004223803,0.001091433,0.382091,0.03054741,0.001557417,0.005169979,0.4859826],"study_design_scores_gemma":[0.00003298235,0.0002734073,0.007650569,0.00001491641,0.00003324424,0.00007126281,0.0001767187,0.9711061,0.01876293,0.001222331,0.0006236818,0.00003186611],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.7750599,0.0004248101,0.2064793,0.0003435476,0.0001065208,0.0006855274,0.00148335,0.01296896,0.002447966],"genre_scores_gemma":[0.7554617,0.0001391031,0.2372924,0.00008584061,0.00002879625,0.0002564523,0.004935468,0.0002562926,0.001543942],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.01534485,"threshold_uncertainty_score":0.03601688,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.06256651640064904,"score_gpt":0.3114651334682395,"score_spread":0.2488986170675904,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}