arXiv AI By Firdous Kausar, Asmah Muallem, Naw Safrin Sattar, Mohamed Zakaria Kurdi

A Hybrid Insider Threat Detection Framework Combining Multi-Agent Simulation, Layered SIEM Correlation, and Theory-of-Mind Reasoning

Read the original on arXiv AI →

The paper introduces a hybrid insider threat detection framework that combines multi-agent simulation, layered SIEM correlation, trust‑adaptive thresholds, behavioral and communication forensics, and Theory‑of‑Mind reasoning. It evaluates four variants—Layered SIEM‑Core, Cognitive‑Enriched SIEM, Evidence‑Gated SIEM, and an Enron‑calibrated version—showing progressively higher actor‑level F1 scores and reduced false positives, especially with evidence gating. Domain‑shift tests reveal that an Enron‑trained email classifier does not transfer to other domains, but fine‑tuning achieves high F1, and scalability tests confirm stable performance up to 1,000 agents.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Sep 25

On the Effectiveness of Kernel-Level Evidence for Agent Security

The paper introduces the Agent Cross‑Layer Evidence (ACE) corpus, pairing application‑level telemetry with kernel‑level syscall traces to study agent security. It shows that kernel evidence alone is discriminative and that combining it with application‑level data outperforms either layer alone, revealing complementary signals. The study also demonstrates that this cross‑layer approach generalizes to unseen attack families and works across different agent runtimes.

By Spencer King, Zhilu Zhang, Mikhail Kuznetsov, Kay Liu, Baris Coskun, Wei Ding
arXiv AI
Jun 17

An AI Security Agent for Banking: Multi-Vector Fraud and AML Detection Across Retail and Corporate Accounts

arXiv:2606. 17555v1 Announce Type: cross Abstract: Banks simultaneously face signature-based fraud (card-not-present attacks, account takeover, ATM cloning) and behavioural financial crime (structuring, layering, mule networks, business email compromise) -- two threat families with fundamentally different detection requirements.

By Joseph Walusimbi, Joshua Benjamin Ssentongo
arXiv Machine Learning
Jul 31

Cybersecurity Detection Classification with Reasoning-enabled Language Models

arXiv:2607. 28460v1 Announce Type: new Abstract: A major issue in Security Operations Centers (SOCs) is alert fatigue, as the number of detections reported is more than staff can triage in a given day.

By Amol Khanna, Manu Nandan, Cristian Viorel Popa, Joan Pujol-Roig, Diana Bolocan, Laura Vasilie, Alexandru Apostu, Chase Helwig, Mihaela Gaman, Michael Brautbar, Edward Raff, Chase Midler, Sven Krasser