AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
PDF (1.2 MB)
Collect
Submit Manuscript AI Chat Paper
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Research Article | Open Access

Evo-TTP: Generative and robust prediction of novel cyber threat tactics using adversarial fine-tuning of large language models

Dilkhaz Mohammed( )Shahram Jamali
Department of Computer Engineering, University of Mohaghegh Ardabili, Ardabil, Iran
Show Author Information

Abstract

The asymmetrical nature of the modern cyber threat landscape allows advanced persistent threats (APTs) to innovate tactics at a significantly faster rate than defensive frameworks can document them. While the MITRE ATT & CK® framework provides a standardized taxonomy of known behaviors, it essentially functions as a retrospective database — a "dictionary of the past" which fails to anticipate future "zero-day" tactics, techniques, and procedures (TTPs). This paper introduces Evo-TTP, a comprehensive framework for the predictive generation of novel and robust tactics, techniques, and procedures via big data mining and adversarial learning. By leveraging the massive structured data from the MITRE ATT & CK® Enterprise Matrix v18.0, Evo-TTP treats the prediction of future threats as a high-dimensional pattern completion problem. Our methodology addresses two primary failures in current generative AI applications to big data: mode collapse, which refers to hallucinating biologically or technically impossible scenarios, and algorithmic brittleness, which is characterized by its susceptibility to adversarial perturbations. We employ a tripartite approach: (1) applying semantic pattern mining on the v18.0 dataset to create a baseline knowledge graph that reveals hidden correlations; (2) utilizing synthetic novelty expansion with a teacher-student architecture, using Llama-3.1-405B as the teacher and Llama-3.1-8B as the student model, to overcome data scarcity; and (3) conducting training in adversarial group relative policy optimization (GRPO). This training regime maximizes a composite reward function by balancing novelty, technical feasibility, and resilience against adversarial noise. Validated against the 2025 benchmarks and vetted according to SafeGen-X principles, Evo-TTP demonstrates a 23.1% increase in utility and an 18.2% improvement in robustness to adversarial attacks when compared with standard fine-tuning methods. This research positions generative AI not only as a text processor but also as a critical instrument in big data for uncovering the hidden evolutionary mechanics of cyberwarfare.

References

【1】
【1】
 
 
AIMS Electronics and Electrical Engineering
Pages 314-333

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Mohammed D, Jamali S. Evo-TTP: Generative and robust prediction of novel cyber threat tactics using adversarial fine-tuning of large language models. AIMS Electronics and Electrical Engineering, 2026, 10(2): 314-333. https://doi.org/10.3934/electreng.2026013

5

Views

0

Downloads

0

Crossref

0

Web of Science

0

Scopus

Received: 07 January 2026
Revised: 15 March 2026
Accepted: 30 March 2026
Published: 15 June 2026
©2026 the Author(s), licensee AIMS Press.

This is an open access article distributed under the terms of the Creative Commons Attribution License (https://creativecommons.org/licenses/by/4.0)