{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T14:30:11Z","timestamp":1785335411634,"version":"3.55.0"},"reference-count":109,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2025,4,10]],"date-time":"2025-04-10T00:00:00Z","timestamp":1744243200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The automated identification and evaluation of potential attack paths within infrastructures is a critical aspect of cybersecurity risk assessment. However, existing methods become impractical when applied to complex infrastructures. While machine learning (ML) has proven effective in predicting the exploitation of individual vulnerabilities, its potential for full-path prediction remains largely untapped. This challenge stems from two key obstacles: the lack of adequate datasets for training the models and the dimensionality of the learning problem. To address the first issue, we provide a dataset of 1033 detailed environment graphs and associated attack paths, with the objective of supporting the community in advancing ML-based attack path prediction. To tackle the second, we introduce a novel Physics-Informed Graph Neural Network (PIGNN) architecture for attack path prediction. Our experiments demonstrate its effectiveness, achieving an F1 score of 0.9308 for full-path prediction. We also introduce a self-supervised learning architecture for initial access and impact prediction, achieving F1 scores of 0.9780 and 0.8214, respectively. Our results indicate that the PIGNN effectively captures adversarial patterns in high-dimensional spaces, demonstrating promising generalization potential towards fully automated assessments.<\/jats:p>","DOI":"10.3390\/jcp5020015","type":"journal-article","created":{"date-parts":[[2025,4,10]],"date-time":"2025-04-10T10:47:41Z","timestamp":1744282061000},"page":"15","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Physics-Informed Graph Neural Networks for Attack Path Prediction"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5661-8131","authenticated-orcid":false,"given":"Marin","family":"Fran\u00e7ois","sequence":"first","affiliation":[{"name":"Laboratoire d\u2019Analyse et de Mod\u00e9lisation de Syst\u00e8mes pour l\u2019Aide \u00e0 la D\u00e9cision (LAMSADE), UMR CNRS 7243, Universit\u00e9 Paris-Dauphine PSL, 75775 Paris, France"},{"name":"Dauphine Recherches en Management (DRM), UMR CNRS 7088, Universit\u00e9 Paris-Dauphine PSL, 75775 Paris, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pierre-Emmanuel","family":"Arduin","sequence":"additional","affiliation":[{"name":"Dauphine Recherches en Management (DRM), UMR CNRS 7088, Universit\u00e9 Paris-Dauphine PSL, 75775 Paris, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Myriam","family":"Merad","sequence":"additional","affiliation":[{"name":"Laboratoire d\u2019Analyse et de Mod\u00e9lisation de Syst\u00e8mes pour l\u2019Aide \u00e0 la D\u00e9cision (LAMSADE), UMR CNRS 7243, Universit\u00e9 Paris-Dauphine PSL, 75775 Paris, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,4,10]]},"reference":[{"key":"ref_1","first-page":"31","article-title":"From information to a system","volume":"9","author":"Minden","year":"2000","journal-title":"Behav. Healthc. Tomorrow"},{"key":"ref_2","unstructured":"Servigne, S. (2010). Conception, architecture et urbanisation des syst\u00e8mes d\u2019information. Encyclop\u00e6dia Universalis, Encyclop\u00e6dia Universalis."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Yu, E.S.K. (2004). Information Systems. The Practical Handbook of Internet Computing, Chapman and Hall\/CRC.","DOI":"10.1201\/9780203507223.ch33"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1111\/rmir.12169","article-title":"Cyber risk management: History and future research directions","volume":"24","author":"Eling","year":"2021","journal-title":"Risk Manag. Insur. Rev."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1080\/07421222.1985.11517734","article-title":"Managing the risks associated with end-user computing","volume":"2","author":"Alavi","year":"1985","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1080\/07421222.1991.11517914","article-title":"Risk analysis for information technology","volume":"8","author":"Rainer","year":"1991","journal-title":"J. Manag. Inf. