Repository logo

Intelligent Inside Threat Detection Framework Based on Digital Twin, Transformer Variant Models, and Transfer Learning

dc.contributor.authorWang, Zhi Qiang
dc.contributor.supervisorEl Saddik, Abdulmotaleb
dc.date.accessioned2025-04-17T14:32:15Z
dc.date.available2025-04-17T14:32:15Z
dc.date.issued2025-04-17
dc.description.abstractWith the rise of networked systems and modern hacker techniques, insider threats have become a greater concern than external hackers, as they often cause more significant damage and are harder to detect due to authorized access, complex behaviors, data imbalances, and a lack of explainability. To address these challenges, we proposed DTITD, a centralized learning framework that combines Digital Twin (DT) technology and transformer models. DTITD tackles data imbalance by utilizing contextual embeddings from pre-trained Large Language Models (LLMs), and it provides insights into user behavior through Digital Twin analysis, enhancing detection explainability. Extensive experiments on CERT r4.2 (dense) and CERT r6.2 (sparse) datasets show that DistilledTrans, a customized transformer model, outperforms baseline models in accuracy, precision, recall, F1-score, and AUC, while being computationally efficient. To overcome challenges like data privacy and resource costs, we introduced FedITD, a Federated Parameter-Efficient Tuning (PETuning) framework with Federated Learning (FL) and Transfer Learning. This framework allows for decentralized model learning without data transmission, safeguarding privacy and reducing resource costs. Combining DTITD and FedITD provides a highly accurate, efficient, and privacy-preserving solution for insider threat detection at an enterprise level.
dc.identifier.urihttp://hdl.handle.net/10393/50351
dc.identifier.urihttps://doi.org/10.20381/ruor-31027
dc.language.isoen
dc.publisherUniversité d'Ottawa / University of Ottawa
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internationalen
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectDigital Twin
dc.subjectCybersecurity
dc.subjectInsider Threat
dc.subjectdeep learning
dc.subjecttransformer
dc.subjectBERT
dc.subjectRoBERTa
dc.subjectGPT
dc.subjectdata augmentation
dc.subjectartificial intelligence
dc.subjectmachine learning
dc.subjectUEBA
dc.subjectXLNet
dc.subjectDistilBERT
dc.subjectLLM
dc.subjectParameter Efficient Tuning
dc.subjectLoRA,
dc.subjectAdapter
dc.subjectBitFit
dc.subjectNLP
dc.subjectTransfer Learning
dc.titleIntelligent Inside Threat Detection Framework Based on Digital Twin, Transformer Variant Models, and Transfer Learning
dc.typeThesisen
thesis.degree.disciplineGénie / Engineering
thesis.degree.levelDoctoral
thesis.degree.namePhD
uottawa.departmentScience informatique et génie électrique / Electrical Engineering and Computer Science

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
Wang_Zhi_Qiang_2025_thesis.pdf
Size:
2.29 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail ImageThumbnail Image
Name:
license.txt
Size:
6.65 KB
Format:
Item-specific license agreed upon to submission
Description: