{"id":"W4417470884","doi":"10.1109/iccst63435.2025.11293461","title":"Explicit Behavioral Embedding Method for Generating Explanations of Insider Threat Events","year":2025,"lang":"","type":"article","venue":"","topic":"Information and Cyber Security","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Waterloo","funders":"","keywords":"Insider threat; Insider; Anomaly detection; Transparency (behavior); Software deployment; Cluster analysis; Embedding; False positive paradox; Deception","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001362327,0.001253936,0.0003926123,0.002424794,0.0003383044,0.0008036673,0.001106371,0.0009898923,0.003716918],"category_scores_gemma":[0.01082789,0.0003457113,0.00102474,0.001126483,0.0004976331,0.002262208,0.001291133,0.001811087,0.0005387017],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006715897,"about_ca_system_score_gemma":0.001075504,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.002498459,"about_ca_topic_score_gemma":0.006385573,"domain_scores_codex":[0.999074,0.0003857034,0.00006362672,0.0002154347,0.00021217,0.00004914516],"domain_scores_gemma":[0.9927532,0.005246375,0.0005967554,0.0007606828,0.0005160101,0.0001269838],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0004858419,0.0007735699,0.0350934,0.0009969476,0.0004270448,0.0009774505,0.001987963,0.214553,0.01450804,0.1028093,0.01702762,0.6103598],"study_design_scores_gemma":[0.00002557306,0.00006190118,0.001601821,0.00004245141,0.00004551154,0.0001111859,0.0001192119,0.934738,0.003201627,0.05623104,0.003798577,0.00002311988],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.02648604,0.0001595689,0.9661904,0.0004363194,0.00003306447,0.000119774,0.001308664,0.00419003,0.001076156],"genre_scores_gemma":[0.4546868,0.0001944313,0.5388709,0.0001686097,0.00005095357,0.0002786127,0.004056415,0.0002755785,0.00141768],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003716918,"threshold_uncertainty_score":0.0124343,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.04822382601698685,"score_gpt":0.3875374557637846,"score_spread":0.3393136297467977,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}