Using a Stack to Find an AI Needle : Topic Modeling for Cyber Threat Intelligence

dc.contributor.authorSchröer, Saskia Laura
dc.contributor.authorSeideman, Jeremy D.
dc.contributor.authorLuo, Shoufu
dc.contributor.authorApruzzese, Giovanni
dc.contributor.authorDietrich, Sven
dc.contributor.authorLaskov, Pavel
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-10-02T13:14:01Z
dc.date.available2026-10-02T13:14:01Z
dc.date.issued2025-12-15
dc.descriptionPublisher Copyright: © 2025 Copyright held by the owner/author(s).en
dc.description.abstractCyber Threat Intelligence (CTI) is a fundamental activity to ensure the protection of modern organizations against sophisticated cyberattackers. A large body of literature has addressed problems related to CTI. Despite the scientific validity of such results, the reality is that CTI practitioners rarely deploy advanced CTI methods proposed by the research community and mostly rely on manual processes. We seek to facilitate the manual analyses typical for CTI practice by proposing a novel topic modeling technique that enables analysts to identify specific topics in CTI data sources. We demonstrate how our method, released as an open source tool, can be used to investigate three case studies revolving around the research question whether attackers are deploying AI for malicious purposes “in the wild,” and, if so, what features of AI interest them the most. We analyzed 7 million discussions from 18 underground forums. Our findings reveal that attackers may favor easy-to-use AI toolkits over the sophisticated AI techniques envisioned in research papers. Our contributions are further validated by a user study (N = 24) with CTI experts, confirming the relevance of our research. Ultimately, we advocate future endeavors to account for the opinion of CTI practitioners—who should, in turn, try to cooperate.en
dc.description.versionPeer revieweden
dc.format.extent18095577
dc.format.extent
dc.identifier.citationSchröer, S L, Seideman, J D, Luo, S, Apruzzese, G, Dietrich, S & Laskov, P 2025, 'Using a Stack to Find an AI Needle : Topic Modeling for Cyber Threat Intelligence', Digital Threats: Research and Practice, vol. 6, no. 4, 32. https://doi.org/10.1145/3766908en
dc.identifier.doi10.1145/3766908
dc.identifier.issn2576-5337
dc.identifier.other250863845
dc.identifier.other05f6e81e-0936-42ca-b335-3bd56c10b2d5
dc.identifier.other105026280830
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8514
dc.language.isoen
dc.relation.ispartofseriesDigital Threats: Research and Practice; 6(4)en
dc.relation.urlhttps://www.scopus.com/pages/publications/105026280830en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.subjectCyber Threat Intelligenceen
dc.subjectUnderground Forumsen
dc.subjectUser Studyen
dc.subjectSoftwareen
dc.subjectInformation Systemsen
dc.subjectSafety Researchen
dc.subjectHardware and Architectureen
dc.subjectComputer Science Applicationsen
dc.subjectComputer Networks and Communicationsen
dc.titleUsing a Stack to Find an AI Needle : Topic Modeling for Cyber Threat Intelligenceen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontojournal/articleen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
3766908.pdf
Stærð:
17.26 MB
Snið:
Adobe Portable Document Format