Anomaly Detection at Multiple Scales

It is under DARPA's Information Innovation office and began in 2011[1][2][3][4] and ended in August 2014[5] The project was intended to detect and prevent insider threats such as "a soldier in good mental health becoming homicidal or suicidal", an "innocent insider becoming malicious", or "a government employee [who] abuses access privileges to share classified information".

[2][6] Specific cases mentioned are Nadal Malik Hasan and WikiLeaks source Chelsea Manning.

[2][6] A final report was published on May 11, 2015, detailing a system known as Anomaly Detection Engine for Networks, or ADEN, developed by the University of Maryland, College Park, whose goal was to "identify malicious users within a network."

Using multiple datasets from Wikipedia, Slashdot, and others, researchers were able to identify vandals and malicious users on a website using both conventional algorithms and artificial intelligence.

[8] The Proactive Discovery of Insider Threats Using Graph Analysis and Learning was part of the ADAMS project.