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"597","DOI":"10.1016\/0167-4048(93)90056-B","article-title":"A comparative framework for risk analysis methods","volume":"12","author":"Eloff","year":"1993","journal-title":"Comput. Secur."},{"key":"ref_8","unstructured":"Whitman, M.E., and Mattord, H.J. (2009). Principles of Information Security, Thomson Course Technology."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Naik, N., Jenkins, P., Grace, P., and Song, J. (2022, January 24\u201326). Comparing attack models for IT systems: Lockheed Martin\u2019s Cyber Kill Chain, MITRE ATT&CK Framework and Diamond Model. Proceedings of the 2022 IEEE International Symposium on Systems Engineering (ISSE), Vienna, Austria.","DOI":"10.1109\/ISSE54508.2022.10005490"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1007\/s10207-023-00751-6","article-title":"Start thinking in graphs: Using graphs to address critical attack paths in a Microsoft cloud tenant","volume":"23","author":"Elmiger","year":"2024","journal-title":"Int. J. Inf. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Dunagan, J., Zheng, A.X., and Simon, D.R. (2009, January 11\u201314). Heat-ray: Combating identity snowball attacks using machinelearning, combinatorial optimization and attack graphs. Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles, Big Sky, MT, USA.","DOI":"10.1145\/1629575.1629605"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Irfan, A.N., Chuprat, S., Mahrin, M.N., and Ariffin, A. (2022, January 19\u201321). Taxonomy of cyber threat intelligence framework. Proceedings of the 2022 13th International Conference on Information and Communication Technology Convergence (ICTC), Jeju Island, Republic of Korea.","DOI":"10.1109\/ICTC55196.2022.9952616"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1016\/S0167-4048(99)80115-1","article-title":"Simulating cyber attacks, defences, and consequences","volume":"18","author":"Cohen","year":"1999","journal-title":"Comput. Secur."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Kuhl, M.E., Sudit, M., Kistner, J., and Costantini, K. (2007, January 9\u201312). Cyber attack modeling and simulation for network security analysis. Proceedings of the 2007 Winter Simulation Conference, Washington, DC, USA.","DOI":"10.1109\/WSC.2007.4419720"},{"key":"ref_15","unstructured":"Abraham, S., and Nair, S. (2025, April 07). A Novel Architecture for Predictive CyberSecurity Using Non-Homogenous Markov Models. Available online: https:\/\/ieeexplore.ieee.org\/document\/7345354."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"107479","DOI":"10.1016\/j.ress.2021.107479","article-title":"Survivability evaluation and importance analysis for cyber\u2013physical smart grids","volume":"210","author":"Woodard","year":"2021","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"626","DOI":"10.1109\/TDSC.2014.2382574","article-title":"P2CySeMoL: Predictive, Probabilistic Cyber Security Modeling Language","volume":"12","author":"Holm","year":"2014","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_18","unstructured":"Holm, H., Shahzad, K., and Buschle, M. (2025, April 07). P2 CySeMoL: Predictive, Probabilistic Cyber Security Modeling Language (No Date). Available online: https:\/\/ieeexplore.ieee.org\/document\/6990572."},{"key":"ref_19","unstructured":"Holm, H., Shahzad, K., and Buschle, M. (2025, April 07). Quantifying & Minimizing Attack Surfaces Containing Moving Target Defenses. Available online: http:\/\/ieeexplore.ieee.org\/document\/7287449."},{"key":"ref_20","unstructured":"Hong, J.B., Kim, D.S., and Haqiq, A. (2025, April 07). What Vulnerability Do We Need to Patch First?. Available online: https:\/\/ieeexplore.ieee.org\/document\/6903625."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Lippmann, R.P., and Ingols, K.W. (2005). An Annotated Review of Past Papers on Attack Graphs, MIT Lincoln Laboratory.","DOI":"10.21236\/ADA431826"},{"key":"ref_22","unstructured":"Valja, M., Korman, M., and Shahzad, K. (2025, April 07). Integrated Metamodel for Security Analysis, IEEE Xplore Login (No Date A). Available online: http:\/\/ieeexplore.ieee.org\/docurnent\/7070437."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1235","DOI":"10.1162\/neco_a_01199","article-title":"A review of recurrent neural networks: LSTM cells and network architectures","volume":"31","author":"Yu","year":"2019","journal-title":"Neural Comput."