Author

N. Prashanthi

1 paper indexed here

Fetches their full publication history.

Not the right person? Other researchers publish under this name.

Open access Jul 2026

Hybrid GCN Framework for Insider Threat Detection with Reduced False Alarms

Among the most consequential vulnerabilities in contemporary IoT-based systems is the insider threat — a class of attack in which authorised users deliberately or inadvertently misuse their privileges, often evading detection for prolonged intervals. Mainstream detection approaches continue to be undermined by three unresolved obstacles: severe class imbalance between benign and malicious records, the curse of dimensionality arising from rich feature sets, and the non-stationary nature of user behavioural profiles. To address these co-occurring challenges within a unified architecture, this work proposes a graphstructured detection framework underpinned by a Graph Convolutional Network (GCN). Relational dependencies among users, devices, and system resources are encoded as graph topology, enabling the model to capture interaction-driven threat indicators that scalar feature vectors cannot represent. Improved Principal Component Analysis (IPCA) performs dimensionality reduction while maximising the retention of discriminative variance. An Outlier-Resistant K-Means algorithm segments the activity space into semantically coherent clusters, and the Enhanced Bidirectional Generative Adversarial Network (EBiGAN) synthesises statistically faithful malicious samples to redress class skew. Hyperparameter optimisation is conducted via Bayesian search guided by the Probability of Improvement (PI) acquisition function. On the CMU CERT benchmark, the proposed system achieves a detection accuracy of 96.8%, a detection rate of 96.7%, and a false alarm rate of only 3%, outperforming all compared baselines and demonstrating readiness for deployment in production IoT security environments.

Dr. M. Muni Babu, E. Divya, K. Bhavana et al. · 0 citations