{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T12:08:23Z","timestamp":1779192503252,"version":"3.51.4"},"reference-count":50,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T00:00:00Z","timestamp":1776038400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"funder":[{"DOI":"10.13039\/100018709","name":"European Defence Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100018709","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018894","name":"European Defence Agency","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100018894","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Information Fusion"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.inffus.2026.104359","type":"journal-article","created":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T09:11:09Z","timestamp":1775898669000},"page":"104359","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Enhancing strategic decision-making via semantic inference: An adaptive framework for threat actor profiling"],"prefix":"10.1016","volume":"134","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-0586-1080","authenticated-orcid":false,"given":"Pedro","family":"Beltr\u00e1n-L\u00f3pez","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7768-9665","authenticated-orcid":false,"given":"Manuel","family":"Gil P\u00e9rez","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4041-1205","authenticated-orcid":false,"given":"Pantaleone","family":"Nespoli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.inffus.2026.104359_bib0001","first-page":"1","article-title":"Cyber threat: its origins and consequence and the use of qualitative and quantitative methods in cyber risk assessment","author":"Crotty","year":"2022","journal-title":"Appl. Comput. Inform."},{"key":"10.1016\/j.inffus.2026.104359_bib0002","first-page":"1","article-title":"Tackling cyberattacks through AI-based reactive systems: a holistic review and future vision","author":"Nespoli","year":"2025","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.inffus.2026.104359_bib0003","series-title":"Antifragile: Things that gain from disorder","volume":"3","author":"Taleb","year":"2014"},{"key":"10.1016\/j.inffus.2026.104359_bib0004","doi-asserted-by":"crossref","DOI":"10.3389\/fpsyg.2023.1165705","article-title":"Understanding decision making in security operations centres: building the case for cyber deception technology","volume":"14","author":"Reeves","year":"2023","journal-title":"Front. Psychol."},{"key":"10.1016\/j.inffus.2026.104359_bib0005","first-page":"1","article-title":"Cyber deception: taxonomy, state of the art, frameworks, trends, and open challenges","author":"Beltr\u00e1n-L\u00f3pez","year":"2025","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.inffus.2026.104359_bib0006","unstructured":"B.A. AL-Zahrani, Adaptive Deception Framework with Behavioral Analysis for Enhanced Cybersecurity Defense, (2025). arXiv preprint arXiv: 2510.02424."},{"key":"10.1016\/j.inffus.2026.104359_bib0007","unstructured":"D.S.L. Cybersecurity and (CyberDataLab), CyberDeception-Threat_Actor_Profiling, 2025, (https:\/\/github.com\/CyberDataLab\/CyberDeception-Threat_Actor_Profiling). Accessed: 2025-12-16."},{"key":"10.1016\/j.inffus.2026.104359_bib0008","series-title":"29th Int. Conf. Comput. Linguist.","first-page":"4593","article-title":"SHAP-based explanation methods: a review for NLP interpretability","author":"Mosca","year":"2022"},{"key":"10.1016\/j.inffus.2026.104359_bib0009","series-title":"Int. Conf. Cyber Conflict (CyCon)","first-page":"327","article-title":"Threat actor type inference and characterization within cyber threat intelligence","author":"Mavroeidis","year":"2021"},{"key":"10.1016\/j.inffus.2026.104359_bib0010","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103350","article-title":"CPID: Insider threat detection using profiling and cyber-persona identification","volume":"132","author":"Racherache","year":"2023","journal-title":"Comput. Secur."},{"issue":"4","key":"10.1016\/j.inffus.2026.104359_bib0011","doi-asserted-by":"crossref","first-page":"2028","DOI":"10.3390\/s23042028","article-title":"Cyber attacker profiling for risk analysis based on machine learning","volume":"23","author":"Kotenko","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.inffus.2026.104359_bib0012","unstructured":"U. Noor, S. Shahid, R. Kanwal, Z. Rashid, A Machine Learning based Empirical Evaluation of Cyber Threat Actors High Level Attack Patterns over Low level Attack Patterns in Attributing Attacks, (2023). arXiv: 2307.10252."},{"key":"10.1016\/j.inffus.2026.104359_bib0013","unstructured":"MITRE Corporation, MITRE ATT&CK, 2025, (????). Accessed: 2025-12-16, https:\/\/attack.mitre.org."},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0014","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1016\/j.eij.2022.11.001","article-title":"Cyber threat attribution using unstructured reports in cyber threat intelligence","volume":"24","author":"Irshad","year":"2023","journal-title":"Egypt Inform. J."},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0015","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1017\/S1351324916000334","article-title":"Word2Vec","volume":"23","author":"Church","year":"2017","journal-title":"Nat. Lang. Eng."},{"key":"10.1016\/j.inffus.2026.104359_bib0016","series-title":"Int. Conf. ICT Smart Soc.","first-page":"1","article-title":"Automated threat hunting, detection, and threat actor profiling using TIRA","author":"Yulianto","year":"2024"},{"key":"10.1016\/j.inffus.2026.104359_bib0017","series-title":"IEEE 22nd World Symp. Appl. Mach. Intell. Inform. (SAMI)","first-page":"175","article-title":"Concept for real time attacker profiling with honeypots, by skill based attacker maturity model","author":"Balogh","year":"2024"},{"key":"10.1016\/j.inffus.2026.104359_bib0018","unstructured":"J. Quibell, Towards in-situ Psychological Profiling of Cybercriminals Using Dynamically Generated Deception Environments, (2024). arXiv: 2405.11497."},{"issue":"9","key":"10.1016\/j.inffus.2026.104359_bib0019","doi-asserted-by":"crossref","first-page":"1364","DOI":"10.3390\/math12091364","article-title":"IPAttributor: Cyber attacker attribution with threat intelligence-enriched intrusion data","volume":"12","author":"Xiang","year":"2024","journal-title":"Math."},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0020","first-page":"70","article-title":"Machine learning approach for classification of cyber threats actors in web region","volume":"6","author":"Edet","year":"2024","journal-title":"J. Technol. Inform."},{"issue":"3","key":"10.1016\/j.inffus.2026.104359_bib0021","doi-asserted-by":"crossref","first-page":"553","DOI":"10.1016\/j.icte.2024.04.005","article-title":"Context-aware cyber-threat attribution based on hybrid features","volume":"10","author":"Irshad","year":"2024","journal-title":"ICT Express"},{"key":"10.1016\/j.inffus.2026.104359_bib0022","unstructured":"Electronic Transactions Development Agency (ETDA), Threat Group Cards: A Threat Actor Encyclopaedia, 2023, (https:\/\/apt.etda.or.th\/cgi-bin\/aptgroups.cgi). [Accessed: 2025-12-16]."},{"issue":"12","key":"10.1016\/j.inffus.2026.104359_bib0023","doi-asserted-by":"crossref","first-page":"9388","DOI":"10.1109\/TKDE.2024.3474792","article-title":"Threatinsight: innovating early threat detection through threat-intelligence-driven analysis and attribution","volume":"36","author":"Wang","year":"2024","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.inffus.2026.104359_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103960","article-title":"APT-MMF: An advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion","volume":"144","author":"Xiao","year":"2024","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0025","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3676284","article-title":"Unveiling cyber threat actors: a hybrid deep learning approach for behavior-based attribution","volume":"6","author":"B\u00f6ge","year":"2025","journal-title":"Digit. Threats Res. Pract."},{"issue":"2","key":"10.1016\/j.inffus.2026.104359_bib0026","doi-asserted-by":"crossref","first-page":"1361","DOI":"10.1109\/COMST.2017.2781126","article-title":"Optimal countermeasures selection against cyber attacks: a comprehensive survey on reaction frameworks","volume":"20","author":"Nespoli","year":"2017","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.inffus.2026.104359_bib0027","series-title":"Technical Report","article-title":"Standardizing cyber threat intelligence information with the structured threat information expression (STIX)","author":"Barnum","year":"2012"},{"key":"10.1016\/j.inffus.2026.104359_bib0028","article-title":"Cyber threat intelligence model: an evaluation of taxonomies, sharing standards, and ontologies within cyber threat intelligence","volume":"abs\/2103.03530","author":"Mavroeidis","year":"2021","journal-title":"CoRR"},{"key":"10.1016\/j.inffus.2026.104359_bib0029","series-title":"2016 ACM Workshop Inf. Shar. Collab. Secur. (WISCS)","first-page":"49","article-title":"MISP: The design and implementation of a collaborative threat intelligence sharing platform","author":"Wagner","year":"2016"},{"issue":"5","key":"10.1016\/j.inffus.2026.104359_bib0030","first-page":"375","article-title":"An efficient self attention-based 1D-CNN-LSTM network for IoT attack detection and identification using network traffic","volume":"3","author":"Sasi","year":"2025","journal-title":"J. Inf. Intell."},{"issue":"13","key":"10.1016\/j.inffus.2026.104359_bib0031","doi-asserted-by":"crossref","first-page":"5941","DOI":"10.3390\/s23135941","article-title":"CICIoT2023: a real-time dataset and benchmark for large-scale attacks in IoT environment","volume":"23","author":"Neto","year":"2023","journal-title":"Sensors"},{"key":"10.1016\/j.inffus.2026.104359_bib0032","series-title":"Int. Conf. Privacy Secur. Trust (PST)","first-page":"1","article-title":"Towards the development of a realistic multidimensional IoT profiling dataset","author":"Dadkhah","year":"2022"},{"key":"10.1016\/j.inffus.2026.104359_bib0033","series-title":"21St Annu. Int. Conf. Privacy Secur. Trust (PST)","first-page":"1","article-title":"Poisoning and evasion: deep learning-Based NIDS under adversarial attacks","author":"Mohammadian","year":"2024"},{"issue":"2","key":"10.1016\/j.inffus.2026.104359_bib0034","first-page":"107","article-title":"DSRL-APT-2023: A new synthetic dataset for advanced persistent threats","volume":"17","author":"Shadabfar","year":"2024","journal-title":"ISC Int. J. Inf. Secur."