Limitations of Graph Neural Networks in the Task of Detecting Insider Threats

Authors

DOI:

https://doi.org/10.31861/sisiot2026.1.01023

Keywords:

insider threats, graph neural networks, heterophily, privileged users, anomaly detection

Abstract

The article investigates a fundamental limitation of graph neural networks in insider threat detection: oversmoothing of node representations, which is most pronounced for privileged users. To make the value of the graph explicit, insiders are assigned not only a weak local signal but also a relational one – an anomalous pattern of links to sensitive resources: feature-only detection yields an area under the ROC curve of about 0.53, whereas one or two aggregation steps raise it to 0.93 – 0.96. Privilege is modelled as a role label that correlates with, but is distinct from, connectivity (Spearman rank correlation 0.43). Verification is performed using a trained graph convolutional network, averaged across stratified splits. As depth increases, detection quality declines; for privileged hubs, the area under the ROC curve falls to the random-guessing level at eight layers and below it by sixteen, whereas for ordinary nodes it remains markedly higher. Two degradation mechanisms are distinguished: label heterophily (early quality loss) and oversmoothing proper (deep collapse). The mitigations are presented and quantitatively compared for both mechanisms: the baseline network is virtually helpless on the privileged segment (AUC 0.42), whereas PairNorm raises this to 0.84, GPR-GNN to 0.88, and H2GCN and GCNII to 0.93 and 0.94, respectively, almost closing the gap between privileged and ordinary nodes; GPR-GNN proves practically depth-invariant. The results are of practical value for designing insider threat detection systems that are resilient to quality degradation within the most high-risk user segment. The robustness of these conclusions to the parameters of graph generation is confirmed by a dedicated analysis that varies the graph size, the number of communities, the mean degree, and the privileged fraction.

Downloads

Download data is not yet available.

Author Biographies

  • Ihor Dobrynin, Kharkiv National University of Radio Electronics

    Research activity: research supervisor of winners of national competitions for students’ scientific works in the field of Information Security; expert auditor of information security management systems. Scientific directions: process approaches to the audit of information security management systems, assessment and minimization of information risks; Project Academic Advocate of ISACA.

  • Vadym Pantelieiev, Kharkiv National University of Radio Electronics

    Research Interests: Research and refinement of methods for predicting domestic incidents through the analysis of social network structures and interactions. Research Publications: 3 research publications.

References

I. Dobrynin, T. Radivilova, N. Maltseva, and D. Ageyev, “Use of approaches to the methodology of factor analysis of information risks for the quantitative assessment of information risks based on the formation of cause-and-effect links,” in Proc. 2018 Int. Sci.-Pract. Conf. Problems of Infocommunications. Science and Technology (PIC S&T), Kharkiv, Ukraine, 2018, pp. 229–232. doi: 10.1109/INFOCOMMST.2018.8632022.

T. Radivilova, K. Lyudmyla, O. Lemeshko, D. Ageyev, M. Tawalbeh, and A. Ilkov, “Analysis of approaches of monitoring, intrusion detection and identification of network attacks,” in Proc. 2020 IEEE Int. Conf. Problems of Infocommunications. Science and Technology (PIC S&T), 2020, pp. 819–822. doi: 10.1109/PICST51311.2020.9467973.

F. Ares-Robledo, H. Rifà-Pous, and R. Clarisó, “Graph neural networks for anomaly detection: A systematic review of dynamic temporal approaches,” Artif. Intell. Rev., vol. 59, Art. no. 129, 2026. doi: 10.1007/s10462-026-11532-7.

S. Jiang, “A survey of heterogeneous graph neural networks for cybersecurity anomaly detection,” arXiv:2510.26307, 2025. [Online]. Available: https://arxiv.org/abs/2510.26307

R. Yumlembam, B. Issac, S. M. Jacob, L. Yang, and D. Krishnan, “Insider threat detection using GCN and Bi-LSTM with explicit and implicit graph representations,” IEEE Trans. Artif. Intell., 2025. [Online]. Available: https://arxiv.org/abs/2512.18483

O. Neretin and V. Kharchenko, “Information technology for assessing and ensuring cybersecurity of large language models,” Secure Inf. Syst. IoT (SISIOT), vol. 3, no. 2, p. 02020, Dec. 2025. doi: 10.31861/sisiot2025.2.02020.

D. Ageyev, L. Kirichenko, T. Radivilova, M. Tawalbeh, and O. Baranovskyi, “Method of self-similar load balancing in network intrusion detection system,” in Proc. 2018 28th Int. Conf. Radioelektronika, Prague, Czech Republic, 2018, pp. 1–4. doi: 10.1109/RADIOELEK.2018.8376406.

