CERESResearch Repository

AC_MAPPER: a robust approach to ATT&CK technique classification using input augmentation and class rebalancing

Loading...
Thumbnail Image

Date published

Free to read from

2025-11-25

Supervisor/s

Industry supervisor/s

Journal Title

Journal ISSN

Volume Title

Publisher

Department

Course name

ISSN

1615-5262

Format

Citation

Albarrak M, Alqudhaibi A, Jagtap S. (2025) AC_MAPPER: a robust approach to ATT&CK technique classification using input augmentation and class rebalancing. International Journal of Information Security, Volume 24, Issue 6, November 2025, Article number 232

Abstract

The detection and classification of adversarial techniques from cyber threat intelligence (CTI) text is a critical task in threat analysis and mitigation. While recent transformer-based models have shown promise, their general-purpose nature often limits effectiveness on complex, domain-specific datasets. In this paper, we present a novel model designed to address the challenges of technique classification across heterogeneous CTI datasets. The proposed method is evaluated against several baselines, including CTI-specific models as well as general-purpose transformers like SciBERT and DistilBERT. The proposed approach “AC_MAPPER” consistently outperforms all baselines in both Accuracy and F1 scores across five benchmark datasets, achieving up to 93.59% accuracy and 93.78% macro F1 on the TRAM Bootstrap dataset. It also demonstrates superior robustness on highly imbalanced and sparse datasets such as HALdata and CAPEC, where baseline models struggle. Comprehensive performance comparisons, highlights the effectiveness of proposed approach. These results underscore the potential of integrating domain-specific design with transformer architectures to advance automated CTI analysis. Our findings contribute toward more accurate and reliable threat detection systems in real-world security applications.

Description

Software description

Software language

Git repository

Keywords

Cyber threat intelligence (CTI), MITRE ATT&CK framework, Natural language processing (NLP), Large language models (LLMs), Data augmentation, 4605 Data Management and Data Science, 46 Information and Computing Sciences, 4611 Machine Learning, Strategic, Defence & Security Studies

DOI

Rights

Attribution 4.0 International

Funder/s

Lunds Universitet

Grant number

Relationships

Relationships

Resources