Adaptive Threat Intelligence: An Incremental Learning Approach for Detecting Evolving APT Attacks
Manish Khule, Deepak Motwani, Dipti Chauhan · 2025
Advanced Persistent Threats (APTs) pose a significant challenge due to their dynamic and evolving nature, making them difficult to detect. Traditional signature-based and static machine learning approaches fail to identify novel attack methods employed by APTs. This paper introduces an Adaptive Threat Intelligence (ATI) framework that leverages incremental learning to update models in real time. The ATI framework continuously integrates new threat intelligence without requiring a complete model retraining. The ATI framework employs a multilevel detection approach, incorporating anomaly detection, behavioral analysis, and AIdriven analytics. Additionally, it adheres to Zero-Trust security principles to prevent attack propagation through constant validation. The effectiveness of the proposed approach is demonstrated through experiments conducted on real datasets, including threat logs from MITRE ATT&CK, showing significantly improved detection rates compared to existing methods. Our ATI framework achieves an impressive $\mathbf{95.2\%}$ accuracy, $\mathbf{96.1\%}$ recall, and $\mathbf{94.8\%}$ F1-score, surpassing traditional models in detecting evolving APTs while reducing false positives. This research aligns with adaptive cybersecurity paradigms, integrating AI-based deep learning and reinforcement learning techniques. Future work will focus on federated learning to enhance threat intelligence sharing and refine real-time threat detection capabilities.