Towards an AI-driven adaptive framework for cybersecurity assessment
Received date: 2025-10-31
Online published: 2026-04-01
Copyright
Against the backdrop of an increasingly complex and dynamically evolving cyber threat landscape, traditional static and periodic cybersecurity assessment methods are no longer sufficient to address emerging challenges. An AI-driven adaptive cybersecurity assessment framework is proposed to realize the intellectualization, automation and continuity of the assessment process. The framework is constructed as a closed-loop system consisting of four layers: data perception, intelligent analysis, dynamic decision-making and feedback optimization. Its core innovation resides in the in-depth integration of artificial intelligence technologies, which involves applying Graph Neural Networks (GNN) for anomaly detection and threat hunting, adopting Deep Reinforcement Learning (DRL) to enable automated penetration testing and attack path planning, and incorporating Large Language Models (LLM) to achieve automated generation of analysis reports. Simulation experiments verify that the proposed framework exhibits remarkable advantages over traditional methods in the depth of vulnerability discovery, the speed of threat response and the accuracy of risk assessment. It can effectively improve the capability of proactive defense, and thus provide a feasible technical approach and practical reference for constructing a dynamic and adaptive next-generation cybersecurity system.
Ji Lijian , Lin Weiwei , Duan Chao , He Tao , Yu Cun . Towards an AI-driven adaptive framework for cybersecurity assessment[J]. Journal of Cybersecurity, 2025 , 3(5) : 61 -72 . DOI: 10.20172/j.issn.2097-3136.250506
表 1 漏洞与威胁发现能力对比情况(召回率)Table 1 Comparison of vulnerability and threat detection capabilities (Recall) |
| 漏洞类型 | 召回率 | |
| 方案A | 方案B | |
| SQL注入 | 100% | 100% |
| XSS | 80% | 100% |
| 不安全的直接对象引用 | 50% | 100% |
| 复杂的权限提升链 | 0% | 75% |
表 2 漏洞与威胁发现能力对比情况(平均精确率)Table 2 Comparison of vulnerability and threat detection capabilities (Average precision) |
| 方案 | 平均精确率 |
| A | 92% |
| B | 96% |
| 1 |
IBM Security. Cost of a data breach report 2023[EB/OL]. [2025-08-12]. https://www.ibm.com/reports/data-breach.
|
| 2 |
He Z, et al. A Transformer-based deep learning approach for network intrusion detection[J/OL]. Computers & Security, 2022, 121: 102839. https://doi.org/10.1016/j.cose.2022.102839.
|
| 3 |
Microsoft. CyberBattleSim[EB/OL]. [2025-08-12]. https://github.com/microsoft/CyberBattleSim.
|
| 4 |
Schneider J, et al. Multi-agent reinforcement learning for autonomous cyber operations[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM Press, 2023: 123-135.
|
| 5 |
Risch M, et al. LLM-as-a-Soc-Analyst: evaluating the utility of large language models for security operations center tasks[PP/OL]. arXiv: 2404.01245, [2025-08-12]. https://arxiv.org/abs/2404.01245.
|
| 6 |
MLCommons. Jailbreak Benchmark: measuring AI resilience to adversarial attacks [EB/OL]. [2025-08-12]. https://mlcommons.org/en/jailbreak-benchmark-2025/.
|
| 7 |
MLCommons. MLCommons unveils new jailbreak benchmark, quantifying AI's "Resilience gap" to adversarial attacks[EB/OL]. [2025-11-12]. https://mlcommons.org.
|
| 8 |
Zhang L, et al. Malware classification with graph convolutional network on system call graphs[J]. Journal of Computer Science and Technology, 2021, 36 (5): 1097- 1111.
|
| 9 |
Wang Y, et al. Autonomous penetration testing for web applications using deep reinforcement learning[J]. Computers & Security, 2023, 124, 102956.
|
| 10 |
Alenezi M, Almustafa K. A comparative evaluation of vulnerability scanners for web applications: coverage and accuracy[J]. IEEE Access, 2024, 12, 12345- 12358.
|
| 11 |
The MITRE Corporation. D3FEND: a knowledge graph of cybersecurity countermeasures[EB/OL]. [2025-08-12]. https://d3fend.mitre.org/.
|
| 12 |
Cloud Security Alliance (CSA). Continuous adaptive security: a framework for cloud-native environments[EB/OL]. [2025-08-12]. https://cloudsecurityalliance.org.
|
| 13 |
Vinayakumar R, et al. A comparative analysis of deep learning approaches for network intrusion detection[J]. Journal of Network and Computer Applications, 2021, 191, 103147.
|
| 14 |
Zhou J, et al. Heterogeneous graph neural network for cyber attack scenario reconstruction[J]. IEEE Transactions on Information Forensics and Security, 2023, 18, 2347- 2360.
|
| 15 |
Li C, et al. MAGPIE: A Benchmark for multi-agent contextual privacy evaluation[C]//Proceedings of the 2025 AAAI Conference on Artificial Intelligence. Palo Alto: AAAI Press, 2025.
|
| 16 |
Sudhakar G, Chandra S R V, Sunitha M, et al. Hybrid AI-based threat prediction and mitigation framework for securing cloud storage[J]. The European Physical Journal Plus, 2025, 140 (10): 982.
|
| 17 |
Canadian Institute for Cybersecurity. CIC-IDS2017 dataset[EB/OL]. [2025-08-12]. https://www.unb.ca/cic/datasets/ids-2017.html.
|
| 18 |
张伟, 李静. 生成式AI驱动的网络安全漏洞评估与风险管理: 系统分类与技术演进[J] 计算机研究与发展, 2005, 62(5), 1050-1065.
Zhang W, Li J. Generative AI-driven cybersecurity vulnerability assessment and risk management: system classification and technology evolution[J]. Journal of Computer Research and Development, 2025, 62(5): 1050-1065.
|
| 19 |
Sharma A, Rani S, Shabaz M. A comprehensive review of explainable AI in cybersecurity: Decoding the black box[J]. ICT Express, 2025, 11 (6): 1200- 1219.
|
| 20 |
Sokol K, Flach P. Explainability fact sheets: a framework for systematic assessment of explainable approaches[C]//Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency. New York: ACM Press, 2020: 56-67.
|
/
| 〈 |
|
〉 |