},{"key":"ref_24","unstructured":"Yusuf, S.E., Mengmeng, G., and Hong, J.B. (2025, April 07). Security Modelling and Analysis of Dynamic Enterprise Networks. Available online: http:\/\/ieeexplore.ieee.org\/stamp\/stamp.jsp?arnumber=7876345."},{"key":"ref_25","unstructured":"Ekin, T. (2025, April 07). Augmented Probability Simulation Methods for Non-Cooperative Games. Available online: https:\/\/arxiv.org\/abs\/1910.04574."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Miller, S., Wagner, C., Aickelin, U., and Garibaldi, J.M. (2016). Modelling Cyber-Security Experts\u2019 Decision Making Processes using Aggre-gation Operators. arXiv.","DOI":"10.2139\/ssrn.2839710"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Applebaum, A., Miller, D., Strom, B., Korban, C., and Wolf, R. (2016, January 5\u20139). Intelligent, automated red team emulation. Proceedings of the Annual Computer Security Applications Conference, ACSAC, Los Angeles, CA, USA.","DOI":"10.1145\/2991079.2991111"},{"key":"ref_28","first-page":"34","article-title":"Developing a Framework and Methodology for Assessing Cyber Risk for Business Leaders","volume":"20","author":"Miller","year":"2018","journal-title":"J. Appl. Bus. Econ."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Sarraute, C., Buffet, O., and Hoffmann, J. (2012, January 22\u201326). POMDPs make better hackers: Accounting for uncertainty in penetration testing. Proceedings of the AAAI Conference on Artificial Intelligence, AAAI, Toronto, ON, Canada.","DOI":"10.1609\/aaai.v26i1.8363"},{"key":"ref_30","unstructured":"Molina-Markham, A., Winder, R.K., and Ridley, A. (2021). Network defense is not a game. arXiv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Goel, D., Ward-Graham, M.H., Neumann, A., Neumann, F., Nguyen, H., and Guo, M. (2022, January 9\u201313). Defending active directory by combining neural network based dynamic program and evolutionary diversity optimisation. Proceedings of the Genetic and Evolutionary Computation Conference, Boston, MA, USA.","DOI":"10.1145\/3512290.3528729"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Han, Y., Rubinstein, B.I., Abraham, T., Alpcan, T., De Vel, O., Erfani, S., Hubczenko, D., Leckie, C., and Montague, P. (2018, January 29\u201331). Reinforcement learning for autonomous defence in software-defined networking. Proceedings of the Decision and Game Theory for Security: 9th International Conference, GameSec 2018, Seattle, WA, USA. Proceedings 9.","DOI":"10.1007\/978-3-030-01554-1_9"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Han, Y., Hubczenko, D., Montague, P., De Vel, O., Abraham, T., Rubinstein, B.I., Leckie, C., Alpcan, T., and Erfani, S. (2020, January 19\u201324). Adversarial reinforcement learning under partial observability in autonomous computer network defence. Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK.","DOI":"10.1109\/IJCNN48605.2020.9206634"},{"key":"ref_34","unstructured":"Baillie, C., Standen, M., Schwartz, J., Docking, M., Bowman, D., and Kim, J. (2020). Cyborg: An autonomous cyber operations research gym. arXiv."},{"key":"ref_35","unstructured":"Dhir, N., Hoeltgebaum, H., Adams, N., Briers, M., Burke, A., and Jones, P. (2021). Prospective artificial intelligence approaches for active cyber defence. arXiv."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Gangupantulu, R., Cody, T., Park, P., Rahman, A., Eisenbeiser, L., Radke, D., Clark, R., and Redino, C. (2022, January 1\u20133). Using cyber terrain in reinforcement learning for penetration testing. Proceedings of the 2022 IEEE International Conference on Omni-layer Intelligent Systems (COINS), Barcelona, Spain.","DOI":"10.1109\/COINS54846.2022.9855011"},{"key":"ref_37","unstructured":"Li, L., Fayad, R., and Taylor, A. (2021). Cygil: A cyber gym for training autonomous agents over emulated network systems. arXiv."},{"key":"ref_38","unstructured":"Andrew, A., Spillard, S., Collyer, J., and Dhir, N. (2022). Developing optimal causal cyber-defence agents via cyber security simulation. arXiv."