Counterfactual mitigation optimization for multi-stage attacks via causal AI
Main Article Content
Abstract
Multi-stage cyberattacks often bypass defenses not due to detection failures, but because response actions are delayed or poorly aligned with the true causal drivers of attack progression. This paper proposes Counterfactual Mitigation Optimization (CMO), a causal AI framework that transforms heterogeneous security telemetry into a structural causal model and evaluates counterfactual intervention scenarios to identify minimal, high-impact mitigation actions. Unlike alert-driven playbooks, CMO generates actionable, stage-aware response plans aligned with the MITRE ATT&CK lifecycle while accounting for uncertainty, operational constraints, and side effects. The paper outlines the framework architecture, causal graph construction, counterfactual evaluation under feasibility constraints, and a multi-objective optimization strategy, and presents an experimental blueprint for assessing effectiveness in multi-stage attack scenarios.
Article Details
References
V. Galwaduge, D. Silva, and A. Jayasumana, “Novel actionable counterfactual explanations for intrusion detection using diffusion models,” Security and Privacy, vol. 5, no. 3, pp. 1–30, 2025. DOI: https://doi.org/10.3390/jcp5030068
https://www.mdpi.com/2624-800X/5/3/68
W. Wu, Y. Zhang, Z. Chen, and X. Li, “ProvX: Generating counterfactual-driven attack explanations for provenance-based intrusion detection,” arXiv preprint arXiv:2508.06073, pp. 1–18, 2025.
https://arxiv.org/abs/2508.06073
M. Homaei, M. Tarif, and P. G. Rodríguez, “Causal digital twins for cyber-physical security: A framework for robust anomaly detection,” Machine Learning with Applications, vol. 11, Art. no. 100558, pp. 1–16, 2025. DOI: https://doi.org/10.2139/ssrn.5679807
https://www.sciencedirect.com/science/article/pii/S2666827025002075
A. Sharma, “A comprehensive review of explainable artificial intelligence in cybersecurity,” Journal of Cybersecurity and Privacy, vol. 5, no. 2, pp. 1–25, 2025.
https://www.sciencedirect.com/science/article/pii/S2405959525001584
X. Shi, R. Müller, and N. Papernot, “Counterfactual explanations for anomaly detection using graph-based models,” in CEUR Workshop Proceedings, vol. 4073, pp. 1–15, 2025.
https://ceur-ws.org/Vol-4073/BEHAIV2025_CRV_4.pdf
F. Guan, Y. Liu, and H. Wang, “AI-driven intelligent perception of cyber threats in enterprise systems,” in Proceedings of the ACM Conference on Computer and Communications Security, pp. 1–12, 2025.
https://dl.acm.org/doi/10.1145/3744668.3744675
M. Pawlicki, “The dual nature of explainable AI challenges in intrusion detection systems,” International Journal of Intelligent Systems, vol. 39, no. 4, pp. 1–22, 2024.
https://link.springer.com/article/10.1007/s10462-024-10972-3
R. Guidotti, A. Monreale, S. Ruggieri, and F. Turini, “Counterfactual explanations and algorithmic recourse for machine learning models,” ACM Computing Surveys, vol. 56, no. 9, pp. 1–32, 2024.
