{"id":"W3153493802","doi":"10.1109/tnsm.2021.3071928","title":"Anomaly Detection for Insider Threats Using Unsupervised Ensembles","year":2021,"lang":"en","type":"article","venue":"IEEE Transactions on Network and Service Management","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":129,"is_retracted":false,"has_abstract":true,"ca_institutions":"Dalhousie University","funders":"Natural Sciences and Engineering Research Council of Canada; Killam Trusts","keywords":"Insider threat; Anomaly detection; Computer science; Robustness (evolution); Insider; Unsupervised learning; Machine learning; Artificial intelligence; Data mining","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002285434,0.001215574,0.001431313,0.002446822,0.0007800772,0.001005981,0.001722956,0.001055289,0.0004782036],"category_scores_gemma":[0.006668322,0.0003574868,0.001358738,0.001302069,0.0006279923,0.001934049,0.00142177,0.001696206,0.0003575745],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0007013936,"about_ca_system_score_gemma":0.0007705792,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003123579,"about_ca_topic_score_gemma":0.005267015,"domain_scores_codex":[0.9980651,0.0004763781,0.0001160685,0.0005623801,0.0005791514,0.0002009353],"domain_scores_gemma":[0.9951487,0.001888691,0.0006463013,0.0008066582,0.001309769,0.0001998555],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0003092206,0.0006141428,0.05128044,0.0001034417,0.0005483557,0.0002663679,0.0003268996,0.4420092,0.01796813,0.004310346,0.004263846,0.4779997],"study_design_scores_gemma":[0.000002868722,0.000044409,0.002251953,0.000005013801,0.00002251157,0.00006407446,0.00002590537,0.992316,0.002474329,0.002409499,0.0003724131,0.00001098253],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1642569,0.0003957581,0.8316844,0.0002912259,0.0001056369,0.00008371894,0.0002045924,0.001575295,0.001402456],"genre_scores_gemma":[0.8734665,0.0001872133,0.1236522,0.0001382055,0.0001169237,0.00007522645,0.0008780477,0.00009958266,0.001386152],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003123579,"threshold_uncertainty_score":0.01208669,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03015125374528249,"score_gpt":0.244499425418582,"score_spread":0.2143481716732995,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}