{"id":"W4416962837","doi":"10.1109/pst65910.2025.11268873","title":"Semantic and Graph-Based Unsupervised Learning for Insider Threat Detection Using User Activity Sequences","year":2025,"lang":"","type":"article","venue":"","topic":"Information and Cyber Security","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"Polytechnique Montréal","funders":"","keywords":"Insider threat; Anomaly detection; Unsupervised learning; Word2vec; Graph; Feature learning; Convolutional neural network; Insider; Semantics (computer science)","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0004760018,0.001370849,0.0006760944,0.002280331,0.0003385015,0.0005443873,0.001050322,0.0006831791,0.0007640939],"category_scores_gemma":[0.002080614,0.0002554985,0.0008214524,0.00178294,0.0006605085,0.001868465,0.0008817288,0.001303586,0.000719867],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006345018,"about_ca_system_score_gemma":0.0006328986,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.004724213,"about_ca_topic_score_gemma":0.00988257,"domain_scores_codex":[0.9991636,0.00021193,0.0000443855,0.0003406666,0.0001593043,0.0000800694],"domain_scores_gemma":[0.9989499,0.0003703162,0.0002226542,0.0002214667,0.0001664371,0.00006912479],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004627446,0.0009261137,0.04140352,0.0003410324,0.0003322291,0.0005838696,0.0005579577,0.1942172,0.02060409,0.01316724,0.01353258,0.7138714],"study_design_scores_gemma":[0.000006930652,0.00008845105,0.004193575,0.00001771195,0.00002462321,0.000174956,0.00009536461,0.9786421,0.003375106,0.01123055,0.002131019,0.00001955511],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1906284,0.001088023,0.7966393,0.0004782493,0.0001150724,0.0001716959,0.002360543,0.005230445,0.003288261],"genre_scores_gemma":[0.8541479,0.0004926511,0.1347029,0.0001942636,0.00008032948,0.0001316061,0.007002094,0.000200264,0.0030481],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.004724213,"threshold_uncertainty_score":0.009393394,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02682991840008874,"score_gpt":0.276319815093874,"score_spread":0.2494898966937853,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}