Skip to main navigation Skip to search Skip to main content

Privacy-Preserving Insider Threat Detection via Federated Learning and Behavioural Feature Engineering

  • Nimra Abbasi

Student thesis: Master's Thesis

Abstract

Insider threats represent one of the most critical and difficult cybersecurity risks facing modern organisations, as malicious insiders can exploit legitimate access to sensitive systems while evading traditional detection mechanisms. Existing centralised machine learning approaches require sensitive behavioural data to be aggregated in one place, creating privacy concerns, regulatory risks, and single points of failure that make them impractical in distributed organisational environments. This thesis aims to design, implement, and evaluate a Privacy-Preserving Insider Threat Detection (PPITD) approach that achieves high detection performance without centralising sensitive user data by combining federated learning, differential privacy, and deep neural network-based behavioural analysis. The PPITD approach applies advanced feature engineering across heterogeneous behavioural data sources, including email, logon, device, file, HTTP, and psychometric records from the CERT insider threat dataset. A deep neural network incorporating attention mechanisms, residual connections, and focal loss is trained in a federated setting across 10 simulated organisational clients over 25 communication rounds. Privacy is strengthened through differential privacy noise injection (ε=1.0, δ=10⁻⁵) and secure aggregation, meaning that raw behavioural data is not required to leave local client environments during training. The results show that PPITD achieves 99.33% accuracy and 94.74% F1-score on the CERT dataset, while still operating in a distributed and privacy-preserving setting. Under differential privacy constraints, the model retains 90.0% accuracy, demonstrating a practical privacy-utility balance. The federated model also converges rapidly, reaching 98.9% accuracy by communication round 12. Comparative evaluation against traditional machine learning techniques and some existing works shows that PPITD delivers competitive performance while preserving privacy more effectively than non-private baselines. Overall, the findings suggest that federated learning with differential privacy is a viable privacy-preserving alternative for insider threat detection in distributed organisational environments.
Date of Award1 Jun 2026
Original languageEnglish
SupervisorMohammed Al-Mhiqani (Main Supervisor) & Shamaila Iram (Co-Supervisor)

Cite this

'