Electronic Thesis/Dissertation
 

Large Language Models – Towards User Behavior Modeling for Intrusion Detection

Open Access Deposited

Large Language Models – Towards User Behavior Modeling for Intrusion Detection Insider threats are a persistent challenge because they exploit legitimate access, and they often appear to be routine activity. Traditional defenses, such as rule-based systems and tree-based classifiers, have trouble with temporal patterns, which results in high false-positive rates that create alert fatigue in analysts. This study examines the potential of sequence models to improve anomaly detection, and the productivity gains that language models can bring through explanation and scenario classification, towards the aim of strengthening analyst usability in the detection of insider threats on corporate networks.This work addresses four key points. First, Long Short-Term Memory (LSTM) autoencoders and LSTM with attention are compared to Isolation Forest and Local Outlier Factor and evaluated on metrics such as Area Under the Curve (AUC), F-Score (F1), precision, recall, and false-positive rate. We then look to the role of interpretability features like attention weights, feature attributions, and counterfactual examples for reducing analyst effort. A simple Interpretability Burden Score (IBS) and attribution consistency in the sense that categories of malicious activities display similar characteristics will act as proxies for cognitive effort. Thirdly, explanations are linked to end-to-end detection delay, defined as the time from the first anomalous action to an actionable alert, which is estimated by combining model latency with a simulated review time derived from IBS and finally, large language models are tested for classifying alerts into higher-level insider scenarios, such as Intellectual Property Theft, Fraud, and IT Sabotage, using zero-shot and one-shot prompting. We find that sequence models outperform traditional baselines, and that language models help by producing explanations and scenario labels acting as co-pilots, resulting in shorter detection delays, lower workload, and enriched context.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Ningaiah_gwu_0075A_17713.pdf Ningaiah_gwu_0075A_17713.pdf 2025-12-15 Open Access