Scientific Reports· 2026Q1
Behavioural biometrics-based continuous authentication using transformer networks for detecting insider-threat session hijacking
- 0citations
- Q1SCImago
- 2026year
Short summary
A Transformer network achieved a 1.3% equal error rate (EER) in detecting insider session hijacking via keystroke dynamics, significantly outperforming established detectors (9.3% EER).
AI-generated from the title and abstract; the full text is not read.
Key points
- Transformer network achieved 1.3% EER for insider session hijacking detection, outperforming scaled-Manhattan (9.3%), CNN (2.1%), and RNN (3.1%) detectors.
- The model detects 99.7% of takeovers within approximately five impostor actions at a 1% genuine-user false alarm rate.
- Authentication accuracy improves monotonically with the size of the sliding window of actions.
- The primary novelty lies in the windowed action-token formulation and operational evaluation, not a new attention mechanism.
AI-generated from the title and abstract; the full text is not read.
Abstract
Abstract Insider threats, in which a legitimate user’s already-authenticated session is taken over by another enrolled individual, evade one-time login authentication because the session is trusted before the takeover occurs. Continuous authentication, which re-verifies the user throughout a session from behavioural signals, is a natural defence. We study behavioural-biometric continuous authentication from keystroke dynamics and ask whether a Transformer network can detect insider session hijacking more reliably than established detectors. Using the public CMU keystroke-dynamics benchmark of 51 users, we frame each password repetition as an action token and authenticate over a sliding window of consecutive actions, training a Transformer encoder that attends across the window. On held-out later sessions, the Transformer attains an equal error rate of $$1.3\%$$ , compared with $$9.3\%$$ for a strong scaled-Manhattan detector, and it outperforms convolutional and recurrent neural baselines ( $$2.1\%$$ and $$3.1\%$$ ). Casting insider attack as an abrupt mid-session hijacking, the Transformer detects $$99.7\%$$ of takeovers at a $$1\%$$ genuine-user false-alarm rate within about five impostor actions, versus 80– $$88\%$$ for the statistical detectors. We further show that authentication accuracy improves monotonically with window size, visualise the learned user-discriminative representation, and document a template-aging effect across sessions that motivates adaptive thresholds. An ablation shows that the gain arises chiefly from the learned per-action representation and its pooling rather than from Transformer-specific sequence modelling, and we position the contribution accordingly: the novelty of this work lies in the windowed action-token formulation of insider hijacking and in its operational evaluation, not in a new attention mechanism. We also state plainly what the study does not establish. The evaluation is fixed-text, closed-set, and simulates an abrupt takeover; operating points are selected retrospectively on held-out traffic and therefore upper-bound what a prospectively calibrated deployment would achieve. We specify, and release, an adaptive-threshold and template-refresh procedure for deployment, and analyse action segmentation, multimodal extension, usability, and system-level cost, but we do not claim empirical validation of these under free-text, open-set, or adaptive-adversary conditions.
The authors' abstract, as published at the source. Scientific Reports, 2026 · DOI ↗
Continue with a free account
Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.
Continue free on the webSign in with Google or Apple; no card needed. You come back to this paper.
On your phone:
Field: Information Systems
Information SystemsComputer Science