{"id":"W4416962837","doi":"10.1109/pst65910.2025.11268873","title":"Semantic and Graph-Based Unsupervised Learning for Insider Threat Detection Using User Activity Sequences","year":2025,"lang":"","type":"article","venue":"","topic":"Information and Cyber Security","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"Polytechnique Montréal","funders":"","keywords":"Insider threat; Anomaly detection; Unsupervised learning; Word2vec; Graph; Feature learning; Convolutional neural network; Insider; Semantics (computer science)","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":["metaepi_narrow"],"consensus_categories":[],"category_scores_codex":[0.0006141599,0.0002947522,0.0003099467,0.0004219465,0.001185869,0.0008005865,0.0002717741,0.0002020047,0.0000333391],"category_scores_gemma":[0.00009495713,0.0002814061,0.0001526117,0.0009664458,0.0001654583,0.00194223,0.0001638687,0.0003124316,0.000004477178],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0000980199,"about_ca_system_score_gemma":0.0003400198,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0007164884,"about_ca_topic_score_gemma":0.0005204271,"domain_scores_codex":[0.9982151,0.0001909898,0.0003955452,0.0005067459,0.0002602399,0.0004314069],"domain_scores_gemma":[0.9988537,0.0002444193,0.0001724509,0.000327172,0.0003008142,0.0001014181],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0006519154,0.0005742984,0.0354385,0.003378253,0.0005161274,0.00001194688,0.01230282,0.03795647,0.04625799,0.07357477,0.00009947336,0.7892374],"study_design_scores_gemma":[0.001083844,0.0001255193,0.006556108,0.0001316454,0.00005882514,0.000005665698,0.00025401,0.9329564,0.05614371,0.001884791,0.000494538,0.0003049423],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.4327224,0.00008384156,0.5653028,0.0004395222,0.000429374,0.0003978078,8.953942e-7,0.00009357181,0.0005297329],"genre_scores_gemma":[0.9914191,0.00003065343,0.007327491,0.0008905093,0.00002809031,0.00002079529,0.000001407544,0.000008109726,0.0002737883],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.8949999,"threshold_uncertainty_score":0.9999638,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02682991840008874,"score_gpt":0.276319815093874,"score_spread":0.2494898966937853,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}