T. Radivilova, L. Kirichenko, A. S. Alghawli, D. Ageyev, O. Mulesa, O. Baranovskyi, A. Ilkov, V. Kulbachnyi, and O. Bondarenko, “Statistical and signature analysis methods of intrusion detection,” in Information Security Technologies in the Decentralized Distributed Networks, Lecture Notes on Data Engineering and Communications Technologies, vol. 115, R. Oliynykov, O. Kuznetsov, O. Lemeshko, and T. Radivilova, Eds. Cham, Switzerland: Springer, 2022. doi: 10.1007/978-3-030-95161-0_5.

T. Radivilova, L. Kirichenko, D. Ageyev, M. Tawalbeh, V. Bulakh, and P. Zinchenko, “Intrusion detection based on machine learning using fractal properties of traffic realizations,” in Proc. 2019 IEEE Int. Conf. Advanced Trends in Information Theory (ATIT), Kyiv, Ukraine, 2019, pp. 218–221. doi: 10.1109/ATIT49449.2019.9030452.

T. K. Rusch, M. M. Bronstein, and S. Mishra, “A survey on oversmoothing in graph neural networks,” arXiv:2303.10993. [Online]. Available: https://arxiv.org/abs/2303.10993

F. Di Giovanni, J. Rowbottom, B. P. Chamberlain, T. Markovich, and M. M. Bronstein, “Understanding convolution on graphs via energies,” arXiv:2206.10991. [Online]. Available: https://arxiv.org/abs/2206.10991

J. Chen, Y. Wang, C. Bodnar, R. Ying, P. Liò, and Y. G. Wang, “Dirichlet energy enhancement of graph neural networks by framelet augmentation,” arXiv:2311.05767. doi: 10.48550/arXiv.2311.05767.

K. Zhang, P. Deidda, D. J. Higham, and F. Tudisco, “Are we measuring oversmoothing in graph neural networks correctly?,” arXiv:2502.04591, 2025. doi: 10.48550/arXiv.2502.04591.

X. Sun et al., “Understanding the influence of extremely high-degree nodes on graph anomaly detection,” in Pattern Recognition (ICPR 2025). Cham, Switzerland: Springer, 2025. [Online]. Available: https://link.springer.com/chapter/10.1007/978-3-031-78183-4_2

J. Zhu, Y. Yan, L. Zhao, M. Heimann, L. Akoglu, and D. Koutra, “Beyond homophily in graph neural networks: Current limitations and effective designs,” arXiv:2006.11468, 2020. [Online]. Available: https://arxiv.org/abs/2006.11468

U. Alon and E. Yahav, “On the bottleneck of graph neural networks and its practical implications,” arXiv:2006.05205, 2020. [Online]. Available: https://arxiv.org/abs/2006.05205

M. Chen, Z. Wei, Z. Huang, B. Ding, and Y. Li, “Simple and deep graph convolutional networks,” arXiv:2007.02133, 2020. [Online]. Available: https://arxiv.org/abs/2007.02133

L. Zhao and L. Akoglu, “PairNorm: Tackling oversmoothing in GNNs,” arXiv:1909.12223, 2020. [Online]. Available: https://arxiv.org/abs/1909.12223

Y. Rong, W. Huang, T. Xu, and J. Huang, “DropEdge: Towards deep graph convolutional networks on node classification,” arXiv:1907.10903, 2020. [Online]. Available: https://arxiv.org/abs/1907.10903

M. Yang and C. Liu, “XGA-E: an explainability-enhanced graph neural network for network traffic anomaly detection,” Cybersecurity, vol. 9, Art. no. 99, 2026. doi: 10.1186/s42400-025-00487-x.

P. Lavanya, H. A. Glory, M. Aggarwal, M. et al., “Unmasking insider threats using a robust hybrid optimized generative pretrained neural network approach,” Sci. Rep., vol. 15, Art. no. 26718, 2025. doi: 10.1038/s41598-025-12127-y.

E. Chien, J. Peng, P. Li, and O. Milenkovic, “Adaptive universal generalized PageRank graph neural network,” arXiv:2006.07988, 2021. [Online]. Available: https://arxiv.org/abs/2006.07988

Downloads


Abstract views: 0

Published

2026-06-30

Issue

Section

Articles

How to Cite

[1]
I. Dobrynin and V. Pantelieiev, “Limitations of Graph Neural Networks in the Task of Detecting Insider Threats”, SISIOT, vol. 4, no. 1, p. 01023, Jun. 2026, doi: 10.31861/sisiot2026.1.01023.

Similar Articles

41-50 of 69

You may also start an advanced similarity search for this article.