Scientific Reports· 2026Q1
Dönüştürücü Ağlar, İç Tehdit Oturum Kaçırmayı %1,3 Hata Oranıyla Tespit Ediyor
Behavioural biometrics-based continuous authentication using transformer networks for detecting insider-threat session hijacking
- 0atıf
- Q1SCImago
- 2026yıl
Kısa özet
Bir Dönüştürücü ağı, tuş vuruşu dinamikleri aracılığıyla iç tehdit oturum kaçırmayı tespit etmede %1,3'lük eşit hata oranı (EER) elde ederek, yerleşik tespit cihazlarından (%9,3 EER) önemli ölçüde daha iyi performans gösterdi.
Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.
Ana noktalar
- Dönüştürücü ağı, iç oturum kaçırmayı tespit etmede %1,3 EER elde ederek ölçeklenmiş Manhattan (%9,3), CNN (%2,1) ve RNN (%3,1) tespit cihazlarından daha iyi performans gösterdi.
- Model, %1 meşru kullanıcı yanlış alarm oranında yaklaşık beş davacı eylemi içinde oturum kaçırmaların %99,7'sini tespit ediyor.
- Kimlik doğrulama doğruluğu, eylemlerin kayan penceresinin boyutuyla monotonik olarak artar.
- Temel yenilik, yeni bir dikkat mekanizmasında değil, pencereli eylem-jeton formülasyonunda ve operasyonel değerlendirmede yatmaktadır.
Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.
Özet (abstract)
Abstract Insider threats, in which a legitimate user’s already-authenticated session is taken over by another enrolled individual, evade one-time login authentication because the session is trusted before the takeover occurs. Continuous authentication, which re-verifies the user throughout a session from behavioural signals, is a natural defence. We study behavioural-biometric continuous authentication from keystroke dynamics and ask whether a Transformer network can detect insider session hijacking more reliably than established detectors. Using the public CMU keystroke-dynamics benchmark of 51 users, we frame each password repetition as an action token and authenticate over a sliding window of consecutive actions, training a Transformer encoder that attends across the window. On held-out later sessions, the Transformer attains an equal error rate of $$1.3\%$$ , compared with $$9.3\%$$ for a strong scaled-Manhattan detector, and it outperforms convolutional and recurrent neural baselines ( $$2.1\%$$ and $$3.1\%$$ ). Casting insider attack as an abrupt mid-session hijacking, the Transformer detects $$99.7\%$$ of takeovers at a $$1\%$$ genuine-user false-alarm rate within about five impostor actions, versus 80– $$88\%$$ for the statistical detectors. We further show that authentication accuracy improves monotonically with window size, visualise the learned user-discriminative representation, and document a template-aging effect across sessions that motivates adaptive thresholds. An ablation shows that the gain arises chiefly from the learned per-action representation and its pooling rather than from Transformer-specific sequence modelling, and we position the contribution accordingly: the novelty of this work lies in the windowed action-token formulation of insider hijacking and in its operational evaluation, not in a new attention mechanism. We also state plainly what the study does not establish. The evaluation is fixed-text, closed-set, and simulates an abrupt takeover; operating points are selected retrospectively on held-out traffic and therefore upper-bound what a prospectively calibrated deployment would achieve. We specify, and release, an adaptive-threshold and template-refresh procedure for deployment, and analyse action segmentation, multimodal extension, usability, and system-level cost, but we do not claim empirical validation of these under free-text, open-set, or adaptive-adversary conditions.
Yazarların özeti; kaynağından alınmıştır. Scientific Reports, 2026 · DOI ↗
Ücretsiz hesapla devam et
Makaleye Sor ile bu makaleye günde 3 soru ücretsiz; makaleyi kaydet, kaynakçasını al, ilgi alanına göre her gün yeni özetler. Çıkarımlar Premium.
Web'de ücretsiz devam etGoogle ya da Apple hesabınla giriş; kart istemez. Bu makaleye geri dönersin.
Telefonda:
Alan: Bilişim Sistemleri
Information SystemsComputer Science