{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T09:54:29Z","timestamp":1777888469848,"version":"3.51.4"},"reference-count":0,"publisher":"Advances in Artificial Intelligence and Machine Learning","issue":"02","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["AAIML"],"published-print":{"date-parts":[[2026]]},"abstract":"<jats:p>To address the challenge of detecting insider threats, this study proposes identifying anomalous cases by analyzing user file operations recorded in organizational system logs. This study involved monitoring user document operations in a special laboratory environment, from which a sample dataset was systematically created for further analysis. Relevant data\nsources were identified to capture file-based user activities through operating system logs.\nFeatures suitable for the study were selected. Cleaning, filtering, and normalization were\nperformed on the data. The cleaned data were consolidated into a single dataset and analyzed\nusing unsupervised learning and statistical methods suitable for classification tasks. The\nfollowing algorithms were selected: Isolation Forest, Local Outlier Factor, One-Class Support Vector Machine (SVM), and Z-Score. A total of 50 anomalous actions were performed\nby users in the study. As a result of the evaluation, 36 of these 50 anomalous cases were\nconsistently as anomalies by all algorithms. This study demonstrates the potential for realtime detection of insider threats in the future. The approach is particularly relevant for\norganizations that handle sensitive data, and it can be integrated into UEBA and DLP systems.<\/jats:p>","DOI":"10.54364\/aaiml.2026.62284","type":"journal-article","created":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T05:37:56Z","timestamp":1773380276000},"page":"5128-5141","source":"Crossref","is-referenced-by-count":0,"title":["Detecting Anomalous States Through File Operations Using Unsupervised Learning Algorithms"],"prefix":"10.54364","volume":"06","author":[{"given":"Islambek","family":"Saymanov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Firdavs","family":"Muxammadiev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gayrat","family":"Juraev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yebo","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Olga","family":"Boiprav","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruhillo","family":"Alaev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Obidjon","family":"Bozorov","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Timur","family":"Abdullayev","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"32807","published-online":{"date-parts":[[2026]]},"container-title":["Advances in Artificial Intelligence and Machine Learning"],"original-title":[],"link":[{"URL":"https:\/\/www.oajaiml.com\/uploads\/archivepdf\/232262284.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T04:45:43Z","timestamp":1777610743000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.oajaiml.com\/uploads\/archivepdf\/232262284.pdf"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":0,"journal-issue":{"issue":"02","published-online":{"date-parts":[[2026]]},"published-print":{"date-parts":[[2026]]}},"URL":"https:\/\/doi.org\/10.54364\/aaiml.2026.62284","relation":{},"ISSN":["2582-9793"],"issn-type":[{"value":"2582-9793","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}