Robustness to adversarially manipulated and heavily corrupted CTI

Investigate the robustness of AutoSigma to adversarial manipulation and heavily corrupted cyber threat intelligence inputs beyond the controlled noise conditions evaluated in the study.

Background

AutoSigma is evaluated under controlled character-level perturbations to cyber threat intelligence reports and remains highly similar to the outputs produced from clean reports at low contamination rates. However, performance degrades substantially as the contamination level increases. The system is designed for validated CTI reports, while adversarial manipulation and severe corruption are explicitly outside the current scope. Establishing robustness in these settings is therefore identified as a concrete direction for future investigation.

References

It is important to note that AutoSigma is designed to operate on validated CTI reports typically used by SOC teams. Handling adversarial manipulation or heavily corrupted CTI inputs is beyond the scope of this work and is left for future investigation.

From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation  (2608.19011 - Ghaffarzadegan et al., 19 Aug 2026) in Section 5, RQ3.4 ("How does AutoSigma perform with noisy data?")