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1109\/JPROC.2011.2161239","article-title":"Toward continuous state\u2014Space regulation of coupled cyber\u2014Physical systems","volume":"100","author":"Bradley","year":"2011","journal-title":"Proc. IEEE"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"3929","DOI":"10.1109\/TSG.2021.3121009","article-title":"Cyber-attack detection for photovoltaic farms based on power-electronics-enabled harmonic state space modeling","volume":"13","author":"Zhang","year":"2021","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"3763","DOI":"10.1109\/TSG.2020.2982566","article-title":"Reliability modeling and assessment of cyber space in cyber-physical power systems","volume":"11","author":"He","year":"2020","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1016\/j.chaos.2015.10.030","article-title":"A new cyber security risk evaluation method for oil and gas SCADA based on factor state space","volume":"89","author":"Yang","year":"2016","journal-title":"Chaos, Solitons Fractals"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"126023","DOI":"10.1109\/ACCESS.2021.3104260","article-title":"Offensive security: Towards proactive threat hunting via adversary emulation","volume":"9","author":"Ajmal","year":"2021","journal-title":"IEEE Access"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"70443","DOI":"10.1109\/ACCESS.2023.3272629","article-title":"Toward effective evaluation of cyber defense: Threat based adversary emulation approach","volume":"11","author":"Ajmal","year":"2023","journal-title":"IEEE Access"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Yoo, J.D., Park, E., Lee, G., Ahn, M.K., Kim, D., Seo, S., and Kim, H.K. (2020). Cyber attack and defense emulation agents. Appl. Sci., 10.","DOI":"10.3390\/app10062140"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Eckhart, M., and Ekelhart, A. (2019). Digital twins for cyber-physical systems security: State of the art and outlook. Security and Quality in Cyber-Physical Systems Engineering: With Forewords by Robert M. Lee and Tom Gilb, Springer.","DOI":"10.1007\/978-3-030-25312-7_14"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Dietz, M., Vielberth, M., and Pernul, G. (2020, January 25\u201328). Integrating digital twin security simulations in the security operations center. Proceedings of the 15th International Conference on Availability, Reliability and Security, Dublin, Ireland.","DOI":"10.1145\/3407023.3407039"},{"key":"ref_48","unstructured":"Dietz, M., Englbrecht, L., and Pernul, G. (2021, January 1\u20132). Enhancing industrial control system forensics using replication-based digital twins. Proceedings of the Advances in Digital Forensics XVII: 17th IFIP WG 11.9 International Conference, Virtual Event. Revised Selected Papers 17."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Homaei, M., Guti\u00e9rrez, O.M., N\u00fa\u00f1ez, J.C.S., Vegas, M.A., and Lindo, A.C. (2023). A Review of Digital Twins and their Application in Cybersecurity based on Artificial Intelligence. arXiv.","DOI":"10.20944\/preprints202310.1127.v1"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"103961","DOI":"10.1016\/j.compind.2023.103961","article-title":"ENIGMA: An explainable digital twin security solution for cyber\u2013physical systems","volume":"151","author":"Suhail","year":"2023","journal-title":"Comput. Ind."},{"key":"ref_51","unstructured":"Allison, D., Smith, P., and Mclaughlin, K. (August, January 29). Digital Twin-Enhanced Incident Response for Cyber-Physical Systems. Proceedings of the 18th International Conference on Availability, Reliability and Security, Benevento, Italy."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Empl, P., Schlette, D., Zupfer, D., and Pernul, G. (2022, January 23\u201326). SOAR4IoT: Securing IoT Assets with Digital Twins. Proceedings of the 17th International Conference on Availability, Reliability and Security, Vienna, Austria.","DOI":"10.1145\/3538969.3538975"},{"key":"ref_53","unstructured":"Coppolino, L., Nardone, R., Petruolo, A., Romano, L., and Souvent, A. (August, January 29). Exploiting digital twin technology for cybersecurity monitoring in smart grids. Proceedings of the 18th International Conference on Availability, Reliability and Security, Benevento, Italy."},{"key":"ref_54","unstructured":"Fran\u00e7ois, M. (2024, January 28\u201331). GraphETL: Construction d\u2019une plateforme versatile pour la mod\u00e9lisation du risque cyber. Proceedings of the INFormatique des ORganisations et Syst\u00e8mes d\u2019Information et de D\u00e9cision (INFORSID)\u2014Forum JCJC, 42e \u00e9dition, Nancy, France."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Fran\u00e7ois, M., Arduin, P.E., and Merad, M. (2021). Artificial Intelligence & Cybersecurity: A Preliminary Study of Automated Pentesting with Offensive Artificial Intelligence. Proceedings of the International Conference on Information and Knowledge Systems, Springer.","DOI":"10.1007\/978-3-030-85977-0_10"},{"key":"ref_56","unstructured":"Fran\u00e7ois, M., Arduin, P.E., and Merad, M. (2023, January 6\u20139). Classification of Decision Support Systems for Cybersecurity. Proceedings of the 15th Mediterranean Conference on Information Systems (MCIS) and the 6th Middle East & North Africa Conference on digital Information Systems (MENACIS), Madrid, Spain."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Jacobs, J., Romanosky, S., Suciu, O., Edwards, B., and Sarabi, A. (2023, January 3\u20137). Enhancing Vulnerability Prioritization: Data-driven Exploit Predictions with Community-driven Insights. Proceedings of the 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Delft, The Netherlands.","DOI":"10.1109\/EuroSPW59978.2023.00027"},{"key":"ref_58","unstructured":"FIRST (2025, April 07). Common Vulnerability Scoring System. Available online: https:\/\/www.first.org\/."},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3436242","article-title":"Exploit prediction scoring system (epss)","volume":"2","author":"Jacobs","year":"2021","journal-title":"Digit. Threat. Res. Pract."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Allodi, L., and Massacci, F. (2012, January 15). A preliminary analysis of vulnerability scores for attacks in wild: The ekits and sym datasets. Proceedings of the 2012 ACM Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, Raleigh, NC, USA.","DOI":"10.1145\/2382416.2382427"},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2630069","article-title":"Comparing vulnerability severity and exploits using case-control studies","volume":"17","author":"Allodi","year":"2014","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Younis, A.A., and Malaiya, Y.K. (2015, January 3\u20135). Comparing and evaluating CVSS base metrics and microsoft rating system. Proceedings of the 2015 IEEE International Conference on Software Quality, Reliability and Security, Vancouver, BC, Canada.","DOI":"10.1109\/QRS.2015.44"},{"key":"ref_63","unstructured":"Suciu, O., Nelson, C., Lyu, Z., Bao, T., and Dumitra\u0219, T. (2022, January 10\u201312). Expected exploitability: Predicting the development of functional vulnerability exploits. Proceedings of the 31st USENIX Security Symposium (USENIX Security 22), Boston, MA, USA."},{"key":"ref_64","unstructured":"Goodfellow, I., Bengio, Y., Courville, A., and Bengio, Y. (2016). Deep Learning, MIT Press."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"303","DOI":"10.1007\/BF02551274","article-title":"Approximation by superpositions of a sigmoidal function","volume":"2","author":"Cybenko","year":"1989","journal-title":"Math. Control Signals Syst."},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Fran\u00e7ois, M., Arduin, P., and Merad, M. (2024, January 17\u201320). Latent States: Model Based Machine Learning Perspectives on Cyber Resilience. Proceedings of the IEEE 4th Intelligent Cybersecurity Conference (ICSC), Valencia, Spain.","DOI":"10.1109\/ICSC63108.2024.10894907"},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Rahman, M.R., Mahdavi-Hezaveh, R., and Williams, L. (2020, January 17\u201320). A literature review on mining cyberthreat intelligence from unstructured texts. Proceedings of the 2020 International Conference on Data Mining Workshops (ICDMW), Virtual.","DOI":"10.1109\/ICDMW51313.2020.00075"},{"key":"ref_68","doi-asserted-by":"crossref","unstructured":"Takko, T., Bhattacharya, K., Lehto, M., Jalasvirta, P., Cederberg, A., and Kaski, K. (2023). Knowledge mining of unstructured information: Application to cyber domain. Sci. Rep., 13.","DOI":"10.1038\/s41598-023-28796-6"},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"3779","DOI":"10.1109\/TNNLS.2021.3121870","article-title":"Deep reinforcement learning for cyber security","volume":"34","author":"Nguyen","year":"2021","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_70","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1016\/j.cose.2016.04.003","article-title":"A problem shared is a problem halved: A survey on the dimensions of collective cyber defense through security information sharing","volume":"60","author":"Skopik","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_71","unstructured":"Sedenberg, E.M., and Dempsey, J.X. (2018). Cybersecurity information sharing governance structures: An ecosystem of diversity, trust, and tradeoffs. arXiv."