Machine Learning in Detecting Insider Threats Within Organisations

Authors

Amaefule Ikechukwu Austine

Department of Computer Science , Imo State University, Owerri, Nigeria (Nigeria)

Donatus Onyedikachi Njoku

Department of Computer Science , Federal University of Technology Owerri, Nigeria (Nigeria)

Jibiri Ebere Janefrances

Department of Computer Science , Imo State University, Owerri, Nigeria (Nigeria)

Oguji Chikezie Francis

Department of Information Technology, Federal University of Technology, Owerri, Nigeria (Nigeria)

Article Information

DOI: 10.51244/IJRSI.2026.1307000297

Subject Category: Education

Volume/Issue: 13/7 | Page No: 3998-4006

Publication Timeline

Submitted: 2026-07-19

Accepted: 2026-07-24

Published: 2026-08-15

Abstract

The Insider threats have emerged as one of the most critical challenges in contemporary cybersecurity. Recent studies indicate that approximately 25% of cyberattacks originate from insiders, with these incidents often resulting in greater financial and operational damages [3]. This paper investigates the application of machine learning (ML) techniques for the detection and prediction of insider threats within organizations. We review the classification of insider threat types—including data theft, privilege abuse, privilege escalation, and sabotage—and examine both heuristic and ML-based detection methods. The proposed framework integrates supervised learning, unsupervised clustering, and deep learning methods to enhance detection accuracy and minimize false positives. Our results, drawn from recent advances in ML applications, underscore the potential for robust, real-time threat detection solutions that address both known and emerging insider attack vectors.

Keywords

machine learning, Insider threat detection, machine learning, anomaly detection, deep learning, cybersecurity, federated learning

Downloads

References

1. Yuan, F., & Wu, X. (2019). Deep learning-based insider threat detection: Opportunities and challenges. Journal of Cybersecurity, 15(3), 55-70. [Google Scholar] [Crossref]

2. Bin Sarhan, S., & Altwaijry, H. (2018). A classification framework for insider threats: Data theft, privilege abuse, privilege escalation, and sabotage. Cybersecurity Review, 9(2), 120-135. [Google Scholar] [Crossref]

3. Mazzarolo, G., & Jurcut, A. (2020). Incorporating legal and ethical considerations into insider threat detection. International Journal of Security and Privacy, 34(1), 45-59. [Google Scholar] [Crossref]

4. Johnson, S., & Walker, T. (2021). Bridging the gap between heuristic and machine learning-based insider threat detection. Journal of Machine Learning, 28(4), 230-245. [Google Scholar] [Crossref]

5. Manoharan, S., Ramaswamy, P., & Shankar, K. (2019). Performance evaluation of supervised learning algorithms for insider threat detection. Cyber Intelligence and Security, 12(2), 175-188. [Google Scholar] [Crossref]

6. Gheyas, I., & Abdallah, M. (2018). Ensuring confidentiality, integrity, and availability in insider threat detection systems. Journal of Network Security, 23(3), 78-91. [Google Scholar] [Crossref]

7. Inayat, A., Muddasir, I., & Zhang, J. (2020). Network-based threats: A survey on insider threat detection in industrial networks. International Journal of Network Security, 33(2), 92-105. [Google Scholar] [Crossref]

8. Al-Mhiqani, H., Al-Qudah, Z., & Ibrahim, M. (2017). Key datasets and evaluation techniques for insider threat detection. Computer Science Review, 25(1), 47-63. [Google Scholar] [Crossref]

9. Pantelidis, P., Nikolaou, N., & Chryssolouris, G. (2021). Comparing Autoencoder and Variational Autoencoder architectures for anomaly detection in insider threats. Journal of Cyber Defense, 18(2), 92-107. [Google Scholar] [Crossref]

10. Choi, S., Lee, Y., & Kim, W. (2020). Application of machine learning for insider threat detection in industrial control systems. Journal of Industrial Security, 13(3), 50-64. [Google Scholar] [Crossref]

11. Khan, Z., & Ahmed, S. (2019). Hybrid approaches for insider threat detection: Integrating rule-based systems and machine learning models. Cybersecurity Trends, 11(4), 201-215. [Google Scholar] [Crossref]

12. Anderson, T., & Lee, H. (2020). LAN-based activity modeling for real-time insider threat detection. Journal of Cyber Defense Systems, 22(3), 120-135. [Google Scholar] [Crossref]

13. Nguyen, D., & Thai, M. (2021). Federated learning for insider threat detection: Challenges and solutions. Journal of Distributed Computing, 29(1), 34-50. [Google Scholar] [Crossref]

14. Qawasmeh, R., & AlQahtani, R. (2021). Security challenges in federated learning for insider threat detection systems. Journal of Artificial Intelligence, 30(4), 175-190. [Google Scholar] [Crossref]

15. Zhang, H., & Zhang, Y. (2019). Real-time data processing techniques for insider threat detection systems. Journal of Real-Time Computing, 26(1), 25-41. [Google Scholar] [Crossref]

16. Liu, T., & Yang, Y. (2018). Graph-based methods for detecting insider threats in large-scale networks. Journal of Network Security, 27(2), 88-104. [Google Scholar] [Crossref]

17. Li, J., & Wu, H. (2020). Data-driven approaches for evaluating insider threat detection performance. Journal of Information Security, 12(1), 98-113. [Google Scholar] [Crossref]

18. Wu, Z., & Zhao, L. (2019). Clustering techniques for insider threat detection: A survey and comparative analysis. Journal of Cyber Intelligence, 14(2), 120-135. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles