A Hybrid Insider Threat Detection Framework Combining Multi-Agent Simulation, Layered SIEM Correlation, and Theory-of-Mind Reasoning

arXiv:2601.04243 · cs.CR, cs.AI · Submitted 2026-01-06 · Read on arXiv

cs.CR, cs.AI

Submitted: 2026-01-06

Updated: 2026-09-01

Comments: v2: Substantially revised and extended version with new experimental results, additional evaluation, and expanded analysis. The title has been updated to reflect the revised scope of the manuscript

Code: https://github.com/firdous3679/Insider-Threat-Detection-MAS-SIEM

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Terminology

Related papers