},{"key":"10.1016\/j.inffus.2026.104359_bib0035","series-title":"Deployable Mach. Learn. Secur. Def. First Int. Workshop, MLHat 2020","first-page":"138","article-title":"DAPT 2020\u2013Constructing a benchmark dataset for advanced persistent threats","author":"Myneni","year":"2020"},{"key":"10.1016\/j.inffus.2026.104359_bib0036","unstructured":"Stratosphere IPS, Malware Capture Facility Project, 2020, (https:\/\/www.stratosphereips.org\/datasets-malware). Accessed: 2025-12-16."},{"key":"10.1016\/j.inffus.2026.104359_bib0037","article-title":"IoT-23: A labeled dataset with malicious and benign IoT network traffic","author":"Garcia","year":"2020","journal-title":"Zenodo"},{"key":"10.1016\/j.inffus.2026.104359_bib0038","series-title":"IEEE Glob. Workshops","first-page":"1365","article-title":"Machine learning 5G attack detection in programmable logic","author":"Coldwell","year":"2022"},{"key":"10.1016\/j.inffus.2026.104359_bib0039","unstructured":"S. Samarakoon, Y. Siriwardhana, P. Porambage, M. Liyanage, S.-Y. Chang, J. Kim, J. Kim, M. Ylianttila, 5G-NIDD: A comprehensive network intrusion detection dataset generated over 5G wireless network, (2022). arXiv: 2212.01298."},{"key":"10.1016\/j.inffus.2026.104359_bib0040","series-title":"Crit. Inf. Infrastruct. Secur.","first-page":"230","article-title":"Denial of service attacks: detecting the frailties of machine learning algorithms in the classification process","author":"Fraz\u00e3o","year":"2019"},{"key":"10.1016\/j.inffus.2026.104359_bib0041","series-title":"3Rd Int. Conf. Inf. Syst. Secur. Priv.","first-page":"253","article-title":"Characterization of tor traffic using time based features","volume":"2","author":"Lashkari","year":"2017"},{"key":"10.1016\/j.inffus.2026.104359_bib0042","series-title":"2Nd Int. Conf. Inf. Syst. Secur. Priv.","first-page":"407","article-title":"Characterization of encrypted and VPN traffic using time-related","volume":"1","author":"Draper Gil","year":"2016"},{"key":"10.1016\/j.inffus.2026.104359_bib0043","series-title":"South. Assoc. Inf. Syst. Conf.","first-page":"141","article-title":"Graph database applications and concepts with neo4j","author":"Miller","year":"2013"},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0044","doi-asserted-by":"crossref","first-page":"5233","DOI":"10.1038\/s41598-019-41695-z","article-title":"From Louvain to Leiden: guaranteeing well-connected communities","volume":"9","author":"Traag","year":"2019","journal-title":"Sci. Rep."},{"issue":"2","key":"10.1016\/j.inffus.2026.104359_bib0045","doi-asserted-by":"crossref","first-page":"1153","DOI":"10.1109\/COMST.2015.2494502","article-title":"A survey of data mining and machine learning methods for cyber security intrusion detection","volume":"18","author":"Buczak","year":"2015","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0046","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1186\/s40537-020-00318-5","article-title":"Cybersecurity data science: an overview from machine learning perspective","volume":"7","author":"Sarker","year":"2020","journal-title":"J. Big Data"},{"issue":"1","key":"10.1016\/j.inffus.2026.104359_bib0047","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1186\/s40537-024-00886-w","article-title":"Machine learning-based network intrusion detection for big and imbalanced data using oversampling, stacking feature embedding and feature extraction","volume":"11","author":"Talukder","year":"2024","journal-title":"J. Big Data"},{"issue":"3","key":"10.1016\/j.inffus.2026.104359_bib0048","doi-asserted-by":"crossref","first-page":"530","DOI":"10.3390\/electronics9030530","article-title":"A two-level flow-based anomalous activity detection system for IoT networks","volume":"9","author":"Ullah","year":"2020","journal-title":"Electronics"},{"key":"10.1016\/j.inffus.2026.104359_bib0049","series-title":"16th Eur. Conf. Cyber Warfare Secur. (ECCWS)","first-page":"361","article-title":"Flow-based benchmark data sets for intrusion detection","author":"Ring","year":"2017"},{"issue":"7","key":"10.1016\/j.inffus.2026.104359_bib0050","doi-asserted-by":"crossref","DOI":"10.1111\/cogs.13013","article-title":"Towards a cognitive theory of cyber deception","volume":"45","author":"Cranford","year":"2021","journal-title":"Cogn. Sci."}],"container-title":["Information Fusion"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1566253526002381?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1566253526002381?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T11:40:57Z","timestamp":1779190857000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1566253526002381"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":50,"alternative-id":["S1566253526002381"],"URL":"https:\/\/doi.org\/10.1016\/j.inffus.2026.104359","relation":{},"ISSN":["1566-2535"],"issn-type":[{"value":"1566-2535","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Enhancing strategic decision-making via semantic inference: An adaptive framework for threat actor profiling","name":"articletitle","label":"Article Title"},{"value":"Information Fusion","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.inffus.2026.104359","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier B.V.","name":"copyright","label":"Copyright"}],"article-number":"104359"}}