Skip to main navigation Skip to search Skip to main content

An autonomous AI-driven framework for adaptive cyber deception with real-time threat detection and behaviour-based attribution

    Research output: Contribution to journalArticlepeer-review

    Abstract

    The increasing sophistication of contemporary cyber threats has exposed fundamental limitations in traditional security mechanisms, particularly static intrusion detection systems and non-adaptive deception technologies. Modern adversaries increasingly employ multi-stage, behaviourally adaptive attack strategies that evolve in response to defensive actions, rendering isolated detection and static deception ineffective. This paper presents an autonomous AI-driven cyber deception framework that tightly integrates real time threat detection, adaptive deception orchestration, and behaviour-based adversarial attribution within a unified, closed-loop architecture. The proposed system combines a hybrid machine-learning detection engine that fuses supervised classification, anomaly detection, and temporal sequence modelling with a reinforcement learning–based deception controller that dynamically optimises deception strategies to maximise attacker engagement and intelligence gain under operational constraints. Behavioural interactions generated through deception are systematically analysed using similarity-based and probabilistic reasoning to infer adversarial tactics, techniques, and procedures aligned with the MITRE ATT&CK framework. Experimental evaluation conducted within a controlled cyber-range environment demonstrates high detection accuracy (95.4%), low mean detection latency (85 ms), strong deception believability (88% fingerprinting resistance), sustained attacker engagement of up to 280 seconds, and robust technique-level attribution accuracy (88.5%). The results show that integrating detection, deception, and behavioural attribution into an autonomous decision-making pipeline significantly enhances situational awareness and intelligence generation, advancing cyber defence from reactive monitoring toward proactive adversarial engagement
    Original languageEnglish
    Article number462
    Number of pages32
    JournalComputers
    Volume15
    Issue number7
    DOIs
    Publication statusPublished - 21 Jul 2026

    Keywords

    • cyber deception
    • intrusion detection
    • machine learning
    • reinforcement learning
    • honeypots
    • behavioural attribution
    • autonomous cyber defence
    • MITRE ATT&CK

    Fingerprint

    Dive into the research topics of 'An autonomous AI-driven framework for adaptive cyber deception with real-time threat detection and behaviour-based attribution'. Together they form a unique fingerprint.

    Cite this