arrow
Return

Rule-Based Learning for Explainable XGBoost Internal Threat Detection

delete2026-01-01
delete0
PRE
AI
Y
Yaying Qiu
L
Lijuan Sun *
J
Jingchen Wu
G
Gao, Yutong
J
Jincui Yang
DOI:10.1007/978-3-031-97352-9_28delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In the field of data security, internal threat detection is a critical issue due to its complexity and stealthiness. This paper proposes an explainable method for internal threat detection based on rule learning with XGBoost. Firstly, the XGBoost model is used to extract features from user behavior data and generate initial decision rules. These rules are then processed, filtered, and optimized to construct a subset of rules. Finally, this subset of rules is used as input features to build a penalized logistic regression model, enhancing the interpretability and accuracy of the model. Experimental results show that the proposed method achieves a 96.7% accuracy rate on the CMU-CERT dataset. The method demonstrates decision rationale through interpretable rules, improving the understanding and trust in the detection results.
Keywords:
Internal Threat Detection
Rule Extraction
Interpretability

Journal

D
DATA INFORMATION IN ONLINE ENVIRONMENTS, DIONE 2024
IF:
0
Papers:
25
Citations:
0

Organization

B
beijing university of posts & telecommunications
Scholars:
1.4W
Papers: 1.2W
Citations: 9