Detecting Ambiguity Aversion in Cyberattack Behavior to Inform Cognitive Defense Strategies
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866914208888651776 |
|---|---|
| author | Carney, Stephan Hans, Soham Hirschmann, Sofia Marsella, Stacey Fonken, Yvonne Wu, Peggy Gurney, Nikolos |
| author_facet | Carney, Stephan Hans, Soham Hirschmann, Sofia Marsella, Stacey Fonken, Yvonne Wu, Peggy Gurney, Nikolos |
| contents | Adversaries (hackers) attempting to infiltrate networks frequently face uncertainty in their operational environments. This research explores the ability to model and detect when they exhibit ambiguity aversion, a cognitive bias reflecting a preference for known (versus unknown) probabilities. We introduce a novel methodological framework that (1) leverages rich, multi-modal data from human-subjects red-team experiments, (2) employs a large language model (LLM) pipeline to parse unstructured logs into MITRE ATT&CK-mapped action sequences, and (3) applies a new computational model to infer an attacker's ambiguity aversion level in near-real time. By operationalizing this cognitive trait, our work provides a foundational component for developing adaptive cognitive defense strategies. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2512_08107 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Detecting Ambiguity Aversion in Cyberattack Behavior to Inform Cognitive Defense Strategies Carney, Stephan Hans, Soham Hirschmann, Sofia Marsella, Stacey Fonken, Yvonne Wu, Peggy Gurney, Nikolos Cryptography and Security Human-Computer Interaction Adversaries (hackers) attempting to infiltrate networks frequently face uncertainty in their operational environments. This research explores the ability to model and detect when they exhibit ambiguity aversion, a cognitive bias reflecting a preference for known (versus unknown) probabilities. We introduce a novel methodological framework that (1) leverages rich, multi-modal data from human-subjects red-team experiments, (2) employs a large language model (LLM) pipeline to parse unstructured logs into MITRE ATT&CK-mapped action sequences, and (3) applies a new computational model to infer an attacker's ambiguity aversion level in near-real time. By operationalizing this cognitive trait, our work provides a foundational component for developing adaptive cognitive defense strategies. |
| title | Detecting Ambiguity Aversion in Cyberattack Behavior to Inform Cognitive Defense Strategies |
| topic | Cryptography and Security Human-Computer Interaction |
| url | https://arxiv.org/abs/2512.08107 |