Abstract
The increasing sophistication of contemporary cyber threats has exposed fundamental limitations in traditional security mechanisms, particularly static intrusion detection systems and non-adaptive deception technologies. Modern adversaries increasingly employ multi-stage, behaviourally adaptive attack strategies that evolve in response to defensive actions, rendering isolated detection and static deception ineffective. This paper presents an autonomous AI-driven cyber deception framework that tightly integrates real time threat detection, adaptive deception orchestration, and behaviour-based adversarial attribution within a unified, closed-loop architecture. The proposed system combines a hybrid machine-learning detection engine that fuses supervised classification, anomaly detection, and temporal sequence modelling with a reinforcement learning–based deception controller that dynamically optimises deception strategies to maximise attacker engagement and intelligence gain under operational constraints. Behavioural interactions generated through deception are systematically analysed using similarity-based and probabilistic reasoning to infer adversarial tactics, techniques, and procedures aligned with the MITRE ATT&CK framework. Experimental evaluation conducted within a controlled cyber-range environment demonstrates high detection accuracy (95.4%), low mean detection latency (85 ms), strong deception believability (88% fingerprinting resistance), sustained attacker engagement of up to 280 seconds, and robust technique-level attribution accuracy (88.5%). The results show that integrating detection, deception, and behavioural attribution into an autonomous decision-making pipeline significantly enhances situational awareness and intelligence generation, advancing cyber defence from reactive monitoring toward proactive adversarial engagement
| Original language | English |
|---|---|
| Article number | 462 |
| Number of pages | 32 |
| Journal | Computers |
| Volume | 15 |
| Issue number | 7 |
| DOIs | |
| Publication status | Published - 21 Jul 2026 |
Keywords
- cyber deception
- intrusion detection
- machine learning
- reinforcement learning
- honeypots
- behavioural attribution
- autonomous cyber defence
- MITRE ATT&CK
Fingerprint
Dive into the research topics of 'An autonomous AI-driven framework for adaptive cyber deception with real-time threat detection and behaviour-based attribution'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver