• e - ISSN No : 2832-4277
IJRTTE Logo

INTERNATIONAL JOURNAL OF RECENT TRENDS IN TECHNOLOGY AND ENGINEERING (IJRTTE)

AI-Driven Adversarial Threat Simulation for Cyber-Defense Training

Kazi Kutubuddin Sayyad Liyakat
Professor, Department of Electronics and Telecommunication Engineering, Brahmdevdada Mane Institute of Technology, India.
Jeyashree Y
Associate Professor, Department of Electrical and Electronics Engineering, SRM Institute of Science and Technology, India.
Mohammed Saleh Al Ansari
Associate Professor, College of Engineering, Department of Chemical Engineering, University of Bahrain, India.

Keywords: AI-Driven Threat Simulation, Adversarial Machine Learning, Reinforcement Learning for Cybersecurity, Cyber-Defense Training, MITRE ATT&CK Framework, Cyber Range Simulation, Multi-Agent Attack–Defense Modeling.

Abstract

The rising complexity of the contemporary cyber threats has created an urgent demand of smart, adaptive and realistic systems of cyber-defense training that can equip the defenders to operate in the dynamic adversarial environments. Outdated signature-focused or policy-oriented deterrence methods do not advise the elasticity of state-of-the-array persistent threats (APTs) and evasive behavior. As a step towards overcoming these constraints, the present paper suggests an AI-Based Adversarial Threat Simulation Framework, which combines reinforcement learning, adversarial machine learning, multi-agent attacker/defender modelling and cyber-range/orchestration, which aims to build a realistic, scalable, training-friendly cyber-defense environment. The framework uses the adversarial reinforcement learning agent to generate, using a dynamic mapping to the MITRE ATT&CK framework, multi-step stealthy campaigns of intrusion autonomously with a defensive AI agent or human trainee learning to detect, classify, and suppress emerging threats. Adversarial machine learning module adds to the model to improve simulation realism to produce malicious samples which can tunnel hypotheses. It has been shown by experimental results that the adversarial agent acquires more advanced attack tactics as the percentage of success and stealth are increased by 78 percent, and the defensive accuracy is higher, decreasing the detection latency up to 40 percent. The scenario orchestration engine also converts adversarial behaviours to progressive training modules and improves automated defences and human analyst performances. The proposed framework is proved to be superior to traditional DRL-only simulators in the diversity of attacks, their resistance, and training utility by the comparative analysis. On the whole, this work offers a versatile, dynamic, and operationally applicable base of training on cyber-defense of the next generation
Download Certificate
Details

