Peer Reviewed Open Access Journal
ISSN: 3139-3349
The rapid expansion of modern digital environments and cyber-physical systems has significantly increased organizational exposure to insider threats. Unlike external actors, malicious insiders operate with legitimate credentials and system access, enabling them to easily bypass static perimeter controls and traditional intrusion detection systems. To address this challenge, this paper introduces a multi-tiered Behavioral Analytics Framework for Machine-Learned Insider Threat Detection. The proposed framework continuously ingests multi-modal telemetry spanning computer-mediated linguistic communications, system access logs, and physical badge records to construct dynamic user profiles and isolate subtle behavioral anomalies. While traditional linear classifiers struggle in this domain due to high false-positive rates, tree-based gradient boosting models provide exceptional discriminative capability. In particular, XGBoost achieves superior threat sensitivity with an F_1-score of 75.5% and an AUC of 98.5%, recording the fewest false negatives overall. By integrating these gradient boosting dynamics into an optimized voting ensemble core, the proposed framework achieves a peak classification accuracy of 98.3%, an AUC of 98.5%, and an F_1-score of 98.2%, while constraining False Acceptance (FAR) and False Rejection (FRR) rates to 3.1% and 2.8%, respectively. Operating with an average inference latency of 185 ms, predictive risk scores feed directly into an automated Zero-Trust enforcement engine. Augmented by Explainable AI (XAI) feature attribution modules and adversarial input defenses, the framework offers high operational transparency for analysts while maintaining resilience against insider manipulation and evasion.
Insider Threats, Cyber security, Behavioural Analysis, Machine Learning, Anomaly Detection, Data Security
Abbasi, A. R., & Mohammadi, M. (2026). Engineering a resilient smart grid: Practical defense mechanisms and deployable framework against evolving cyber-threats. Results in Engineering, 30(March), 109893. https://doi.org/10.1016/j.rineng.2026.109893
Abukeshek, M., Al-Mhiqani, M., Parkinson, S., Khan, S., & Bearfield, G. (2026). Cybersecurity in intelligent railway systems: Taxonomy, research trends, challenges, and future directions. Computers and Electrical Engineering, 132(December 2025), 110994. https://doi.org/10.1016/j.compeleceng.2026.110994
Afrin, S., Al Muttaki, M. R., Anil, A. I. A., & Hasan, S. (2026). AI-powered cybersecurity for smart grid communication: A systematic review of intrusion detection and threat mitigation systems. Energy Conversion and Management: X, 29(November 2025), 101416. https://doi.org/10.1016/j.ecmx.2025.101416
Al-Haija, Q. A., & Tamimi, S. Al. (2025). A State-of-the-Art Survey of Adversarial Reinforcement Learning for IoT Intrusion Detection. Computers, Materials & Continua, 0(0), 1–10. https://doi.org/10.32604/cmc.2025.073540
Al-Mhiqani, M. N., Alsboui, T., Al-Shehari, T., Abdulkareem, K. hameed, Ahmad, R., & Mohammed, M. A. (2024). Insider threat detection in cyber-physical systems: a systematic literature review. Computers and Electrical Engineering, 119(PA), 109489. https://doi.org/10.1016/j.compeleceng.2024.109489
Alhasnawi, B. N., Sadeq, A. M., Homod, R. Z., Hussain, F. F. K., Soběslav, V., & Bureš, V. (2026). An extensive examination of cyberattacks, cybersecurity, and energy management in smart grid, including new advancements and machine learning. Energy Conversion and Management: X, 29(December 2025). https://doi.org/10.1016/j.ecmx.2025.101471
Ali, A., Snášel, V., & Platoš, J. (2025). Health-FedNet: A privacy-preserving federated learning framework for scalable and secure healthcare analytics. Results in Engineering, 27(March). https://doi.org/10.1016/j.rineng.2025.106484
Aloraini, F., Javed, A., Rana, O., & Burnap, P. (2022). Adversarial machine learning in IoT from an insider point of view. Journal of Information Security and Applications, 70(October), 103341. https://doi.org/10.1016/j.jisa.2022.103341
Alqahtani, H., & Kumar, G. (2026). Large Language Models for Cybersecurity Intelligence: A Systematic Review of Emerging Threats, Defensive Capabilities, and Security Evaluation Frameworks. Computers, Materials and Continua, 87(3). https://doi.org/10.32604/cmc.2026.077367
Alshehri, M. (2026). Dynamic cyber deception using AI-driven adaptive honeypot networks and context-aware behavioural analysis for proactive threat neutralization. Ain Shams Engineering Journal, 17(4), 104061. https://doi.org/10.1016/j.asej.2026.104061
Asmar, M., & Tuqan, A. (2024). Integrating machine learning for sustaining cybersecurity in digital banks. Heliyon, 10(17), e37571. https://doi.org/10.1016/j.heliyon.2024.e37571
