Learning Profiling with Automated Feedback for Supporting the Assessment of Cybersecurity Education
This paper presents an AI-driven profiling model within a cyber range environment that continuously evaluates learner performance to generate automated, personalized feedback and adaptive learning paths, thereby addressing key challenges in scalability and personalization for cybersecurity education.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the internet as a giant, bustling city where everyone is connected. Like any city, it has its share of troublemakers—hackers, scammers, and digital vandals—who try to break into homes, steal mail, or shut down power plants. To keep this city safe, we don't just need better locks; we need to train the people who build and guard the locks. This is the world of cybersecurity education. Traditionally, learning this trade has been a bit like watching a cooking show: you sit and listen to a teacher explain the theory, or maybe you watch a video. But to actually learn how to cook (or hack), you need to get your hands dirty in the kitchen. In the digital world, this "kitchen" is called a cyber range: a safe, isolated sandbox where students can practice breaking and fixing things without accidentally burning down the real city.
However, there's a problem with these digital kitchens. When a student is practicing, a teacher can't be hovering over their shoulder for every single move, especially if there are thirty students cooking at once. If a student makes a mistake, they might just get a score, like "You got 8 out of 10," but they don't know why they failed or what to do next. It's like getting a test back with a red "F" but no comments on how to study better. This paper asks: Can we build a smart system that acts like a super-attentive coach, watching every move a student makes, understanding their unique strengths and weaknesses, and then giving them a personalized report card and a custom training plan?
The authors of this paper, a team from Brno University of Technology, say yes. They have built a system that combines a cyber range with artificial intelligence to create a "learning profile" for every student. Think of this profile not as a static report card, but as a living, breathing map of a student's skills. As a student tackles cybersecurity challenges (often in a game-like format called Capture the Flag, where you solve puzzles to find hidden "flags"), the system tracks everything: how long they took, how many times they guessed wrong, whether they asked for hints, and how hard the puzzle was.
Instead of just tallying up points, the system uses a mathematical formula to weigh these factors. It asks: Did the student solve the puzzle quickly but with many wrong guesses? Did they breeze through easy tasks but get stuck on the hard ones? Did they rely too much on hints? By crunching these numbers, the system assigns a "profiling score" that tells the story of how the student learned, not just what they got right.
Here is where the magic happens: this score is fed into a Large Language Model (LLM), which is essentially a very advanced AI that can read and write human language. The AI takes the cold, hard numbers and turns them into a warm, helpful conversation. For the student, it generates a personalized feedback report that says things like, "You're a wizard at finding hidden network vulnerabilities, but you tend to rush through the setup phase. Next time, try slowing down on the first step." It even suggests the perfect next challenge: if you aced the easy stuff, it pushes you to a harder level; if you struggled, it offers a slightly easier path to build your confidence.
For the teachers, the system acts like a crystal ball. It aggregates all the student data to show the big picture. It can tell the instructor, "Your whole class is great at hacking, but everyone is struggling with the same specific type of firewall defense," or "This particular task was way too hard for everyone; maybe we need to tweak it."
To prove this works, the team tested their system with 35 real university students. They set up a scenario where the students had to act like digital detectives and hackers, trying to flood a fake website or break into a server. The results were promising. The system successfully tracked the students' progress, calculated their unique profiles, and generated detailed, readable feedback that felt like it came from a human mentor. The study suggests that this approach is technically feasible and offers a way to make cybersecurity training more personal and effective, moving away from one-size-fits-all grading toward a system that truly understands how each learner thinks and struggles. While the paper doesn't claim this solves every problem in education, it shows a clear path toward a future where AI helps teachers give every student the specific guidance they need to become a cybersecurity expert.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.