SPADE: Enhancing Adaptive Cyber Deception Strategies with Generative AI and Structured Prompt Engineering
Shihab Ahmed, A B M Mohaimenur Rahman, Md Morshed Alam, Md Sajidul, Islam Sajid

TL;DR
This paper introduces SPADE, a framework utilizing Generative AI and structured prompt engineering to automate and enhance adaptive cyber deception strategies against evolving malware threats.
Contribution
It presents a systematic approach to leverage large language models for scalable, adaptive cyber deception, addressing challenges like ambiguity and scalability with structured prompt engineering.
Findings
ChatGPT-4o outperformed other models in deception tasks
High engagement (93%) and accuracy (96%) with minimal refinements
Llama3.2 shows potential but needs further optimization
Abstract
The rapid evolution of modern malware presents significant challenges to the development of effective defense mechanisms. Traditional cyber deception techniques often rely on static or manually configured parameters, limiting their adaptability to dynamic and sophisticated threats. This study leverages Generative AI (GenAI) models to automate the creation of adaptive cyber deception ploys, focusing on structured prompt engineering (PE) to enhance relevance, actionability, and deployability. We introduce a systematic framework (SPADE) to address inherent challenges large language models (LLMs) pose to adaptive deceptions, including generalized outputs, ambiguity, under-utilization of contextual information, and scalability constraints. Evaluations across diverse malware scenarios using metrics such as Recall, Exact Match (EM), BLEU Score, and expert quality assessments identified…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Information and Cyber Security · Network Security and Intrusion Detection
