David Tayouri

dblp:326/5728 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0001-7745-1377ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2026 ATAG: AI-Agent Application Threat Assessment with Attack Graphs
abstract
Evaluating the security of multi-agent systems (MASs) powered by large language models (LLMs) is challenging, primarily because of the systems' complex internal dynamics and the evolving nature of LLM vulnerabilities. Traditional attack graph (AG) methods often lack the specific capabilities to model attacks on LLMs. This paper introduces AI-agent application Threat assessment with Attack Graphs (ATAG), a novel framework designed to systematically analyze the security risks associated with AI-agent applications. ATAG extends the MulVAL logic-based AG generation tool with custom facts and interaction rules to accurately represent AI-agent topologies, vulnerabilities, and attack scenarios. As part of this research, we also created the LLM vulnerability database (LVD) to initiate the process of standardizing LLM vulnerabilities documentation. To demonstrate ATAG's efficacy, we applied it to two multi-agent applications. Our case studies demonstrated the framework's ability to model and generate AGs for sophisticated, multi-step attack scenarios exploiting vulnerabilities such as prompt injection, excessive agency, sensitive information disclosure, and insecure output handling across interconnected agents. ATAG is an important step toward a robust methodology and toolset to help understand, visualize, and prioritize complex attack paths in multi-agent AI systems (MAASs). It facilitates proactive identification and mitigation of AI-agent threats in multi-agent applications.
Parth Atulbhai Gandhi, David Tayouri, Akansha Shukla, Beni Ifland, Yuval Elovici, Rami Puzis, Asaf Shabtai
AsiaCCS2
2026 Extending the ATT&CK coverage of logical attack graphs
abstract
Logical attack graphs (LAGs) are used to analyze non-trivial relationships between organizational assets and vulnerabilities for cybersecurity risk assessment in complex computerized environments. They help identify dangerous attack scenarios that extend beyond the immediate impact of vulnerability exploitations. In this article, we focus on MulVAL, one of the most popular open-source LAG frameworks. The expressiveness and extensibility of LAG frameworks allow the addition of new attack scenarios in the form of logical interaction rules. However, the existing set of rules developed for MulVAL covers just 20% of the adversarial techniques listed in the MITRE ATT&CK knowledge base. Furthermore, due to the absence of common coding conventions, the previously proposed interaction rules could not be incorporated into one unified library. In this paper, we define uniform coding conventions based on an ontology proposed by Iannacone et al. and incorporate 351 interaction rules identified in the literature into one comprehensive library supported by a software tool for exploring and managing the interaction rules. Further, we propose a methodology and a semi-automated framework for developing new interaction rules to fill the gap in MITRE ATT&CK coverage and demonstrate them using techniques associated with the MITRE Engenuity ATT&CK Evaluations APT29 scenario.
David Tayouri, Nick Baum, Alina Marchenko, Ortal Lavi, Asaf Shabtai, Rami Puzis
Comput. Secur.1
2026 MIRAGE: Multi-Binary Image Risk Assessment With Attack Graph Employment
abstract
Attackers can exploit known vulnerabilities to infiltrate a device's firmware and the communication between firmware binaries in order to pass between them. To improve cybersecurity, organizations must identify and mitigate the risks of the firmware they use. An attack graph (AG) can be used to assess and visually display firmware's risks by organizing the identified vulnerabilities into attack paths composed of sequences of actions attackers may perform to compromise firmware images. In this paper, we utilize AGs for firmware risk assessment. We propose MIRAGE (Multi-binary Image Risk Assessment with Attack Graph Employment), a framework for identifying potential attack vectors and vulnerable interactions between firmware binaries; MIRAGE accomplishes this by generating AGs for firmware inter-binary communication. To evaluate the MIRAGE framework, we collected a dataset of 1,343 firmware images. We propose models for examining the risks of firmware binaries and attack paths, demonstrate their implementation on the dataset of firmware images, and list the riskiest binaries. We present a case study with a detailed description of an actual attack implementation on a selected firmware from the dataset. The use cases of the proposed framework include identifying risky external interactions, assessing supply chain risks, and analyzing security with digital twins.
David Tayouri, Telem Nachum, Asaf Shabtai
IEEE Trans. Dependable Secur. Comput.1
2025 CORAL: Container Online Risk Assessment with Logical attack graphs
David Tayouri, Omri Sgan Cohen, Inbar Maimon, Dudu Mimran, Yuval Elovici, Asaf Shabtai
Comput. Secur.1