},{"key":"ref_72","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1287\/deca.2018.0387","article-title":"Information sharing in cybersecurity: A review","volume":"16","author":"Pala","year":"2019","journal-title":"Decis. Anal."},{"key":"ref_73","unstructured":"Nolan, A. (2015). Cybersecurity and Information Sharing: Legal Challenges and Solutions, Congressional Research Service."},{"key":"ref_74","doi-asserted-by":"crossref","unstructured":"Murdoch, S., and Leaver, N. (2015, January 12). Anonymity vs. trust in cyber-security collaboration. Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security, Denver, CO, USA.","DOI":"10.1145\/2808128.2808134"},{"key":"ref_75","unstructured":"Dandurand, L., and Serrano, O.S. (2013, January 4\u20137). Towards improved cyber security information sharing. Proceedings of the 2013 5th International Conference on Cyber Conflict (CYCON 2013), Talinn, Estonia."},{"key":"ref_76","unstructured":"(2025, April 07). Specter Ops BloodHound. Available online: https:\/\/bloodhound.readthedocs.io\/en\/latest\/."},{"key":"ref_77","unstructured":"The MITRE Corporation (2025, April 07). CALDERA AEP. Available online: https:\/\/caldera.mitre.org."},{"key":"ref_78","unstructured":"MITRE (2025, April 07). Caldera Profile for Identity Snowball Attacks. Available online: https:\/\/github.com\/mitre\/stockpile\/blob\/master\/data\/adversaries\/1bac97ca-77fc-4c9a-835e-4de1b1b7f639.yml."},{"key":"ref_79","doi-asserted-by":"crossref","unstructured":"Goel, D., Neumann, A., Neumann, F., Nguyen, H., and Guo, M. (2023, January 15\u201319). Evolving Reinforcement Learning Environment to Minimize Learner\u2019s Achievable Reward: An Application on Hardening Active Directory Systems. Proceedings of the Genetic and Evolutionary Computation Conference, Melbourne, Australia.","DOI":"10.1145\/3583131.3590436"},{"key":"ref_80","unstructured":"Goel, D., Moore, K., Guo, M., Wang, D., Kim, M., and Camtepe, S. Optimizing Cyber Defense in Dynamic Active Directories through Reinforcement Learning. Proceedings of the European Symposium on Research in Computer Security."},{"key":"ref_81","unstructured":"Microsoft (2025, April 07). Microsoft Active Directory\u2014ADDS Glossary. Available online: https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/ad-ds\/plan\/appendix-a--reviewing-key-ad-ds-terms."},{"key":"ref_82","unstructured":"MITRE (2025, April 07). ATT&CK S0521\u2014Bloodhound. Available online: http:\/\/attack.mitre.org."},{"key":"ref_83","unstructured":"MITRE (2025, April 07). T1021\u2014Remote Services. Available online: http:\/\/attack.mitre.org."},{"key":"ref_84","unstructured":"MITRE (2025, April 07). T1210\u2014Exploitation of Remote Services. Available online: http:\/\/attack.mitre.org."},{"key":"ref_85","unstructured":"MITRE (2025, April 07). TA006\u2014Credential Access. Available online: http:\/\/attack.mitre.org."},{"key":"ref_86","first-page":"8026","article-title":"Pytorch: An imperative style, high-performance deep learning library","volume":"32","author":"Paszke","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_87","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3447772","article-title":"Knowledge graphs","volume":"54","author":"Hogan","year":"2021","journal-title":"ACM Comput. Surv. (Csur)"},{"key":"ref_88","unstructured":"Agrawal, G., Pal, K., Deng, Y., Liu, H., and Baral, C. (2023, January 27\u201329). AISecKG: Knowledge Graph Dataset for Cybersecurity Education. Proceedings of the AAAI-MAKE 2023: Challenges Requiring the Combination of Machine Learning 2023, San Francisco, CA, USA."},{"key":"ref_89","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1016\/j.isatra.2023.06.030","article-title":"A graph empowered insider threat detection framework based on daily activities","volume":"141","author":"Hong","year":"2023","journal-title":"ISA Trans."},{"key":"ref_90","doi-asserted-by":"crossref","unstructured":"Dasgupta, S., Piplai, A., Ranade, P., and Joshi, A. (2021, January 15\u201318). Cybersecurity Knowledge Graph Improvement with Graph Neural Networks. Proceedings of the 2021 IEEE International Conference on Big Data (Big Data), Virtual.","DOI":"10.1109\/BigData52589.2021.9672062"},{"key":"ref_91","doi-asserted-by":"crossref","first-page":"1201","DOI":"10.1007\/s40747-023-01205-1","article-title":"Cybersecurity knowledge graphs construction and quality assessment","volume":"10","author":"Li","year":"2023","journal-title":"Complex Intell. Syst."