The ANCILE Project
Towards a new generation of intelligent, interpretable and adversarially-aware cybersecurity orchestration.
ANCILE (AutoNoMic Cybersecurity with adversarIal Learning and Explanations) aims to redefine how Security Operations Centres (SOC) detect, understand and mitigate sophisticated cyberattacks.
Rather than relying solely on fully automated black-box artificial intelligence, ANCILE proposes an augmented intelligence approach: human experts remain in the loop, supported by probabilistic, explainable and adversarially trained decision-support systems.
Core Innovation
Probabilistic Intelligence
Moving beyond rigid Boolean alerts, ANCILE produces probabilistic assessments of ongoing attacks, enabling more actionable and nuanced decision-making under uncertainty.
Adversarial Reasoning
By modelling attackers’ strategies through probabilistic plan recognition and decision-theoretic planning, ANCILE anticipates threats instead of merely reacting to them.
Explainable Hybrid AI
Symbolic models (CLAPPS, TPG) and sub-symbolic models (DNN) are combined within interpretable ensembles, ensuring both performance and trustworthiness.
Autonomic SOAR Architecture
The framework refines the MAPEK autonomic computing paradigm into a next-generation SOAR architecture designed for containerized and software-defined infrastructures.
Architectural Vision
ANCILE delivers an autonomic cybersecurity framework structured around a Monitor–Analyse–Plan–Execute–Knowledge (MAPEK) loop. A defence decision-support system collaborates with human analysts, while a mirrored adversarial system simulates attack strategies in controlled cyber-range environments.
All services are implemented as containerized components, communicating through standard APIs, enabling deployment within modern Service-Oriented Architectures (SOA) and Software-Defined Networks (SDN).
Expected Impact
ANCILE aims to significantly improve:
- Accuracy and robustness of zero-day and APT detection
- Speed of attack identification and mitigation
- Reduction of business impact during cyber incidents
- Trust and interpretability of AI-assisted security decisions


