A content-aware self-supervised and RL-based DDQN framework for insider cyberthreat detection under a zero trust architecture
Yasir Ahmed Hamza, Najla Badie Al Dabagh · International Journal of Computers and Applications · 2026
In this study, we propose a new insider cyberthreat detection (ICD) framework called CMS-DDQN. The CMS-DDQN model is also integrated with ZTA in order to provide adaptive insider cyber defence. Additionally, the proposed framework combines multimodal behavioral analytics, semantic content representations, and RL – based decision-making in order to support a unified pipeline that is capable of performing detection, decision, and mitigation. The semantic embeddings extracted from file, email, and HTTP content using SBERT are compressed through self-supervised autoencoders to generate compact latent representations that are able to capture both behavioral semantics and contextual information. Accordingly, the agent learns adaptive access control policies within a custom ZT environment through four security actions: allow, limited access, escalation, and denial. Based on the experimental results, the evaluation on the CERT r6.2 dataset indicates that our CMS-DDQN framework is capable of achieving strong detection capability with 0.9947 accuracy, 0.9660 recall, 0.9328 precision, an F1-score of 0.9491, and an AUC of 0.9988. These findings indicate that the CMS-DDQN model has near-perfect discrimination between malicious and benign behaviors. The results also demonstrate that integrating semantic content awareness, self-supervised representation learning, and RL-based policy optimization significantly improves detection robustness and enables adaptive ZT enforcement.