Van Duong Thi, Thang Tran Duc, Tien Minh Nguyen, Huy-Minh Pham Luong
Insider threats remain a critical challenge in enterprise environments due to the difficulty of distinguishing malicious actions from legitimate user activities. This paper proposes a RiskScore-guided Graph Neural Network (R-GNN) framework for insider threat detection. The framework builds a Knowledge Graph (KG) from heterogeneous enterprise audit logs to represent users, resources, and their interactions, and a formally defined RiskScore is computed from behavioral deviations and incorporated as a guidance signal within graph-based learning. The RiskScore aggregates domain-informed indicators, such as abnormal access frequency and temporal irregularities, into a unified semantic representation that complements the relational structure encoded in the KG. Experiments conducted on the CERT r4.2 insider threat dataset demonstrate that the proposed approach consistently outperforms existing graph-based and sequence-based baselines. Moreover, by integrating RiskScore as an explicit input to the GNN, the framework enables detection results to be interpretable in terms of contributing behavioral risk factors and relational context, providing a practical and effective solution for risk-aware and interpretable insider threat detection in enterprise environments.