An Adaptive Insider Threat Detection Framework Using Causal Analysis and Liquid Neural Networks

Ambairam Muthu Sivakrishna, R. Mohan, Sai Keerthana Anumandla · Security and Privacy · 2025

ABSTRACT Insider threats are still a significant security concern for the majority of organizations, as malicious insiders often act like actual individuals. Current machine learning, deep learning, graph‐based, and hybrid methods have trouble with diversity of data, class imbalance, inaccurate classifications and sensitivity to feature granularity. These limitations make it less useful in real life, especially when minority insider classes are misclassified. In these situations, accuracy alone is not enough in these scenarios. The F1‐score reflects the balance between precision and recall, thereby ensuring that the model not only reduces false positives but also correctly identifies true insiders. This research introduces an adaptive framework that combines causal inference with Median Absolute Deviation (MAD) refinement to preserve causally significant, stable predictors prior to temporal modeling via Liquid Neural Networks (LNN). Experiments were conducted on the Carnegie Mellon University (CMU) CERTr4.2 dataset using three feature granularities like session, day, and behavioral inputs. Session‐wise Preprocessing representation achieved the best results, with 97.98% accuracy, 97.30% precision, 98.71% recall, 98.00% F1‐score, ROC‐AUC of 99.6, and False Positive Rate (FPR) below 2.4%. Th different user experiments have verified the system's adaptability, as the Session‐wise Preprocessing tests have led to an accuracy of 95.77% and an F1‐score of 95.29%. Cross‐dataset experiments involving the training of the model on r4.2 and testing it on r5.2 and r6.2 were carried out, thus indicating solid generalization with F1‐scores close to 93% in spite of the changes in the dataset. Scalability experiments across different data ratios confirmed that the model maintained consistent performance regardless of dataset size. Ablation studies confirmed the necessity of the proposed pipeline, and statistical tests verified that the improvements were consistent and significant. In conclusion, the proposed method addresses key challenges of insider threat detection by delivering balanced precision and recall, and demonstrating robustness, scalability, and strong generalization across datasets and unseen users.

Read the paper · More papers on PaperTik