<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
    <responseDate>2026-09-30T13:06:28.218Z</responseDate>
    <request verb="GetRecord" identifier="ezaposleni.singidunum.ac.rs/rest/sciNaucniRezultati/oai:2:12172" metadataPrefix="dim">http://ezaposleni.singidunum.ac.rs/rest/sciNaucniRezultati/oai</request>
    <GetRecord>
        <record>
            <header>
                <identifier>ezaposleni.singidunum.ac.rs/rest/sciNaucniRezultati/oai:2:12172</identifier>
                <datestamp>2026-09-10T23:20:03Z</datestamp>
                <setSpec>2</setSpec>
            </header>
            <metadata>
                <dim:dim>
                    <dim:field mdschema="dc" element="title" lang="en">Metaheuristic Hyperparameter Optimization for AdaBoost-Based Insider Threat Detection: A Comparative Study on CERT Logon Activity</dim:field>
                    <dim:field mdschema="dc" element="date" qualifier="issued">2026</dim:field>
                    <dim:field mdschema="dc" element="identifier" qualifier="uri">http://ezaposleni.singidunum.ac.rs/rest/sciNaucniRezultati/oai/record/2/12172</dim:field>
                    <dim:field mdschema="dc" element="identifier" qualifier="uri">https://setjournal.com/index.php/SET/article/view/372</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="orcid::0009-0007-7821-0453" confidence="-1">S. Anetic</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="etfid:1124" confidence="-1">S. Andjelic</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="id:56923" confidence="-1">M. Grubjesic</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="id:56924" confidence="-1">M. Abdel-Salam</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="id:56925" confidence="-1">V. Simic</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="orcid::0009-0001-2928-0654" confidence="-1">S. Offorjindu</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="orcid::0000-0002-5511-2531" confidence="-1">M. Antonijevic</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="orcid::0000-0002-4351-068X" confidence="-1">M. Zivkovic</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="orcid::0000-0002-2062-924X" confidence="-1">N. Bacanin</dim:field>
                    <dim:field mdschema="dc" element="contributor" qualifier="author" authority="id:56930" confidence="-1">K. Lalovic</dim:field>
                    <dim:field mdschema="dc" element="description" qualifier="abstract">Insider threats are hard to detect because malicious actions are rare and closely resemble ordinary activity. This study asks how much of the achievable detection performance comes from tuning a classifier&amp;apos;s hyperparameters, and how much depends on which optimizer performs the tuning. AdaBoost is applied to logon activity from the publicly available synthetic Computer Emergency Response Team (CERT) Insider Threat Test Dataset. The majority class was down-sampled to a 9:1 ratio, giving 1,980 observations split 70:30, and nine metaheuristics were compared under an identical budget of 1,020 objective evaluations across 30 independent runs, with hyperparameters selected by three-fold cross-validation on the training partition only and the held-out partition used once for final evaluation. Tuning is decisive: AdaBoost with default parameters reaches a Cohen&amp;apos;s kappa of 0.281 and recovers 14 of 59 insider events, whereas tuned configurations reach approximately 0.59. The choice of optimizer matters far less. Only 0.0151 of Cohen&amp;apos;s kappa separates the strongest from the weakest of the nine, and although the differences are statistically detectable, the ranking is largely stable across budgets. A hybrid Crayfish Optimization Algorithm variant combining quasi-reflective learning with a firefly-inspired step is also evaluated; it improves on the original algorithm but does not reach the leading methods. Analysis of false negative rates and precision-recall behaviour shows that a model of this kind is best deployed as one risk signal within a wider</dim:field>
                    <dim:field mdschema="dc" element="type">article</dim:field>
                    <dim:field mdschema="dc" element="identifier" qualifier="doi">10.54327/set2026/v6.i2.372</dim:field>
                    <dim:field mdschema="dc" element="citation" qualifier="volume">6</dim:field>
                    <dim:field mdschema="dc" element="citation" qualifier="issue">2</dim:field>
                    <dim:field mdschema="dc" element="citation" qualifier="spage">68</dim:field>
                    <dim:field mdschema="dc" element="citation" qualifier="epage">94</dim:field>
                    <dim:field mdschema="dc" element="identifier" qualifier="issn">2744-2527</dim:field>
                    <dim:field mdschema="dc" element="source">Science, Engineering and Technology</dim:field>
                </dim:dim>
            </metadata>
        </record>
    </GetRecord>
</OAI-PMH>
