Efficient Detection of Anomalous User Behavior in Cloud Environments Using Simulated Mouse Dynamics and a Hybrid Ensemble Model
Abstract
This study proposes a lightweight and interpretable framework for identifying suspicious behavior within a cloud-based environment through the use of simulated mouse dynamics and a voting ensemble classifier. Contrary to existing approaches that heavily focus on the use of deep learning techniques, this study utilizes a combination of three classical machine learning classifiers: XGBoost, Random Forest, and Support Vector Machine (SVM). The proposed framework utilizes a voting classifier that achieved a test accuracy of 51.1%, effectively identifying 36 anomalous user sessions. To further increase the interpretability of this framework, this study incorporates a voting classifier based on the use of Shapley Additive Explanation (SHAP), which identifies the most influential behavioral features used to make a prediction. This study shows that a combination of engineered behavioral features, anomaly detection through Isolation Forest, and ensemble voting can provide a lightweight, scalable, and deployable framework for real-time cloud security monitoring without requiring any intrusive biometric techniques.
References
Ali, Z. A., Abduljabbar, Z. H., Tahir, H. A., Sallow, A. B., & Almufti, S. M. (2023). eXtreme gradient boosting algorithm with machine learning: A review. Academic Journal of Nawroz University, 12(2), 320–334. https://doi.org/10.25007/ajnu.v12n2a1612
Antal, M., & Fejér, N. (2020). Mouse dynamics based user recognition using deep learning. Acta Universitatis Sapientiae, Informatica, 12(1), 39–50. https://doi.org/10.2478/ausi-2020-0003
Bhagwat, S., Patil, A., Kale, A., & Agrawal, M. (2026). A Machine Learning based Approach to Analyze and Detect Suspicious User in the Authenticator Application. Journal of The Institution of Engineers (India): Series B, 1-13. ttps://doi.org/10.1007/s40031-026-01352-2
Cremer, F., Sheehan, B., Fortmann, M., Kia, A. N., Mullins, M., Murphy, F., & Materne, S. (2022). Cyber risk and cybersecurity: A systematic review of data availability. The Geneva Papers on Risk and Insurance—Issues and Practice, 47(3), 698–736. https://doi.org/10.1057/s41288-022-00266-6
Cupps, N., & Elgazzar, H. (2026, January). Machine Learning Techniques for Continuous User Authentication Based on Mouse and Keystroke Dynamics. In 2026 IEEE 16th Annual Computing and Communication Workshop and Conference (CCWC) (pp. 0503-0510). IEEE. https://doi.org/10.1109/CCWC67433.2026.11393691
Gangadhar, C., Mapari, R. G., Muthevi, A. K., Suneetha, A., BV, S. K., & Mouleswararao, B. (2026). Exploring the role of behavioral analytics and anomaly detection in securing mobile networks for critical infrastructure. Information Security Journal: A Global Perspective, 35(1), 154-167. https://doi.org/10.1080/19393555.2025.2479027
Herrera-Silva, J. A., & Hernández-Álvarez, M. (2023). Dynamic feature dataset for ransomware detection using machine learning algorithms. Sensors, 23(3), Article 1053. https://doi.org/10.3390/s23031053
Hossain, M. A., Ishtiaq, W., & Islam, M. S. (2026). A Comparative Analysis of Ensemble‐Based Machine Learning Approaches With Explainable AI for Multi‐Class Intrusion Detection in Drone Networks. Security and Privacy, 9(1), e70164. https://doi.org/10.1002/spy2.70164
Hu, T., Niu, W., Zhang, X., Liu, X., Lu, J., & Liu, Y. (2019). An insider threat detection approach based on mouse dynamics and deep learning. Security and Communication Networks, 2019, Article 3898951. https://doi.org/10.1155/2019/3898951
Janjua, F., Masood, A., Abbas, H., & Rashid, I. (2020). Handling insider threat through supervised machine learning techniques. Procedia Computer Science, 177, 64–71. https://doi.org/10.1016/j.procs.2020.10.012
Khan, A., Quraishi, S. J., & Bedi, D. S. S. (2019). Mouse dynamics as continuous user authentication tool. International Journal of Recent Technology and Engineering, 8(4), 10923–10927. https://doi.org/10.35940/ijrte.D4404.118419
Khan, S., Devlen, C., Manno, M., & Hou, D. (2024). Mouse dynamics behavioral biometrics: A survey. ACM Computing Surveys, 56(6). https://doi.org/10.1145/3640311
Li, X., et al. (2023). A high accuracy and adaptive anomaly detection model with dual-domain graph convolutional network for insider threat detection. IEEE Transactions on Information Forensics and Security, 18, 1638–1652. https://doi.org/10.1109/TIFS.2023.3245413
Liu, Z., Wang, Y., Feng, F., Liu, Y., Li, Z., & Shan, Y. (2023). A DDoS detection method based on feature engineering and machine learning in software-defined networks. Sensors, 23(13), Article 6176. https://doi.org/10.3390/s23136176
Lu, H., Karimireddy, S. P., Ponomareva, N., & Mirrokni, V. (2020). Accelerating gradient boosting machines. Proceedings of Machine Learning Research, 108, 516–526.
Mallick, M. A. I., & Nath, R. (2024). Navigating the cyber security landscape: A comprehensive review of cyber-attacks, emerging trends, and recent developments. World Scientific News, 190(1), 1-69.
