1 School of Mathematics and Big Data, Anhui University of Science and Technology, Huainan 232001, China.
2 School of Safety Science and Engineering, Anhui University of Science and Technology, Huainan 232001, China.
* Corresponding Author
ORCID Details
Walter Maanyere: https://orcid.org/0009-0002-5615-5477
International Journal of Science and Research Archive, 2026, 20(03), 448–461
Article DOI: 10.30574/ijsra.2026.20.3.1768
Received on 04 August 2026; revised on 13 September 2026; accepted on 15 September 2026
Insider threats remain one of the most damaging and difficult-to-detect cybersecurity risks, as malicious actors already possess legitimate access privileges. This paper presents a privacy-preserving detection framework that combines per-user process mining with differential privacy, rigorously evaluated on the official Carnegie Mellon CERT r4.2 ground-truth dataset containing 70 confirmed malicious users across three threat scenarios. By shifting from population-wide to per-user Heuristics Miner discovery, the framework overcomes the well-known flower-model degeneration and extracts highly discriminative fitness and sequence-variant features. Operating at user-week granularity (67 298 windows, 0.48 % malicious prevalence), the full feature set achieves a Random Forest AUC-ROC of 0.990 and PR-AUC of 0.232—more than twice the performance of a strong behavioural-only baseline. At a practical privacy budget of ε=1.0, differential privacy incurs an AUC-ROC cost of only 0.001 while still delivering a PR-AUC 56 times higher than random guessing. Aggregating weekly scores to the user level yields an AUC-ROC of 0.923, enabling identification of 80 % of confirmed insiders at a false-positive rate below 25 %. Complementary process-prediction tasks further demonstrate an AUC of 0.776 for next risky-activity forecasting and an R2of 0.714 for one-week-ahead risk-score regression. These results establish that formal (ε,δ)-differential privacy and operationally effective insider-threat detection can be achieved simultaneously when process mining is performed at the appropriate (per-user) granularity.
Insider threat detection, Process mining, Differential privacy, Petri nets, Heuristics Miner, Conformance checking, CERT r4.2.
Preview Article PDF
Walter Maanyere, Xianwen Fang, Palvine Ngob Enow, Brenda Ann Mukoko Etombi and Bernard Ayivor. A PRIVACY-PRESERVING FRAMEWORK FOR INSIDER THREAT DETECTION USING PROCESS MINING, MACHINE LEARNING, AND DIFFERENTIAL PRIVACY. International Journal of Science and Research Archive, 2026, 20(03), 448–461. Article DOI: https://doi.org/10.30574/ijsra.2026.20.3.1768.