},{"key":"ref_92","doi-asserted-by":"crossref","first-page":"49","DOI":"10.3233\/JCS-171063","article-title":"A catalogue associating security patterns and attack steps to design secure applications","volume":"27","author":"Salva","year":"2019","journal-title":"J. Comput. Secur."},{"key":"ref_93","unstructured":"Raissi, M., Perdikaris, P., and Karniadakis, G.E. (2017). Physics informed deep learning (Part I): Data-driven solutions of nonlinear partial differential equations. arXiv."},{"key":"ref_94","doi-asserted-by":"crossref","first-page":"109687","DOI":"10.1016\/j.commatsci.2020.109687","article-title":"Theory-training deep neural networks for an alloy solidification benchmark problem","volume":"180","author":"Rad","year":"2020","journal-title":"Comput. Mater. Sci."},{"key":"ref_95","doi-asserted-by":"crossref","first-page":"465","DOI":"10.1109\/JPROC.2023.3247480","article-title":"Model-based deep learning","volume":"111","author":"Shlezinger","year":"2023","journal-title":"Proc. IEEE"},{"key":"ref_96","unstructured":"Kipf, T.N., and Welling, M. (2016). Semi-supervised classification with graph convolutional networks. arXiv."},{"key":"ref_97","doi-asserted-by":"crossref","unstructured":"Monti, F., Boscaini, D., Masci, J., Rodola, E., Svoboda, J., and Bronstein, M.M. (2017, January 21\u201326). Geometric deep learning on graphs and manifolds using mixture model cnns. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.576"},{"key":"ref_98","unstructured":"Hamilton, W.L., Ying, R., and Leskovec, J. (2017). Inductive Representation Learning on Large Graphs. arXiv."},{"key":"ref_99","unstructured":"Youden, W. (1969). Statistical Techniques. NBS Special Publication, NIST."},{"key":"ref_100","unstructured":"Kingma, D.P., and Ba, J. (2014). Adam: A method for stochastic optimization. arXiv."},{"key":"ref_101","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1080\/03081080500054810","article-title":"Algebraic connectivity of directed graphs","volume":"53","author":"Wu","year":"2005","journal-title":"Linear Multilinear Algebra"},{"key":"ref_102","unstructured":"Purple, N. (2025, April 07). Spectral Graph Theory 2019. Available online: http:\/\/math.uchicago.edu\/~may\/REU2019\/REUPapers\/Purple.pdf."},{"key":"ref_103","unstructured":"McClell, J.L., Rumelhart, D.E., and PDP Research Group (1987). Parallel Distributed Processing, Volume 2: Explorations in the Microstructure of Cognition: Psychological and Biological Models, MIT Press."},{"key":"ref_104","unstructured":"Liashchynskyi, P., and Liashchynskyi, P. (2019). Grid search, random search, genetic algorithm: A big comparison for NAS. arXiv."},{"key":"ref_105","first-page":"4768","article-title":"A unified approach to interpreting model predictions","volume":"30","author":"Lundberg","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_106","unstructured":"MITRE (2020, May 05). CAPEC-Common Attack Pattern Enumeration and Classification (CAPEC). Technical Report. Available online: https:\/\/capec.mitre.org."},{"key":"ref_107","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1214\/ss\/1009213726","article-title":"Statistical modeling: The two cultures (with comments and a rejoinder by the author)","volume":"16","author":"Breiman","year":"2001","journal-title":"Stat. Sci."},{"key":"ref_108","unstructured":"Calders, T., and Jaroszewicz, S. Efficient AUC optimization for classification. Proceedings of the European Conference on Principles of Data Mining and Knowledge Discovery."},{"key":"ref_109","doi-asserted-by":"crossref","unstructured":"Hart, S. (1989). Shapley value. Game Theory, Springer.","DOI":"10.1007\/978-1-349-20181-5_25"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/2\/15\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:12:27Z","timestamp":1760029947000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/2\/15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,10]]},"references-count":109,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2025,6]]}},"alternative-id":["jcp5020015"],"URL":"https:\/\/doi.org\/10.3390\/jcp5020015","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,10]]}}}