Published signals

Chimera: Using Multi-Agent LLMs to Simulate Insider Threats and Map ATT&CK

Score: 7/10 Topic: Multi-agent LLM simulation for insider threat detection

NDSS 2026 research introduces Chimera, a multi-agent LLM system that automatically simulates insider threats and maps them to ATT&CK. This could automate red-team exercises and improve threat detection coverage.

Insider threats remain one of the hardest security challenges because they require understanding human behavior, access patterns, and organizational context. A new paper from NDSS 2026, titled 'Chimera', proposes an innovative solution: using multiple LLM agents that collaborate to simulate realistic insider threat scenarios. These agents can role-play different personas, generate attack paths, and automatically map their actions to the MITRE ATT&CK framework. This is significant because it moves beyond simple LLM-based threat detection into proactive simulation. Instead of waiting for attacks to happen, security teams could use Chimera to generate diverse attack scenarios, test their detection systems, and identify gaps in coverage. The multi-agent aspect is key—it allows for more complex and realistic simulations where different agents represent different roles and motivations. While the paper is academic, the practical implications are clear: AI-driven threat simulation could become a standard part of security operations, reducing the need for expensive manual red-team exercises and helping organizations stay ahead of evolving insider threats.