2026· International Journal of Advanced Networking and Application· Vol 18, pp. 7304-7314· 0 citations
TL;DR
A novel Multi-Layer Adversarial Defense Framework (MLADF), a composite metric for evaluating the robustness of CTI LLM interfaces, and a Confidence-Aware Response Sanitization (CARS) technique combining Monte Carlo dropout uncertainty quantification with knowledgebase factgrounding are introduced.
Abstract
The democratization of Cyber Threat Intelligence (CTI) through Large Language Models (LLMs) represents a paradigm shift in organizational security posture, enabling non-expert users to access and interpret complex threat data through intuitive natural language interfaces. However, this democratization introduces a critical paradox: the very mechanisms that lower the barrier to CTI consumption simultaneously expand the attack surface for adversarial manipulation. This paper presents a comprehensive investigation into the dual challenge of CTI democratization and adversarial resilience, proposing a novel Multi-Layer Adversarial Defense Framework (MLADF) and the CTI-SHIELD (Systematic Hardening and Intelligence-Enhanced LLM Defense) algorithm. Our threat model—formalized through the STRIDE methodology—identifies four primary adversarial attack classes: prompt injection, data poisoning, output manipulation, and model extraction, and systematically analyses their exploitation pathways in CTI deployment contexts. We introduce the Adversarial Resistance Score (ARS), a composite metric for evaluating the robustness of CTI LLM interfaces, and a Confidence-Aware Response Sanitization (CARS) technique combining Monte Carlo dropout uncertainty quantification with knowledgebase factgrounding. Experimental evaluation through structured red-team exercises demonstrates that MLADF reduces adversarial attack success rates by an average of 87.3% compared to unprotected baselines while maintaining 91.4% user comprehension accuracy and achieving calibration error (ECE) of 0.028—superior to all competing methods. A human-in-the-loop user study (n=48) confirms that our protected interface reduces adversarial susceptibility by 76.0% (p<0.001) without degrading usability. Ablation studies confirm all four MLADF layers are individually necessary, and cross-domain generalization experiments across five security verticals confirm AUC > 0.90 outside the CTI training domain.
As AI becomes integral to cybersecurity decision support systems, the attack surface expands beyond models to include user interfaces and decision workflows. This paper explores the concept of adversarially resilient user experience (UX) in AI-powered cybersecurity tools. We examine how adversaries may exploit cognitive, perceptual, and interaction-level vulnerabilities in UX to mislead human analysts or distort model outputs. Drawing on human-computer interaction (HCI), adversarial ML, and cyber threat intelligence, we propose a design framework for resilient UX in such systems. Through threat modeling, scenario analysis, and a taxonomy of attack vectors at the human-AI interface, we provide guidelines for creating decision-support environments that enhance trust, robustness, and interpretability while resisting manipulation. We validate the approach with case studies in phishing detection and network anomaly triage, and we identify key research directions for building human-AI systems that are secure not just technically, but behaviorally and perceptually as well.
Rakesh Chandra· International Journal of Inn...· 0 citations
The proposed Large Language Model-Assisted Threat-Driven Testing System enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby strengthening organizational cyber-readiness at significantly lower cost than traditional security testing approaches.
Praise Emeka Nze, A. Ademuwagun, Muktar Bello et al.· Journal of Cyber Security· 0 citations
As new power systems become increasingly dependent on cloud-supported cyber-physical systems, their openness and interconnectivity continue to increase, thereby exposing risk points for advanced persistent threats (APTs). Deception defense has been widely regarded as an effective proactive approach for mitigating APT threats. However, the remarkable reasoning capabilities of large language models (LLMs) have enabled APT attackers to leverage LLM-based semantic understanding and task-planning capabilities to conduct automated, intelligent penetration attacks, while also bringing new challenges for traditional deception defense mechanisms. To address this issue, we propose a Chameleon service mechanism that constructs multiple types of LLM-oriented deceptive services based on the shared characteristics that LLMs exhibit during environment reconnaissance and target screening, and further incorporates an attack-defense game model with Minimax Q-learning for deployment. In this way, the proposed method increases the likelihood of trapping attackers while minimizing interference with normal power operations. The experimental results show that the proposed Chameleon service mechanism can effectively enhance the trapping effect of deceptive services on LLM-assisted attackers and demonstrate good effectiveness and stability across different candidate scales and LLM evaluation conditions. Our method can provide a feasible solution for proactive deception defense against intelligent attackers in new power systems.
Ying Yao, Yiji Lin, Qinglin Yang et al.· Fall Joint Computer Conferen...· 0 citations
The rapid adoption of large language models (LLMs) in cybersecurity has created a growing need for evaluation methods that reflect operational risk rather than isolated language capability. Existing cybersecurity benchmarks assess useful dimensions such as factual knowledge, vulnerability analysis, secure coding, penetration testing, and threat intelligence reasoning, but many remain limited by static datasets, weak diagnostic granularity, limited adversarial testing, and insufficient attention to human-AI decision-making. This survey analyzes recent LLM cybersecurity benchmarks through three evaluation paradigms: knowledge-oriented, task-oriented, and holistic evaluation. From this analysis, we identify five recurring gaps between benchmark performance and real-world cybersecurity risk: knowledge-reasoning mismatch, capability-risk separation, limited failure attribution, staticity and contamination, and adversarial fragility. To address these gaps, we introduce the Reflective and Iterative Retrieval-Augmented Generation (RIRAG) framework, a dynamic and risk-aware evaluation architecture for cybersecurity LLMs. RIRAG combines continuously updated cybersecurity knowledge, retrieval- and generation-specific metrics, diagnostic logging, independent evaluation, adversarial red teaming, operational risk scoring, and human-AI teaming assessment. The framework is specified through design principles, formal components, implementation guidance, and illustrative case studies. Rather than presenting RIRAG as a validated production system, this article defines a falsifiable empirical validation protocol for future study. The central contribution is a survey-grounded reference architecture for evaluating cybersecurity LLMs as evolving, adversarially exposed, and human-interactive systems.
Unknown authors· Journal of Cybersecurity, Di...· 0 citations
It is argued that adversarial vulnerability stems from the absence of boundary verification, a security primitive that enforces explicit validation of data as it crosses inter-agent boundaries, including content, identity, execution intent, and state integrity.
Faisal Haque Bappy, Tahrim Hossain, T. S. Zaman et al.· 0 citations
The findings show that LLMs can approximate structured cybersecurity reasoning under controlled representations, but do not apply it robustly, which has important implications for the design and evaluation of AI-assisted security decision-support systems.
Pasquale Malacaria, Yunxiao Zhang· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.