A Privacy-Aware Federated Learning Approach for Insider Threat Detection

Nimra Mazhar Abbasi, Mohammed Al-Mhiqani, Hussain Al-Aqrabil, Samer Aoudi · 2025

Insider threats pose critical risks to organisational security, yet existing detection methods face challenges related to privacy, class imbalance, and heterogeneous data distributions. Centralised approaches often compromise sensitive information, limiting cross-organisational collaboration. This paper introduces a privacy-aware insider threat detection approach based on federated learning (FL) with advanced feature engineering and differential privacy. The proposed approach employs a neural architecture with residual connections, multi-head attention, and focal loss to capture complex behavioral patterns from diverse sources, including email, logon activity, device usage, HTTP traffic, file operations, and psychometric data. Local Synthetic Minority Oversampling Technique (SMOTE) oversampling mitigates class imbalance, while behavioral clustering addresses data heterogeneity. Secure aggregation with differential privacy ensures configurable privacy-utility trade-offs. Experiments on the CERT dataset demonstrate that the proposed approach achieves high precision, recall, and F1-score, outperforming existing FL methods while maintaining fairness across clients and strong privacy guarantees.

Read the paper · More papers on PaperTik