CERESResearch Repository

AC_MAPPER: a robust approach to ATT&CK technique classification using input augmentation and class rebalancing

dc.contributor.authorAlbarrak, Majed
dc.contributor.authorAlqudhaibi, Adel
dc.contributor.authorJagtap, Sandeep
dc.date.accessioned2025-11-25T11:24:12Z
dc.date.available2025-11-25T11:24:12Z
dc.date.freetoread2025-11-25
dc.date.issued2025-11-07
dc.date.pubOnline2025-11-07
dc.description.abstractThe detection and classification of adversarial techniques from cyber threat intelligence (CTI) text is a critical task in threat analysis and mitigation. While recent transformer-based models have shown promise, their general-purpose nature often limits effectiveness on complex, domain-specific datasets. In this paper, we present a novel model designed to address the challenges of technique classification across heterogeneous CTI datasets. The proposed method is evaluated against several baselines, including CTI-specific models as well as general-purpose transformers like SciBERT and DistilBERT. The proposed approach “AC_MAPPER” consistently outperforms all baselines in both Accuracy and F1 scores across five benchmark datasets, achieving up to 93.59% accuracy and 93.78% macro F1 on the TRAM Bootstrap dataset. It also demonstrates superior robustness on highly imbalanced and sparse datasets such as HALdata and CAPEC, where baseline models struggle. Comprehensive performance comparisons, highlights the effectiveness of proposed approach. These results underscore the potential of integrating domain-specific design with transformer architectures to advance automated CTI analysis. Our findings contribute toward more accurate and reliable threat detection systems in real-world security applications.
dc.description.journalNameInternational Journal of Information Security
dc.description.sponsorshipLunds Universitet
dc.identifier.citationAlbarrak M, Alqudhaibi A, Jagtap S. (2025) AC_MAPPER: a robust approach to ATT&CK technique classification using input augmentation and class rebalancing. International Journal of Information Security, Volume 24, Issue 6, November 2025, Article number 232en_UK
dc.identifier.eissn1615-5270
dc.identifier.elementsID866400
dc.identifier.issn1615-5262
dc.identifier.issueNo6
dc.identifier.paperNo232
dc.identifier.urihttps://doi.org/10.1007/s10207-025-01146-5
dc.identifier.urihttps://dspace.lib.cranfield.ac.uk/handle/1826/24678
dc.identifier.volumeNo24
dc.languageEnglish
dc.language.isoen
dc.publisherSpringeren_UK
dc.publisher.urihttps://link.springer.com/article/10.1007/s10207-025-01146-5
dc.rightsAttribution 4.0 Internationalen
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.subjectCyber threat intelligence (CTI)en_UK
dc.subjectMITRE ATT&CK frameworken_UK
dc.subjectNatural language processing (NLP)en_UK
dc.subjectLarge language models (LLMs)en_UK
dc.subjectData augmentationen_UK
dc.subject4605 Data Management and Data Scienceen_UK
dc.subject46 Information and Computing Sciencesen_UK
dc.subject4611 Machine Learningen_UK
dc.subjectStrategic, Defence & Security Studiesen_UK
dc.titleAC_MAPPER: a robust approach to ATT&CK technique classification using input augmentation and class rebalancingen_UK
dc.typeArticle
dc.type.subtypeJournal Article
dcterms.dateAccepted2025-10-20

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
AC_MAPPER-a_robust_approach-2025.pdf
Size:
3.48 MB
Format:
Adobe Portable Document Format
Description:
Published version

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.63 KB
Format:
Plain Text
Description: