Detecting Ambiguity Aversion in Cyberattack Behavior to Inform Cognitive Defense Strategies

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Carney, Stephan, Hans, Soham, Hirschmann, Sofia, Marsella, Stacey, Fonken, Yvonne, Wu, Peggy, Gurney, Nikolos
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914208888651776
author Carney, Stephan
Hans, Soham
Hirschmann, Sofia
Marsella, Stacey
Fonken, Yvonne
Wu, Peggy
Gurney, Nikolos
author_facet Carney, Stephan
Hans, Soham
Hirschmann, Sofia
Marsella, Stacey
Fonken, Yvonne
Wu, Peggy
Gurney, Nikolos
contents Adversaries (hackers) attempting to infiltrate networks frequently face uncertainty in their operational environments. This research explores the ability to model and detect when they exhibit ambiguity aversion, a cognitive bias reflecting a preference for known (versus unknown) probabilities. We introduce a novel methodological framework that (1) leverages rich, multi-modal data from human-subjects red-team experiments, (2) employs a large language model (LLM) pipeline to parse unstructured logs into MITRE ATT&CK-mapped action sequences, and (3) applies a new computational model to infer an attacker's ambiguity aversion level in near-real time. By operationalizing this cognitive trait, our work provides a foundational component for developing adaptive cognitive defense strategies.
format Preprint
id arxiv_https___arxiv_org_abs_2512_08107
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Detecting Ambiguity Aversion in Cyberattack Behavior to Inform Cognitive Defense Strategies
Carney, Stephan
Hans, Soham
Hirschmann, Sofia
Marsella, Stacey
Fonken, Yvonne
Wu, Peggy
Gurney, Nikolos
Cryptography and Security
Human-Computer Interaction
Adversaries (hackers) attempting to infiltrate networks frequently face uncertainty in their operational environments. This research explores the ability to model and detect when they exhibit ambiguity aversion, a cognitive bias reflecting a preference for known (versus unknown) probabilities. We introduce a novel methodological framework that (1) leverages rich, multi-modal data from human-subjects red-team experiments, (2) employs a large language model (LLM) pipeline to parse unstructured logs into MITRE ATT&CK-mapped action sequences, and (3) applies a new computational model to infer an attacker's ambiguity aversion level in near-real time. By operationalizing this cognitive trait, our work provides a foundational component for developing adaptive cognitive defense strategies.
title Detecting Ambiguity Aversion in Cyberattack Behavior to Inform Cognitive Defense Strategies
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2512.08107