[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-ai-tool-auto-generates-formal-cyberattack-models-from-cves":10,"sections":34},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":29,"feedback":33,"feedback_at":22,"cost_usd":33,"total_tokens":33},9946,"new-ai-tool-auto-generates-formal-cyberattack-models-from-cves","New AI Tool Auto-Generates Formal Cyberattack Models From CVEs","CVE2AP uses LLMs to convert vulnerability writeups into formal, machine-checkable attack-path simulations for security teams.","A new system called CVE2AP teaches AI to turn plain-English vulnerability write-ups into formal attack simulations that a computer can actually check.\n\nResearchers built CVE2AP to take natural-language CVE descriptions - the short technical summaries published for every disclosed vulnerability - and convert them into PDDL, a formal language used to model step-by-step attack sequences for automated reasoning. The system runs structured prompting plus an error-feedback loop: when a planner flags a generated attack path as syntactically broken or unsolvable, CVE2AP feeds that error back to the model and tries again. The team tested the approach across multiple large language models, scoring syntax correctness, solvability, and semantic accuracy. GPT-5.5 gave the best balance of quality and cost, and the feedback loop produced the most consistent gains, with top runs hitting 86.9% syntax correctness, 78.6% solvability, and 93.1% semantic correctness under LLM-based grading.\n\nAttack-path modeling has stayed a mostly manual, expert-driven chore even as new CVEs pile up daily, which means formal threat models go stale fast. Automating that translation step is unglamorous plumbing work, but it could let security teams keep machine-checkable attack graphs current instead of rebuilding them by hand every quarter.\n\nWorth noting: nearly one in five generated attack paths still failed to actually solve, and the quality scores come from using an LLM to judge another LLM's output - a grading method that deserves its own skepticism before anyone wires this into production defenses.","[\"ai\",\"security\",\"cve\",\"attack-modeling\"]","2026-10-05T04:00:00.000Z","2026-10-05T14:47:22.245Z","2026-10-05T14:47:26.281Z","published",null,[],"security",[26,24,27,28],"ai","cve","attack-modeling",[30],{"name":31,"url":32},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2610.03383",0,{"sections":35},[36,39,42,47,52,57,61,66,70,74,79,84,89,94],{"name":37,"slug":26,"count":38,"latest_published_at":18},"AI",6170,{"name":40,"slug":24,"count":41,"latest_published_at":18},"Security",860,{"name":43,"slug":44,"count":45,"latest_published_at":46},"Policy","policy",444,"2026-10-03T15:02:01.000Z",{"name":48,"slug":49,"count":50,"latest_published_at":51},"Deals","deals",323,"2026-10-04T13:00:00.000Z",{"name":53,"slug":54,"count":55,"latest_published_at":56},"Hardware","hardware",204,"2026-10-03T14:50:50.000Z",{"name":58,"slug":59,"count":60,"latest_published_at":18},"Science","science",177,{"name":62,"slug":63,"count":64,"latest_published_at":65},"Consumer Tech","consumer-tech",158,"2026-10-03T03:21:12.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":18},"Dev Tools","dev-tools",97,{"name":71,"slug":72,"count":69,"latest_published_at":73},"Software","software","2026-10-04T10:00:00.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Startups","startups",92,"2026-10-04T14:36:25.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"General","general",51,"2026-10-05T02:35:01.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"Reviews","reviews",32,"2026-10-02T18:00:00.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"How-To","how-to",7,"2026-10-01T09:00:00.000Z"]