DDCC: Synergizing Denoising Diffusion Probabilistic Models and Curriculum-Based Complexity Control for Insider Threat Detection
Jiankuo Dong, Jie Wei, Xiaoyu Hu, Zhenjiang Dong, Fuyuan Chen, Xin Yu Hu, Jin Qi · IEEE Transactions on Industrial Informatics · 2025
Insider threat detection aims to identify malicious activities by employees that may compromise the confidentiality, integrity, or availability of organizational data. Detecting insider threats poses unique challenges compared to external threats, as internal actors often possess authorized system access and familiarity with organizational systems, enabling them to execute attacks discreetly. This article presents a novel approach to insider threat detection, synergizing denoising diffusion probabilistic models (DDPM) with a curriculum-based complexity control strategy (DDCC). While DDPM has shown promise in anomaly detection, its application to insider threat detection remains relatively unexplored. The proposed approach leverages DDPM for context-aware behavioral modeling and anomaly scoring. The methodology encompasses three primary components: First, employee behavioral logs undergo fusion to aggregate context information across various time scales. Second, a curriculum learning module controls the training process, gradually exposing the model to increasingly complex samples. The training data organization progresses from simple to complex sequences, facilitating more effective feature learning. Third, the denoising diffusion probabilistic model reconstructs the fused employee behavioral sequences for anomaly detection. Experimental validation on the CMU CERT r5.2 and r6.2 datasets demonstrates robust performance in insider threat detection across multiple time granularities of aggregated employee logs. The results underscore the effectiveness of this approach in addressing the nuanced challenges associated with detecting internal threats, highlighting its potential for real-world deployment in organizational security frameworks.