LLM-Based Automated Generation and Tri-Modal Representation of Cyber Attack Scenario
Seong-Hyun Roh, Tae-Sung Kim · IEEE Access · 2025
The rapid advancement of information technology, the proliferation of artificial intelligence (AI), and the increasing reliance on digital infrastructure have significantly intensified cyber threats faced by organizations. In this evolving landscape, timely identification of threats and coordinated strategic responses have become essential. However, traditional human-centric approaches to cyber-attack scenario generation are limited in scalability, timeliness, and semantic coherence–especially across stakeholders with diverse technical backgrounds. To address these challenges, this study proposes an automated, LLM-driven framework for generating cyber-attack scenarios and converting them into three semantically aligned modalities: natural language narratives, attack graphs, and formal mathematical representations. This tri-modal approach enhances cross-role interpretability and enables consistent understanding among technical experts and non-technical decision-makers alike. The core objective of this research is to propose an automated pipeline framework that spans from scenario generation to tri-modal representation, designed to support decision-makers by ensuring semantic consistency and enhancing interpretability across stakeholder roles. The framework incorporates real-world threat intelligence, structured input parameters, and prompt engineering techniques to ensure realism and fidelity. Evaluation results using state-of-the-art LLMs—including both open-source and proprietary models—demonstrate the system’s ability to generate coherent, context-aware, and logically consistent outputs. The findings validate the feasibility of the proposed approach and underscore its potential to improve cybersecurity preparedness, training efficacy, and governance communication through structured, intelligible scenario representations.