USER BEHAVIOR ANALYTICS FOR DETECTING AI-DRIVEN SOCIAL ENGINEERING ATTACKS
DOI:
https://doi.org/10.65164/41y5qr89Keywords:
social engineering, behavioral analytics, UEBA, insider threat detection, deep evidential clustering, federated learning, explainable AI, cybersecurity.Abstract
Social engineering remains a persistent security problem because it exploits human decision-making instead of only software flaws. Recent evidence shows that identity misuse and human-driven mistakes continue to be major breach pathways: Verizon's 2025 Data Breach Investigations Report analyzed more than 22,000 incidents and 12,195 confirmed breaches, while credential abuse remained a leading initial attack vector at 22% [1]. This paper examines how behavioral security analytics, user and entity behavior analytics (UEBA), deep learning, deep evidential clustering (DEC), explainable AI (XAI), and federated learning (FL) can defend against social engineering and insider threats. This work synthesizes published results and compares methods, datasets, formulas, advantages, limitations, and deployment gaps. The review finds that AI-driven behavioral analytics can reduce false positives, detect subtle post-login behavior changes, and provide analyst explanations; however, real-world deployment is limited by dataset imbalance, privacy constraints, cold-start baselines, model poisoning, and the difficulty of inferring human intent from logs alone. The paper concludes that the strongest defense is not fully automated surveillance, but a human-centered system that combines contextual behavior modeling, privacy-preserving learning, explainable alerts, and continuous security awareness.