ResearchTrend.AI
  • Papers
  • Communities
  • Events
  • Blog
  • Pricing
Papers
Communities
Social Events
Terms and Conditions
Pricing
Parameter LabParameter LabTwitterGitHubLinkedInBlueskyYoutube

© 2025 ResearchTrend.AI, All rights reserved.

  1. Home
  2. Papers
  3. 2505.11542
2
0

Cybersecurity threat detection based on a UEBA framework using Deep Autoencoders

14 May 2025
Jose Fuentes
Ines Ortega-Fernandez
Nora M. Villanueva
Marta Sestelo
ArXivPDFHTML
Abstract

User and Entity Behaviour Analytics (UEBA) is a broad branch of data analytics that attempts to build a normal behavioural profile in order to detect anomalous events. Among the techniques used to detect anomalies, Deep Autoencoders constitute one of the most promising deep learning models on UEBA tasks, allowing explainable detection of security incidents that could lead to the leak of personal data, hijacking of systems, or access to sensitive business information. In this study, we introduce the first implementation of an explainable UEBA-based anomaly detection framework that leverages Deep Autoencoders in combination with Doc2Vec to process both numerical and textual features. Additionally, based on the theoretical foundations of neural networks, we offer a novel proof demonstrating the equivalence of two widely used definitions for fully-connected neural networks. The experimental results demonstrate the proposed framework capability to detect real and synthetic anomalies effectively generated from real attack data, showing that the models provide not only correct identification of anomalies but also explainable results that enable the reconstruction of the possible origin of the anomaly. Our findings suggest that the proposed UEBA framework can be seamlessly integrated into enterprise environments, complementing existing security systems for explainable threat detection.

View on arXiv
@article{fuentes2025_2505.11542,
  title={ Cybersecurity threat detection based on a UEBA framework using Deep Autoencoders },
  author={ Jose Fuentes and Ines Ortega-Fernandez and Nora M. Villanueva and Marta Sestelo },
  journal={arXiv preprint arXiv:2505.11542},
  year={ 2025 }
}
Comments on this paper