arXiv AI

From Sandbox to Enforcement: Confidence-Qualified Threat Intelligence for Critical Infrastructure

arXiv:2610. 07310v1 Announce Type: cross Abstract: Security operations centres and national incident-response teams defending critical infrastructure collect abundant threat data yet struggle to turn it into actionable intelligence.

arXiv AI
Jul 28

TRACE-CTI: Auditable Post-Extraction Governance of TTP Claims with Knowledge Graphs

arXiv:2607. 24563v1 Announce Type: new Abstract: Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation history needed to decide whether an individual mapping should be trusted.

By Federico Valletta, Giacomo Longo, Enrico Russo, Alessio Merlo
arXiv AI
Jul 2

Toward Cybersecurity-Expert Small Language Models

arXiv:2510. 14113v2 Announce Type: replace-cross Abstract: Large language models (LLMs) are transforming everyday applications, yet deployment in cybersecurity lags due to a lack of high-quality, domain-specific models and training datasets.

By Matan Levi, Daniel Ohayon, Ariel Blobstein, Ravid Sagi, Ian Molloy, Yair Allouche
arXiv Computation and Language
Aug 31

DisCTI: Who Needs to Know Timely? Automated Sector-Aware Cyber Threat Intelligence Dissemination

The paper introduces DisCTI, a system that automatically maps cyber threat intelligence (CTI) events to relevant industry sectors using a multilabel classification approach. By creating a dataset of 872 sector‑labelled CTI events and applying a BERT transformer model, the authors achieve a macro‑averaged F1‑score of 0.89, correctly assigning 94.5% of sector labels. This demonstrates that embedding expert knowledge into machine learning can enable timely, sector‑aware CTI dissemination, improving defensive response.

By Fajar Wijitrisnanto (National Cyber and Crypto Agency, Jakarta, Indonesia), Alsharif Abuadbba (CSIRO, Sydney, Australia), Yansong Gao (CSIRO, Sydney, Australia, The University of Western Australia, Perth, Australia), Nan Wu (CSIRO, Sydney, Australia)
arXiv AI
Jul 9

Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies

arXiv:2607. 06963v1 Announce Type: cross Abstract: Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks.

By Kiarash Ahi, Saeed Valizadeh