본문 바로가기
  • Home

A Study on the Robustness of Insider Threat Detection via SHAP-Guided Adversarial Attacks and Retraining

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2026, 31(9), pp.97~105
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : July 15, 2026
  • Accepted : September 12, 2026
  • Published : September 30, 2026

Yu-Jin An 1,  Hyun-Dong Kim 1,  Sang-Hoon Han 1,  Geon-Yun Shin 1

1한경국립대학교

Accredited

ABSTRACT

This study investigates the effects of SHapley Additive exPlanations (SHAP)-based feature selection on evasion attacks and defense through adversarial retraining in an insider threat detection setting using the CERT r4.2 dataset. Global and local SHAP values from a CatBoost model are combined to generate adversarial samples under a constrained feature-modification budget, and attack generation methods and retraining strategies are compared. The results show that SHAP-based feature selection achieves higher attack success rates (ASRs) than non-SHAP approaches, while searching both perturbation direction and magnitude generates stronger evasion attacks than using a fixed perturbation magnitude. In addition, the robustness gained through adversarial retraining transfers to attack types not used during training. In particular, retraining with a single strong attack improves robustness while limiting degradation in clean detection performance and increases in the false-positive rate for benign samples. With iterative retraining, additional performance gains are limited after the first round.

Journal Copyright Policy

No CCL information provided

Citation status

* References for papers published after 2025 are currently being built.

This paper was written with support from the National Research Foundation of Korea.