References

  1. Oh, S. H., Kim, J., & Park, J. (2024). Dynamic Cyberattack Simulation: Integrating Improved Deep Reinforcement Learning with the MITRE-ATT&CK Framework. Electronics, 13(14), 2831. https://doi.org/10.3390/electronics13142831
  2. Oh, S. H., Kim, J., Nah, J. H., & Park, J. (2024). Employing deep reinforcement learning to cyber-attack simulation for enhancing cybersecurity. Electronics, 13(3), 555. https://doi.org/10.3390/electronics13030555
  3. Kim, B.-S., Suk, H.-W., Choi, Y.-H., Moon, D.-S., & Kim, M.-S. (2024). Optimal cyber-attack strategy using reinforcement learning based on common vulnerability scoring system. CMES – Computer Modeling in Engineering and Sciences, 141(2), 1551–1574. https://doi.org/10.32604/cmes.2024.052375
  4. Bharathi, S., Selvaperumal, S., Ramasenderan, N., Thiruchelvam, V., Annamalai, D., & Reddy, M. (2025). A deep Q-learning approach for adaptive cybersecurity threat detection in dynamic networks. Bulletin of Electrical Engineering and Informatics, 14, 3788–3797. https://doi.org/10.11591/eei.v14i5.9494
  5. Alavizadeh, H., Alavizadeh, H., & Jang-Jaccard, J. (2022). Deep Q-learning based reinforcement learning approach for network intrusion detection. Computers, 11(3), 41. https://doi.org/10.3390/computers11030041
  6. Cengiz, E., & Gök, M. (2023). Reinforcement learning applications in cyber security: A review. Sakarya University Journal of Science, 27, [pages not specified]. https://doi.org/10.16984/saufenbilder.1237742
  7. Finistrella, S., Mariani, S., & Zambonelli, F. (2025). Multi-agent reinforcement learning for cybersecurity: Classification and survey. Intelligent Systems with Applications, 26, 200495. https://doi.org/10.1016/j.iswa.2025.200495
  8. Horta Neto, A. J., Santos, A., & Goldschmidt, R. (2024). Evaluating the stealth of reinforcement learning-based cyber-attacks against unknown scenarios using knowledge transfer techniques. Journal of Computer Security, 33, 1–19. https://doi.org/10.3233/JCS-230145
  9. Salem, A. H., Azzam, S. M., Emam, O. E., & others. (2024). Advancing cybersecurity: A comprehensive review of AI-driven detection techniques. Journal of Big Data, 11, 105. https://doi.org/10.1186/s40537-024-00957-y
  10. Li, B., Wu, Y., Song, J., Lu, R., Li, T., & Zhao, L. (2021). DeepFed: Federated deep learning for intrusion detection in industrial cyber–physical systems. IEEE Transactions on Industrial Informatics, 17(8), 5615–5624. https://doi.org/10.1109/TII.2020.3023430
  11. Halbouni, A., Gunawan, T. S., Habaebi, M. H., Halbouni, M., Kartiwi, M., & Ahmad, R. (2022). Machine learning and deep learning approaches for cybersecurity: A review. IEEE Access, 10, 19572–19585. https://doi.org/10.1109/ACCESS.2022.3151248
  12. Geetha, R., & Thilagam, T. (2021). A review on the effectiveness of machine learning and deep learning algorithms for cyber security. Archives of Computational Methods in Engineering, 28, 2861–2879. https://doi.org/10.1007/s11831-020-09478-2
  13. Sarker, I. H. (2021). Deep cybersecurity: A comprehensive overview from neural network and deep learning perspective. SN Computer Science, 2, 154. https://doi.org/10.1007/s42979-021-00535-6
  14. Torre, D., Mesadieu, F., & Chennamaneni, A. (2023). Deep learning techniques to detect cybersecurity attacks: A systematic mapping study. Empirical Software Engineering, 28, 76. https://doi.org/10.1007/s10664-023-10302-1
  15. Anthi, E., Williams, L., Rhode, M., Burnap, P., & Wedgbury, A. (2021). Adversarial attacks on machine learning cybersecurity defences in industrial control systems. Journal of Information Security and Applications, 58, 102717. https://doi.org/10.1016/j.jisa.2020.102717
  16. Alotaibi, A., & Rassam, M. A. (2023). Adversarial machine learning attacks against intrusion detection systems: A survey on strategies and defense. Future Internet, 15(2), 62. https://doi.org/10.3390/fi15020062
  17. Lin, Z., He, J., Zhao, Y., & others. (2025). EGRTE: Adversarially training a self-explaining smoothed classifier for certified robustness. Cybersecurity, 8, 78. https://doi.org/10.1186/s42400-025-00375-4
  18. Sun, J., & Yang, S. (2025). Adversarial sample generation based on model simulation analysis in intrusion detection systems. Electronics, 14(5), 870. https://doi.org/10.3390/electronics14050870
  19. Ennaji, S., De Gaspari, F., Hitaj, D., K/Bidi, A., & Mancini, L. (2024, September). Adversarial challenges in network intrusion detection systems: Research insights and future prospects.
  20. Chouliaras, N., Kittes, G., Kantzavelou, I., Maglaras, L., Pantziou, G., & Ferrag, M. A. (2021). Cyber ranges and testbeds for education, training, and research. Applied Sciences, 11(4), 1809. https://doi.org/10.3390/app11041809
  21. Ukwandu, E., Farah, M. A. B., Hindy, H., Brosset, D., Kavallieros, D., Atkinson, R., Tachtatzis, C., Bures, M., Andonovic, I., & Bellekens, X. (2020). A review of cyber-ranges and test-beds: Current and future trends. Sensors, 20(24), 7148. https://doi.org/10.3390/s20247148
  22. Yamin, M. M., Katt, B., & Gkioulos, V. (2020). Cyber ranges and security testbeds: Scenarios, functions, tools and architecture. Computers & Security, 88, 101636. https://doi.org/10.1016/j.cose.2019.101636
  23. Shin, Y., Kwon, H., Jeong, J., & Shin, D. (2024). A study on designing cyber training and cyber range to effectively respond to cyber threats. Electronics, 13(19), 3867. https://doi.org/10.3390/electronics13193867
  24. Lillemets, P., Bashir Jawad, N., Kashi, J., Sabah, A., & Dragoni, N. (2025). A systematic review of cyber range taxonomies: Trends, gaps, and a proposed taxonomy. Future Internet, 17(6), 259. https://doi.org/10.3390/fi17060259
  25. Ogenyi, F. C., Ugwu, C. N., & Ugwu, O. P.-C. (2025). Securing the future: AI-driven cybersecurity in the age of autonomous IoT. Frontiers in the Internet of Things, 4, 1658273. https://doi.org/10.3389/friot.2025.1658273
  26. Gupta, C., Johri, I., Srinivasan, K., Hu, Y.-C., Qaisar, S. M., & Huang, K.-Y. (2022). A systematic review on machine learning and deep learning models for electronic information security in mobile networks. Sensors, 22(5), 2017. https://doi.org/10.3390/s22052017