Limitations of Graph Neural Networks in the Task of Detecting Insider Threats
DOI:
https://doi.org/10.31861/sisiot2026.1.01023Keywords:
insider threats, graph neural networks, heterophily, privileged users, anomaly detectionAbstract
The article investigates a fundamental limitation of graph neural networks in insider threat detection: oversmoothing of node representations, which is most pronounced for privileged users. To make the value of the graph explicit, insiders are assigned not only a weak local signal but also a relational one – an anomalous pattern of links to sensitive resources: feature-only detection yields an area under the ROC curve of about 0.53, whereas one or two aggregation steps raise it to 0.93 – 0.96. Privilege is modelled as a role label that correlates with, but is distinct from, connectivity (Spearman rank correlation 0.43). Verification is performed using a trained graph convolutional network, averaged across stratified splits. As depth increases, detection quality declines; for privileged hubs, the area under the ROC curve falls to the random-guessing level at eight layers and below it by sixteen, whereas for ordinary nodes it remains markedly higher. Two degradation mechanisms are distinguished: label heterophily (early quality loss) and oversmoothing proper (deep collapse). The mitigations are presented and quantitatively compared for both mechanisms: the baseline network is virtually helpless on the privileged segment (AUC 0.42), whereas PairNorm raises this to 0.84, GPR-GNN to 0.88, and H2GCN and GCNII to 0.93 and 0.94, respectively, almost closing the gap between privileged and ordinary nodes; GPR-GNN proves practically depth-invariant. The results are of practical value for designing insider threat detection systems that are resilient to quality degradation within the most high-risk user segment. The robustness of these conclusions to the parameters of graph generation is confirmed by a dedicated analysis that varies the graph size, the number of communities, the mean degree, and the privileged fraction.
Downloads
References
I. Dobrynin, T. Radivilova, N. Maltseva, and D. Ageyev, “Use of approaches to the methodology of factor analysis of information risks for the quantitative assessment of information risks based on the formation of cause-and-effect links,” in Proc. 2018 Int. Sci.-Pract. Conf. Problems of Infocommunications. Science and Technology (PIC S&T), Kharkiv, Ukraine, 2018, pp. 229–232. doi: 10.1109/INFOCOMMST.2018.8632022.
T. Radivilova, K. Lyudmyla, O. Lemeshko, D. Ageyev, M. Tawalbeh, and A. Ilkov, “Analysis of approaches of monitoring, intrusion detection and identification of network attacks,” in Proc. 2020 IEEE Int. Conf. Problems of Infocommunications. Science and Technology (PIC S&T), 2020, pp. 819–822. doi: 10.1109/PICST51311.2020.9467973.
F. Ares-Robledo, H. Rifà-Pous, and R. Clarisó, “Graph neural networks for anomaly detection: A systematic review of dynamic temporal approaches,” Artif. Intell. Rev., vol. 59, Art. no. 129, 2026. doi: 10.1007/s10462-026-11532-7.
S. Jiang, “A survey of heterogeneous graph neural networks for cybersecurity anomaly detection,” arXiv:2510.26307, 2025. [Online]. Available: https://arxiv.org/abs/2510.26307
R. Yumlembam, B. Issac, S. M. Jacob, L. Yang, and D. Krishnan, “Insider threat detection using GCN and Bi-LSTM with explicit and implicit graph representations,” IEEE Trans. Artif. Intell., 2025. [Online]. Available: https://arxiv.org/abs/2512.18483
O. Neretin and V. Kharchenko, “Information technology for assessing and ensuring cybersecurity of large language models,” Secure Inf. Syst. IoT (SISIOT), vol. 3, no. 2, p. 02020, Dec. 2025. doi: 10.31861/sisiot2025.2.02020.
D. Ageyev, L. Kirichenko, T. Radivilova, M. Tawalbeh, and O. Baranovskyi, “Method of self-similar load balancing in network intrusion detection system,” in Proc. 2018 28th Int. Conf. Radioelektronika, Prague, Czech Republic, 2018, pp. 1–4. doi: 10.1109/RADIOELEK.2018.8376406.