Mohan, S., Kumari, V. S., Vidhya, S., Santhoshkumar, S. P., & Chitra, A. (2025, September). Human Behavior as a Key: An Innovative Fusion of AI and MFA. In 2025 International Conference on Computing and Communications (COMPUTINGCON) (pp. 1-6). IEEE. https://doi.org/10.1109/COMPUTINGCON64838.2025.11378231
Mohanachandran, D. K., Vyas, R., Ninawe, S. S., Lakkimsetty, N. R., Maurya, S., & Ansari, M. A. (2026). Harnessing data-driven and explainable ensemble machine learning for infrastructure deterioration prediction through real-world benchmarking of models. Asian Journal of Civil Engineering, 27(4), 1811-1829. https://doi.org/10.1007/s42107-025-01588-1
Nisha, T. N., & Pramod, D. (2024). Insider intrusion detection techniques: A state-of-the-art review. Journal of Computer Information Systems, 64(1), 106–123. https://doi.org/10.1080/08874417.2023.2175337
Patel, C. K. (2026). A Comprehensive Review of User Authentication and Authorization Techniques in Cloud Computing. Pinnacle International Scientific & Management Studies, 38-47.
Peccatiello, R. B., Gondim, J. J. C., & Garcia, L. P. F. (2023). Applying one-class algorithms for data stream-based insider threat detection. IEEE Access, 11, 70560–70573. https://doi.org/10.1109/ACCESS.2023.3293825
Prajitno, N. T. M., Hadiyanto, H., & Rochim, A. F. (2023). Research opportunity of insider threat detection based on machine learning methods. In 2023 5th International Conference on Artificial Intelligence in Information and Communication (ICAIIC) (pp. 292–296). IEEE. https://doi.org/10.1109/ICAIIC57133.2023.10067010
Prasad, P. S. S., Nayak, S. K., & Krishna, M. V. (2024). Enhanced insider threat detection through machine learning approach with imbalanced data resolution. Journal of Theoretical and Applied Information Technology, 102(3), 914–926.
Quraishi, S. J., & Bedi, S. S. (2022). Secure system of continuous user authentication using mouse dynamics. In Proceedings of the 3rd International Conference on Intelligent Engineering and Management (ICIEM 2022) (pp. 138–144). IEEE. https://doi.org/10.1109/ICIEM54221.2022.9853050
Rajpoot, A., Sharma, N., Sahu, S., Anand, V., Bhalerao, S., & Yadav, S. (2025, November). Real-Time Multi-User Authentication Using Mouse Dynamics Behavioural Biometrics. In 2025 International Conference on Emerging Technologies and Innovation for Sustainability (EmergIN) (pp. 466-471). IEEE. https://doi.org/10.1109/EmergIN67762.2025.11450662
Saxena, N., Hayes, E., Bertino, E., Ojo, P., Choo, K. K. R., & Burnap, P. (2020). Impact and key challenges of insider threats on organizations and critical businesses. Electronics, 9(9), Article 1460. https://doi.org/10.3390/electronics9091460
Subash, A., Song, I., Lee, I., & Lee, K. (2025). Integrating user demographic parameters for mouse behavioral biometric-based assessment fraud detection in online education platforms. EURASIP Journal on Information Security, 2025(1), 21. https://doi.org/10.1186/s13635-025-00207-5
Tao, X., Huang, Y., Liu, J., Wang, T., Zhao, W., Wang, C., & Fu, J. (2026). User identity authentication via spatiotemporal mouse dynamics modeling. Computer Networks, 112502. https://doi.org/10.1016/j.comnet.2026.112502
Vijaykumar, P., & Kashikar, P. (2026). Understanding biometric-based systems for detecting and preventing cyber-attacks: Current trends, emerging technologies, and synthetic biometrics. Security and Safety, 5, 2026003. https://doi.org/10.1051/sands/2026003
Wang, J., Sun, Q., & Zhou, C. (2023). Insider threat detection based on deep clustering of multi-source behavioral events. Applied Sciences, 13(24), Article 13021. https://doi.org/10.3390/app132413021
Wang, J., Wang, W. C., Hu, X. X., Qiu, L., & Zang, H. F. (2024). Black-winged kite algorithm: A nature-inspired meta-heuristic for solving benchmark functions and engineering problems. Artificial Intelligence Review, 57(4). https://doi.org/10.1007/s10462-024-10723-4
Wang, Z. Q., & El Saddik, A. (2023). DTITD: An intelligent insider threat detection framework based on digital twin and self-attention-based deep learning models. IEEE Access, 11, 114013–114030. https://doi.org/10.1109/ACCESS.2023.3324371
Wanyonyi, E. N., Abeka, S., & Masinde, N. (2023). A systematic review on machine learning insider threat detection models, datasets and evaluation metrics. International Journal of Network Security & Its Applications, 15(6), 37–56. https://doi.org/10.5121/ijnsa.2023.15603
Yi, J., & Tian, Y. (2024). Insider threat detection model enhancement using hybrid algorithms between unsupervised and supervised learning. Electronics, 13(5), Article 973. https://doi.org/10.3390/electronics13050973
Zhou, H. (2025). The Role of Intelligent Security Prevention Technology in Crime Prevention—A Crime Deterrence Based on Technological Means. The Development of Humanities and Social Sciences, 1(5), 92-101. https://doi.org/10.71204/dqsddd47
Zhukabayeva, T., Zholshiyeva, L., Karabayev, N., Khan, S., & Alnazzawi, N. (2025). Cybersecurity solutions for industrial internet of things–edge computing integration: Challenges, threats, and future directions. Sensors, 25(1), 213. https://doi.org/10.3390/s25010213
Copyright (c) 2026 Journal La Multiapp

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.



