Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Challenges in Handling Detection Errors in AI-Based Anomaly Detection: A study on How Cybersecurity Professionals Handle False Positives and False Negatives
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

False Positives (FPs) and False Negatives (FNs) remain common challenges in AI-based anomaly detection systems (ADS) used to identify cybersecurity threats. These issues continue to affect both detection accuracy and the analysts’ trust in the systems. While most research focuses on improving anomaly detection models, this study examined how cybersecurity professionals handle FPs and FNs in practice. Based on 31 written interviews with cybersecurity professionals, this study explored how these tools are used in reality situations. The analysis showed that AI-based anomaly detection systems can be helpful to search unusual activity but these systems are not fully trusted without human involvement. Participants mentioned challenges such as false alerts, unclear decision making, and the need to adjust the systems and collaborate with other teams. The findings suggest that the effectiveness of AI-based anomaly detection systems depends on factors that they are trust, clear communication and a good connection between the system’s output and what teams need in practice.

Place, publisher, year, edition, pages
2025. , p. 43
Keywords [en]
AI-based anomaly detection, false positives, false negatives, cybersecurity, anomaly detection systems, alert fatigue, human-AI interaction, operational security
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:his:diva-25902OAI: oai:DiVA.org:his-25902DiVA, id: diva2:2004321
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Supervisors
Examiners
Available from: 2025-10-07 Created: 2025-10-07 Last updated: 2025-10-07Bibliographically approved

Open Access in DiVA

fulltext(665 kB)909 downloads
File information
File name FULLTEXT01.pdfFile size 665 kBChecksum SHA-512
7ea12b6a7596d83479d2df33e96add3b647fbbe3aaf352770795c35ac9307d96ce4113822ab9317899dd2b58f8861221704c96b0b7161b56748037726609084d
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 2824 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf