FEDERATED COGNITIVE DIGITAL TWINS FOR AUTONOMOUS AI AGENT INSIDER THREAT PREDICTION AND CONTAINMENT
DOI:
https://doi.org/10.63878/qrjs1213Abstract
As users have legitimate access and business environments become more autonomous with the use of AI agents, insider threats continue to be a significant problem in the cybersecurity landscape. The current detection methods typically are reactive, require centralized data collection, and have privacy protection and scalability problems. In order to solve these problems, this paper introduces a Federated Cognitive Digital Twin (FCDT) framework for the autonomous prediction and containment of insider threats using AI agents. The proposed framework leverages Federated Learning, Cognitive Digital Twins, Long Short-Term Memory (LSTM) for behavioral prediction, and a Threat Risk Scoring mechanism to facilitate privacy-preserving collaborative learning and proactive threat detection in distributed environments. On one hand Federated Learning enables multiple organizations to train a global model without exposing sensitive data, and on the other hand, Cognitive Digital Twins continuously model behaviors and detect possible insider threats. To test the proposed framework, the UNSW-NB15 dataset was used, and the experiments were carried out in Google Colab. The model showed promising classification performance, with an accuracy of 84.21%, precision of 90.49%, recall of 79.70%, F1 score of 84.75% and ROC-AUC of 93.82%, indicating a good discriminating ability. It is observed from the experimental results that the proposed framework is effective in improving the insider threat prediction with data privacy and scalable cyber security intelligence. Overall, the proposed FCDT framework offers a promising approach to ensure the security of modern distributed enterprise systems in the face of dynamic insider threats and autonomous AI-agent risks.

