@article{ART003383493},
author={Yu-Jin An and Hyun-Dong Kim and Sang-Hoon Han and Geon-Yun Shin},
title={A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2026},
volume={31},
number={9},
pages={97-105}
TY - JOUR
AU - Yu-Jin An
AU - Hyun-Dong Kim
AU - Sang-Hoon Han
AU - Geon-Yun Shin
TI - A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining
JO - Journal of The Korea Society of Computer and Information
PY - 2026
VL - 31
IS - 9
PB - The Korean Society Of Computer And Information
SP - 97
EP - 105
SN - 1598-849X
AB - This study investigates the effects of SHapley Additive exPlanations (SHAP)-based feature selection on evasion attacks and defense through adversarial retraining in an insider threat detection setting using the CERT r4.2 dataset. Global and local SHAP values from a CatBoost model are combined to generate adversarial samples under a constrained feature-modification budget, and attack generation methods and retraining strategies are compared. The results show that SHAP-based feature selection achieves higher attack success rates (ASRs) than non-SHAP approaches, while searching both perturbation direction and magnitude generates stronger evasion attacks than using a fixed perturbation magnitude. In addition, the robustness gained through adversarial retraining transfers to attack types not used during training. In particular, retraining with a single strong attack improves robustness while limiting degradation in clean detection performance and increases in the false-positive rate for benign samples. With iterative retraining, additional performance gains are limited after the first round.
KW - SHAP;Insider Threat Detection;Evasion Attack;Adversarial Retraining;Model Robustness
DO -
UR -
ER -
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han and Geon-Yun Shin. (2026). A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining. Journal of The Korea Society of Computer and Information, 31(9), 97-105.
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han and Geon-Yun Shin. 2026, "A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining", Journal of The Korea Society of Computer and Information, vol.31, no.9 pp.97-105.
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han, Geon-Yun Shin "A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining" Journal of The Korea Society of Computer and Information 31.9 pp.97-105 (2026) : 97.
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han, Geon-Yun Shin. A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining. 2026; 31(9), 97-105.
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han and Geon-Yun Shin. "A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining" Journal of The Korea Society of Computer and Information 31, no.9 (2026) : 97-105.
Yu-Jin An; Hyun-Dong Kim; Sang-Hoon Han; Geon-Yun Shin. A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining. Journal of The Korea Society of Computer and Information, 31(9), 97-105.
Yu-Jin An; Hyun-Dong Kim; Sang-Hoon Han; Geon-Yun Shin. A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining. Journal of The Korea Society of Computer and Information. 2026; 31(9) 97-105.
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han, Geon-Yun Shin. A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining. 2026; 31(9), 97-105.
Yu-Jin An, Hyun-Dong Kim, Sang-Hoon Han and Geon-Yun Shin. "A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining" Journal of The Korea Society of Computer and Information 31, no.9 (2026) : 97-105.