A Human-AI Interaction Dashboard for Detecting Potentially Malicious Emails
Abstract
While considerable effort has been expended on cybersecurity methods for strengthening firewalls, emails and compromised accounts represent key vulnerabilities for many organizations that can’t be addressed solely through firewall defences. Thus, the detection of anomalous, and possibly malicious, emails is a major concern in many organizations. In this paper we report on interactive machine learning (iML) models that we have developed for detecting anomalous emails. These models utilize an active learning approach to improve the efficiency of expert labelling of instances. We also report on work we have done to develop a more comprehensive dashboard that will assist analysts in labelling and investigating potentially malicious emails. Our approach takes advantage of analyses of email text to create visualizations, and an associated workflow, that allow analysts to get an organized overview of the email space. Analysts can then drill down into regions of the space that may have a higher probability of containing malicious emails. We initially used a simple interface for the labelling task that gave the human analysts relatively little support in making their labelling decisions. Guided by results reported in the research literature, plus our own requirements analyses, we then developed visualizations and an enhanced user interface designed to support efficient and effective iML. The resulting dashboard uses visual summaries of text as part of a multi-step labelling process.
Authors: Jaturong Kongmanee, Mu-Huan Chung, April Luna, Lisa Zhan, Khilan Jerath, Abhay Raman, Mark Chignell
Published in: IEEE International Conference on Human-Machine Systems (ICHMS) (2024)