A Bayesian Correlated Equilibrium for Early Insider-Threat Detection

📅 2026-09-02
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文通过构建一个基于贝叶斯时间相关均衡的动态博弈模型,协调认证者检测内部威胁,比理性基线提前1.7-4.5天发现恶意行为。
📝 Abstract
We model insider threat detection as a dynamic Bayesian game in which a platform coordinates a committee of strategic certifiers to sustain equilibrium among honest users and detect malicious deviations before exfiltration. Certifiers and users operate under a Bayesian Temporal Correlated Equilibrium (BTCE), where a sealed-envelope correlating device issues private recommendations over time and obedience is verified at every on-path information state. Unlike Stackelberg formulations, BTCE coordinates heterogeneous certifiers without requiring commitment power. We incorporate present bias and loss aversion to capture impulsive escalation dynamics, enabling 1.7--4.5 days earlier detection than rational baselines. We prove three guarantees: (1) calibrated intervention losses make recommended behavior a current-self best response despite behavioral biases, (2) controlled evidence accumulation guarantees intervention in bounded expected time before exfiltration, and (3) median aggregation confines implemented actions to the honest recommendation range when fewer than half of certifiers are Byzantine. On CERT r6.2 our mechanism achieves up to 28.3% pre-exfiltration detection with false positives below 1.6%, while both a transformer baseline and a streaming provenance approximation (HOLMESLite) achieve near-zero pre-exfiltration detection under comparable constraints.
Problem

Research questions and friction points this paper is trying to address.

insider threat detection
dynamic Bayesian game
Bayesian Temporal Correlated Equilibrium
honest users
malicious deviations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Bayesian Temporal Correlated Equilibrium (BTCE)
Early Detection
Behavioral Biases
Calibrated Intervention Losses
Median Aggregation
🔎 Similar Papers
No similar papers found.
J
Javed M. Shah
University of Illinois Chicago, Chicago, United States
I
Ian A. Kash
University of Illinois Chicago, Chicago, United States
Natalie Parde
Natalie Parde
University of Illinois Chicago
Natural Language ProcessingArtificial Intelligence