Skip to main content
Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection
  1. publications
  2. ai

Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection

Available Media Publication (PDF)
Conference USENIX Security Symposium (Usenix Security) - 2026
Authors Alex Kantchelian , Casper Neo , Ryan Stevens ,
Citation BibTeX
BibTeX
@inproceedings{Kantchelian2026Facade,
  title = {Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection},
  author = {Alex Kantchelian and Casper Neo and Ryan Stevens and Hyungwon Kim and Zhaohao Fu and Sadegh Momeni and Birkett Huber and Cem Topcuoglu and Senaka Buthpitiya and Elie Bursztein and Yanis Pavlidis and Martin Cochran and Massimiliano Poletto},
  booktitle = {USENIX Security Symposium},
  year = {2026},
  organization = {USENIX Association}
}

Facade detects suspicious activity by learning how users, resources and actions relate to one another. Instead of looking at an event in isolation, the system considers its surrounding context across document access, database queries and HTTP/RPC requests.

The model learns from benign activity using contrastive learning, addressing the scarcity of labeled insider incidents. The paper describes the system deployed at Google since 2018 and reports false positive rates low enough for practical investigation.

The earlier Black Hat presentation introduces the system and its open-source implementation.

newsletter signup
newsletter signup