arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于早期内部威胁检测的贝叶斯相关均衡

A Bayesian Correlated Equilibrium for Early Insider-Threat Detection

Javed M. Shah, Ian A. Kash, Natalie Parde

arXiv 2609.03096首次发表:更新:

发表机构

University of Illinois Chicago(伊利诺伊大学芝加哥分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出贝叶斯时间相关均衡(BTCE)机制,将内部威胁检测建模为动态贝叶斯博弈,在CERT r6.2数据集上实现28.3%的外泄前检测率,早于理性基准1.7至4.5天。

AI 中文摘要

我们将内部威胁检测建模为动态贝叶斯博弈,其中平台协调一组具有策略性的验证者,以维持诚实用户之间的均衡,并在数据外泄前检测恶意偏离行为。验证者和用户在贝叶斯时间相关均衡(BTCE)下运作,其中密封信封式相关设备随时间发布私人建议,且在每个路径上的信息状态下都会验证服从情况。与斯塔克尔伯格(Stackelberg)公式不同,BTCE无需承诺能力即可协调异构验证者。我们引入当前偏差和损失厌恶来捕捉冲动升级动态,相比理性基准,这能实现早1.7至4.5天的检测。我们证明了三项保证:(1)校准的干预损失使建议行为成为当前自我的最佳反应,尽管存在行为偏差;(2)受控证据积累保证在数据外泄前的有限预期时间内进行干预;(3)当中少于一半的验证者为拜占庭节点时,中位数聚合将实施的行动限制在诚实建议范围内。在CERT r6.2数据集上,我们的机制实现了高达28.3%的外泄前检测率,且误报率低于1.6%,而在可比约束下,Transformer基准和流式来源近似方法(HOLMESLite)的外泄前检测率接近零。

英文摘要

We model insider threat detection as a dynamic Bayesian game in which a platform coordinates a committee of strategic certifiers to sustain equilibrium among honest users and detect malicious deviations before exfiltration. Certifiers and users operate under a Bayesian Temporal Correlated Equilibrium (BTCE), where a sealed-envelope correlating device issues private recommendations over time and obedience is verified at every on-path information state. Unlike Stackelberg formulations, BTCE coordinates heterogeneous certifiers without requiring commitment power. We incorporate present bias and loss aversion to capture impulsive escalation dynamics, enabling 1.7--4.5 days earlier detection than rational baselines. We prove three guarantees: (1) calibrated intervention losses make recommended behavior a current-self best response despite behavioral biases, (2) controlled evidence accumulation guarantees intervention in bounded expected time before exfiltration, and (3) median aggregation confines implemented actions to the honest recommendation range when fewer than half of certifiers are Byzantine. On CERT r6.2 our mechanism achieves up to 28.3% pre-exfiltration detection with false positives below 1.6%, while both a transformer baseline and a streaming provenance approximation (HOLMESLite) achieve near-zero pre-exfiltration detection under comparable constraints.

CommentsAccepted in GameSec 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