Methodology
A rigorous, interdisciplinary, and experimentally validated research framework guiding the ANCILE project.
Methodological Principles
Game-Theoretic Evaluation
Controlled adversarial experiments are used to evaluate research results and machine learning models through attacker–defender scenarios.
Probabilistic Knowledge Representation
Uncertainty is explicitly modeled using probabilistic reasoning, enabling robust detection and mitigation decisions.
Hybrid AI Approaches
Combination of manual programming, symbolic AI and sub-symbolic machine learning to acquire, interpret and refine security knowledge.
Model-Driven & Agile Engineering
Model-Driven Engineering (MDE), SOA architectures, containerization, and continuous integration ensure reliable PoC development.
Research Workflow
State-of-the-Art Analysis
Comprehensive review of cutting-edge research in probabilistic classification, adversarial plan recognition, explainable AI, decision-theoretic planning, and adversarial machine learning for cyber defence.
Service-Oriented Design (UML)
Detailed UML modeling of each technical work package, addressing research gaps identified in the State-of-the-Art.
Proof-of-Concept Development
Agile implementation of the prototype with continuous integration and non-regression testing.
Containerized Service Integration
Integration of heterogeneous platforms (Prolog for CLAPPS, C for TPG, Python for DNN) via containerized services communicating through REST APIs and message queues.
Adversarial Evaluation
Experimental validation through cyber range simulations where attack and defence teams compete, generating datasets for in-depth analysis.
Scientific Dissemination
Publication of research findings in high-impact scientific venues and contribution to the cybersecurity research community.