Daah, C., Fallot, Y., Qureshi, A., Awan, I., & Konur, S. (2026). AI-driven zero trust and blockchain framework for secure electric vehicle infrastructure. Expert Systems with Applications, 312(November 2025), 131577. https://doi.org/10.1016/j.eswa.2026.131577
Devi, D. P., Sethuraman, S. C., & Khan, M. K. (2025). Blockchain-based Deep Learning Models for Intrusion Detection in Industrial Control Systems: Frameworks and Open Issues. Journal of Network and Computer Applications, 243(August), 104286. https://doi.org/10.1016/j.jnca.2025.104286
Emati, J. H. M., Tchendji, V. K., & Djam-Doudou, M. (2025). Enhancing trust in machines integration with Dirichlet distribution and self-sovereign identity. Array, 28(November), 100579. https://doi.org/10.1016/j.array.2025.100579
Erfan, F., Bellaiche, M., & Halabi, T. (2026). Sybil attack defense in blockchain-based industrial IoT systems using decentralized federated learning. Internet of Things (The Netherlands), 37, 101927. https://doi.org/10.1016/j.iot.2026.101927
Inayat, U., Farzan, M., Mahmood, S., Zia, M. F., Hussain, S., & Pallonetto, F. (2024). Insider threat mitigation: Systematic literature review. Ain Shams Engineering Journal, 15(12), 103068. https://doi.org/10.1016/j.asej.2024.103068
Janjua, F., Masood, A., Abbas, H., & Rashid, I. (2020). Handling insider threat through supervised machine learning techniques. Procedia Computer Science, 177, 64–71. https://doi.org/10.1016/j.procs.2020.10.012
Jayanthiladevi, A., Natarajan, J., Arjun, K., Atlas, L. G., Arvindhan, M., & Arockiam, D. (2025). AI-Based Cybersecurity Frameworks for 7G-Enabled Virtual Therapy Platforms. Cyber Security and Applications, 100099. https://doi.org/10.1016/j.csa.2025.100099
Parashar, J., Hung, B. T., Upreti, K., Kshirsagar, P. R., Mahajan, S., & Kadry, S. (2026). An enhanced hybrid framework for IoT healthcare security using blockchain-driven multimedia data analysis and cybersecurity techniques. Array, 30(March), 100759. https://doi.org/10.1016/j.array.2026.100759
Polat, O., Durmuş, Ö., Doğan, F., Türkoğlu, M., Şeker, H., Atasoy, F., & Algül, E. (2026). Supervised and deep learning techniques for DDoS detection in software-defined network architectures: a systematic review. Engineering Science and Technology, an International Journal, 75(October 2025). https://doi.org/10.1016/j.jestch.2026.102290
Prasad, N., Diro, A., Warren, M., & Fernando, M. (2025). A survey of cyber threat attribution: Challenges, techniques, and future directions. Computers and Security, 157(October 2024). https://doi.org/10.1016/j.cose.2025.104606
Rahim, M. A., Rokonuzzaman, M., Alqumsan, A. A., Arogbonlo, A., Islam, M. Z., Trinh, H., & Islam, M. S. (2025). An intelligent and secure internet of robotic things: A review and conceptual framework. Internet of Things (The Netherlands), 33, 101684. https://doi.org/10.1016/j.iot.2025.101684
Rehman, A., Saba, T., Jamjoom, M. M., Al-Otaibi, S., & Khan, M. I. (2026). Advances in Machine Learning for Explainable Intrusion Detection Using Imbalance Datasets in Cybersecurity with Harris Hawks Optimization. Computers, Materials & Continua, 86(1), 1–15. https://doi.org/10.32604/cmc.2025.068958
Reka, S. S., Dragicevic, T., Venugopal, P., Ravi, V., & Rajagopal, M. K. (2024). Big data analytics and artificial intelligence aspects for privacy and security concerns for demand response modelling in smart grid: A futuristic approach. Heliyon, 10(15), e35683. https://doi.org/10.1016/j.heliyon.2024.e35683
S, M., & K R, J. (2025). Blockchain-IoMT-enabled federated learning: An intelligent privacy-preserving control policy for electronic health records. Array, 28(August), 100586. https://doi.org/10.1016/j.array.2025.100586
Shah, H., Muhammad, D., Almutairi, S. S., & Moteri, M. A. A. (2026). Lightweight secure communication framework with eXplainable artificial intelligence for trustworthy healthcare analytics. Machine Learning with Applications, 24(March), 100874. https://doi.org/10.1016/j.mlwa.2026.100874
Tariq, M. A., Khan, S., Mazhar, T., Shahzad, T., Arooj, S., Ouahada, K., Khan, M. A., & Hamam, H. (2026). Federated Deep Learning in Intelligent Urban Ecosystems: A Systematic Review of Advancements and Applications in Smart Cities, Homes, Buildings, and Healthcare Systems. CMES - Computer Modeling in Engineering and Sciences, 146(3). https://doi.org/10.32604/cmes.2026.078672
Umrani, M. I., Butler, B., O’ Driscoll, A., & Davy, S. (2026). Toward secure complex UAV cyber-physical systems: A unified threat taxonomy and cross-layer survey of cybersecurity challenges. Internet of Things (The Netherlands), 37(November 2025), 101902. https://doi.org/10.1016/j.iot.2026.101902