T. Radivilova, L. Kirichenko, A. S. Alghawli, D. Ageyev, O. Mulesa, O. Baranovskyi, A. Ilkov, V. Kulbachnyi, and O. Bondarenko, “Statistical and signature analysis methods of intrusion detection,” in Information Security Technologies in the Decentralized Distributed Networks, Lecture Notes on Data Engineering and Communications Technologies, vol. 115, R. Oliynykov, O. Kuznetsov, O. Lemeshko, and T. Radivilova, Eds. Cham, Switzerland: Springer, 2022. doi: 10.1007/978-3-030-95161-0_5.
T. Radivilova, L. Kirichenko, D. Ageyev, M. Tawalbeh, V. Bulakh, and P. Zinchenko, “Intrusion detection based on machine learning using fractal properties of traffic realizations,” in Proc. 2019 IEEE Int. Conf. Advanced Trends in Information Theory (ATIT), Kyiv, Ukraine, 2019, pp. 218–221. doi: 10.1109/ATIT49449.2019.9030452.
T. K. Rusch, M. M. Bronstein, and S. Mishra, “A survey on oversmoothing in graph neural networks,” arXiv:2303.10993. [Online]. Available: https://arxiv.org/abs/2303.10993
F. Di Giovanni, J. Rowbottom, B. P. Chamberlain, T. Markovich, and M. M. Bronstein, “Understanding convolution on graphs via energies,” arXiv:2206.10991. [Online]. Available: https://arxiv.org/abs/2206.10991
J. Chen, Y. Wang, C. Bodnar, R. Ying, P. Liò, and Y. G. Wang, “Dirichlet energy enhancement of graph neural networks by framelet augmentation,” arXiv:2311.05767. doi: 10.48550/arXiv.2311.05767.
K. Zhang, P. Deidda, D. J. Higham, and F. Tudisco, “Are we measuring oversmoothing in graph neural networks correctly?,” arXiv:2502.04591, 2025. doi: 10.48550/arXiv.2502.04591.
X. Sun et al., “Understanding the influence of extremely high-degree nodes on graph anomaly detection,” in Pattern Recognition (ICPR 2025). Cham, Switzerland: Springer, 2025. [Online]. Available: https://link.springer.com/chapter/10.1007/978-3-031-78183-4_2
J. Zhu, Y. Yan, L. Zhao, M. Heimann, L. Akoglu, and D. Koutra, “Beyond homophily in graph neural networks: Current limitations and effective designs,” arXiv:2006.11468, 2020. [Online]. Available: https://arxiv.org/abs/2006.11468
U. Alon and E. Yahav, “On the bottleneck of graph neural networks and its practical implications,” arXiv:2006.05205, 2020. [Online]. Available: https://arxiv.org/abs/2006.05205
M. Chen, Z. Wei, Z. Huang, B. Ding, and Y. Li, “Simple and deep graph convolutional networks,” arXiv:2007.02133, 2020. [Online]. Available: https://arxiv.org/abs/2007.02133
L. Zhao and L. Akoglu, “PairNorm: Tackling oversmoothing in GNNs,” arXiv:1909.12223, 2020. [Online]. Available: https://arxiv.org/abs/1909.12223
Y. Rong, W. Huang, T. Xu, and J. Huang, “DropEdge: Towards deep graph convolutional networks on node classification,” arXiv:1907.10903, 2020. [Online]. Available: https://arxiv.org/abs/1907.10903
M. Yang and C. Liu, “XGA-E: an explainability-enhanced graph neural network for network traffic anomaly detection,” Cybersecurity, vol. 9, Art. no. 99, 2026. doi: 10.1186/s42400-025-00487-x.
P. Lavanya, H. A. Glory, M. Aggarwal, M. et al., “Unmasking insider threats using a robust hybrid optimized generative pretrained neural network approach,” Sci. Rep., vol. 15, Art. no. 26718, 2025. doi: 10.1038/s41598-025-12127-y.
E. Chien, J. Peng, P. Li, and O. Milenkovic, “Adaptive universal generalized PageRank graph neural network,” arXiv:2006.07988, 2021. [Online]. Available: https://arxiv.org/abs/2006.07988
Published
Issue
Section
License
Copyright (c) 2026 Security of Infocommunication Systems and Internet of Things

This work is licensed under a Creative Commons Attribution 4.0 International License.









