CVE2AP: Automated Generation of PDDL-Encoded Attack Paths via Large Language Models

📅 2026-10-02
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the limitations of traditional attack path modeling, which relies heavily on manual effort and struggles to keep pace with rapidly evolving threats. We propose an automated framework leveraging large language models (LLMs) to generate PDDL-encoded attack paths directly from natural language CVE descriptions. Methodologically, the framework incorporates structured prompting and an iterative error-correction mechanism driven by planner feedback to jointly optimize the syntactic correctness and solvability of the generated paths. Experimental results demonstrate that our approach achieves an 86.9% syntactic validity rate, a 78.6% solvability rate, and a 93.1% semantic accuracy rate, with GPT-5.5 exhibiting the optimal quality-cost trade-off. This work effectively advances the automation and scalability of cybersecurity analysis.
📝 Abstract
Attack Path (AP) modeling is fundamental to cybersecurity analysis, where the Planning Domain Definition Language (PDDL) has been widely adopted to encode APs into formal and machine-verifiable representations for automated reasoning about vulnerability exploitation, attack progression, and their potential impacts. However, existing AP modeling approaches largely rely on expert-driven manual construction, limiting their scalability and ability to keep pace with rapidly evolving cyber threats. Large language models (LLMs) are promising candidates, as their extensive pre-trained knowledge and reasoning capabilities enable them to interpret and transform threat intelligence into formal representations. In this paper, we propose \textbf{CVE2AP}, an LLM-based approach for automatically generating PDDL-encoded attack paths from natural language CVE (Common Vulnerability Exposure) descriptions. CVE2AP leverages structured prompting and incorporates an error-feedback mechanism that iteratively refines the generated paths using planner-reported syntactic and solvability errors. We conduct a systematic empirical evaluation across multiple LLMs and generation configurations, assessing generation quality across syntactic, solvability and semantic dimensions, together with token consumption and generation time. The results demonstrate that CVE2AP effectively generates high-quality PDDL-encoded attack paths, achieving up to 86.9\% syntax correctness, 78.6\% solvability, and 93.1\% semantic correctness under LLM-as-expert evaluation, while \texttt{GPT-5.5} offers the best quality-cost trade-off and error feedback yields the most consistent quality improvement.
Problem

Research questions and friction points this paper is trying to address.

Attack Path Modeling
PDDL
CVE
Automated Generation
Cybersecurity
Innovation

Methods, ideas, or system contributions that make the work stand out.

Large Language Models
Attack Path Generation
PDDL Encoding
Error-Feedback Mechanism
CVE
🔎 Similar Papers
No similar papers found.