LLM4ITD: Insider Threat Detection with Fine-Tuned Large Language Models

Meiou Zhang,Xinru Liang,Feng Tian,Yuting Yang,Honglan Yu,Bo Li
DOI: https://doi.org/10.1109/iist62526.2024.00017
2024-01-01
Abstract:Recently, insider threat detection has been an important means to ensure data security. By analyzing user logs and finding significant deviations, existing methods have obtained some achievements. However, they still use handcrafted rules to transform logs into specific input forms, which is time-consuming and requires prior knowledge. Moreover, they extensively depend on a substantial amount of labeled malicious data which is hard to obtain. To address these identified issues, this paper proposes to use Large Language Models for Insider Threat Detection (LLM4ITD). Prompt construction module designs a new template to guide LLM4ITD in identifying potential malicious activities without specific rules. The fine-tuning module adopts parameter-efficient methods to fine-tune LLM4ITD, thus improving the accuracy of insider threat detection with limited labeled data. Extensive experiments on the CERT dataset demonstrate that LLM4ITD outperforms various state-of-the-art methods.
What problem does this paper attempt to address?