Deep Vision Guard: Insider Threat Detection Via Deep Learning-Enhanced Image Forensics

Authors

  • Sourav Kumar Upadhyay
  • Dr. Subhash Chandra Dutta

Keywords:

Insider Threat Detection; Deep Learning; Behavioral Image Forensics; CNN–BiLSTM–Attention; Explainable Artificial Intelligence

Abstract

Insider threats remain difficult to detect because malicious activities are often embedded within legitimate organizational behavior and conventional monitoring may overlook subtle temporal deviations. This research introduces DeepVisionGuard, a deep learning-supported behavioral image-forensics framework to discriminate an anomalous insider from a normal cybersecurity event. A total of 71,965 events were cleaned from the SPEDIA dataset and converted into 5,212 chunks of behavioral-image data, each containing a fixed sequence of 32 events, with the help of 84 engineered features. The main architecture was based on CNN for spatial feature extraction, BiLSTM for temporal modelling, and attention, and Grad-CAM and temporal-attention analysis were used for interpretability. In 733 independent test chunks, the directly supervised model had 14 false positives and 14 false negatives and achieved an accuracy of 96.18%, an F1-score of 0.9451, an MCC of 0.9158, an ROC-AUC of 0.9912 and a PR-AUC of 0.9872. The ablation results indicated that by removing the CNN-only part, the performance was significantly lower, while the addition of attention was not statistically significantly better than CNN–BiLSTM, confirming that the CNN-only part was essential and critical to the model's performance. Gains in description were not significant and were small in a secondary experiment that was unsupervised-pretrained. Overall, DeepVisionGuard demonstrates that behavioral-image representation combined with temporal modelling can support accurate, leakage-aware, and interpretable insider-threat detection, while future work should examine cross-organizational validation, sparse anomaly scenarios, richer threat labels, and real-time analyst-assisted deployment.

Downloads

Published

2026-09-05

How to Cite

Upadhyay, S. K., & Dutta, D. S. C. (2026). Deep Vision Guard: Insider Threat Detection Via Deep Learning-Enhanced Image Forensics. International Journal of Artificial Intelligence and Machine Learning, 6(9s), 1275–1286. Retrieved from https://www.svedbergopen.com/index.php/ijaiml/article/view/1581