GARAGE: Characterizing the Automation Boundary in LLM-based Attack Graph Generation

2026-07-20Cryptography and Security

Cryptography and Security
AI summary

The authors created a tool called GARAGE to help improve vehicle cybersecurity by organizing complex threat information into an easy-to-use knowledge base. GARAGE combines data from many security reports and vulnerabilities to make detailed attack maps specific to vehicles. They tested GARAGE and found it can accurately apply knowledge to new car systems it hasn't seen before. The authors also show how GARAGE can be used alongside human input to assist in risk assessment decisions.

Cyber Threat IntelligenceRAG frameworkattack graphCVESTIX 2.1kill chain analysisTARAhuman-in-the-loopLLMAuto-ISAC
Authors
Daekwon Pi, Sangho Lee, Young Hun Lee, Huy Kang Kim
Abstract
While modern vehicle security depends on effective Cyber Threat Intelligence (CTI) synthesis, current automated tools struggle with unstructured data and automotive-specific architectural nuances. To bridge this gap, we introduce GARAGE, a RAG-powered framework that converts fragmented CTI into an actionable, domain-specific knowledge base for automated attack graph generation. GARAGE synthesizes a dataset of 12,786 CVEs and 140 incident reports into a STIX 2.1 and Auto-ISAC ATM-compliant knowledge base. By formalizing tactical-pattern-level scenarios through granular kill chain analysis, GARAGE achieves threat generation capabilities. Our 320 Leave-One-Out experiments reveal that the framework can accurately transfer security knowledge to entirely unseen vehicle architectures. Furthermore, we position GARAGE as a scalable TARA support tool within human-in-the-loop workflows, offering a comprehensive cost-performance analysis to guide its deployment across various LLM tiers.