{"id":"W4417470884","doi":"10.1109/iccst63435.2025.11293461","title":"Explicit Behavioral Embedding Method for Generating Explanations of Insider Threat Events","year":2025,"lang":"","type":"article","venue":"","topic":"Information and Cyber Security","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Insider threat; Insider; Anomaly detection; Transparency (behavior); Software deployment; Cluster analysis; Embedding; False positive paradox; Deception","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0007787633,0.0002334695,0.0003498137,0.0003523822,0.0004903246,0.0001814013,0.0006258773,0.0001496794,0.000160098],"category_scores_gemma":[0.00007327068,0.0002348522,0.0002275497,0.0006822238,0.00002087361,0.001266437,0.0003531066,0.0001517586,0.000009670083],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.00008972456,"about_ca_system_score_gemma":0.0002952035,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0002098945,"about_ca_topic_score_gemma":0.0001223915,"domain_scores_codex":[0.9978467,0.0001113853,0.0009796201,0.0003686619,0.000321369,0.0003722378],"domain_scores_gemma":[0.9983153,0.0002149306,0.0003032298,0.0005356539,0.0005476072,0.00008329243],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.00001184486,0.0002677905,0.0005820455,0.0001412413,0.0000728513,5.504892e-7,0.01232347,0.002112086,0.001035956,0.8427579,0.002577817,0.1381164],"study_design_scores_gemma":[0.0008542297,0.00007275558,0.0003511529,0.0001067663,0.00006084641,0.000003258045,0.001428435,0.9667899,0.02407329,0.004697322,0.001316968,0.0002450988],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.01675225,0.0001014268,0.9723228,0.0006992231,0.001086246,0.0006607689,0.00002674792,0.00006374263,0.008286841],"genre_scores_gemma":[0.4648671,0.00001207199,0.5318789,0.001009201,0.00004502543,0.0001033912,0.00001698703,0.000006985777,0.002060288],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.9646778,"threshold_uncertainty_score":0.9576994,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.04822382601698685,"score_gpt":0.3875374557637846,"score_spread":0.3393136297467977,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}