Araştırmadan Eğitime: Makine Öğrenmesi Yöntemlerinin Siber Güvenlik Tehditlerine Uygulanması İçin Laboratuvar Temelli Bir Yaklaşım Geliştirilmesi
KARAKUŞ M. (Yürütücü), SAVRAN KIZILTEPE R., OSMANOĞLU M., GÜLER E., YILMAZ A. E.
TÜBİTAK Projesi, 1071-Uluslararası Araştırma Fonlarından Yararlanma Kapasitesinin ve Uluslararası Ar-Ge İşbirliklerine Katılımın Arttırılmasına Yönelik Destek Programı, 2026 - 2028
- Proje Türü: TÜBİTAK Projesi
- Destek Programı: 1071-Uluslararası Araştırma Fonlarından Yararlanma Kapasitesinin ve Uluslararası Ar-Ge İşbirliklerine Katılımın Arttırılmasına Yönelik Destek Programı
- Başlama Tarihi: Ağustos 2026
- Bitiş Tarihi: Ağustos 2028
Proje Özeti
professionals by establishing the Research-to-Education (R2E) framework of AI, Data Science, Machine Learning for Cybersecurity (ADM4CYB). The project aims to advance the technology from a Technology Readiness Level (TRL) 2 (conceptual design) to TRL 6 (technology demonstrated in a relevant environment) within a 24-month duration. The US partner's complementary effort is already funded by the NSF-EAGER program (Award No: 2515085, Budget: $300,000, https://www.nsf.gov/awardsearch/show-award/?AWD_ID=2515085).
Scientific and technological excellence is defined by three core innovations that transform state-of-the-art research into practical, reproducible labs. First, the project enables Full-Cycle Adversarial Education, where students actively generate attack traffic, process datasets, build Machine Learning (ML)/Deep Learning (DL) defense models, and deploy countermeasures in real-time, moving beyond static tools. Second, it delivers a Modular 11-Topic Framework covering critical and contemporary fields, including but not limited to DoH detection, IDS, DDoS mitigation, adversarial ML, blockchain, software security, hardware security, Post-Quantum Cryptography (PQC), and Phasor Measurement Unit (PMU) spoofing. Third, the architecture is containerized and reproducible, utilizing Labtainers and Docker for integration with the TÜBİTAK ULAKBİM cloud and the US NAIRR (National AI Research Resource) infrastructure, ensuring scalable, high-performance computing access for all participants. Pedagogically, the labs are grounded in active and project-based learning, aligning with ABET (Accreditation Board for Engineering and Technology), ACM CSEC (Cybersecurity Curricula), and NIST NICE (National Initiative for Cybersecurity Education) standards.
The methodology executes a rigorous 24-month R2E pipeline, converting academic work into educational content via a seven-step model: problem selection, attack/data generation, preprocessing, feature engineering, model training, validation, and deployment. Core activities include the development of 11 Full-Cycle Labs that are self-contained units integrating attack simulation, dataset creation, and ML defense across topics like network security, software/hardware security, critical infrastructure (Smart Grid), and PQC. Infrastructure deployment will host these labs on TÜBİTAK national platforms (TÜBİTAK-ULAKBİM), Ankara University Açık Ders (open courseware portal) and the US NAIRR ecosystem to democratize access to high-resource environments. A key measurable outcome is the implementation of an assessment system using automated grading and ABET-aligned rubrics to support large-scale pilots involving > 400 students across Türkiye and the US.
Project Management, jointly led by Ankara University and the University of Michigan-Flint, is structured into six interconnected work packages (WPs) over 24 months. WP1-WP2 focus on the architectural design and full development of the 11 cybersecurity labs. WP3 is dedicated to cloud deployment on TÜBİTAK and NAIRR infrastructures. WP4 involves the large-scale pilot implementation, reaching over 400 students. WP5 covers accreditation mapping, assessment, and pedagogical validation. Finally, WP6 focuses on the development of a Red-Team/Blue-Team CTF gamification engine to enhance engagement and practical skill development. The project's success criteria are defined by the successful deployment of all 11 labs, the completion of the pilot with > 400 students, and the development of the Capture The Flag (CTF) engine.
The structure and contribution of international collaboration are central to the project's success, facilitating technology transfer and nationalization of cutting-edge curricula. The collaboration ensures nationalization by adapting R2E labs to Turkish standards with localized language support and achieving curriculum alignment with global ABET, ACM CSEC, and NIST NICE standards. It provides equitable access by leveraging NAIRR to remove hardware barriers, granting Turkish students access to GPU-class resources. The continuous knowledge exchange through coordinated research activities, shared publication strategies, and researcher mobility ensures mutual improvement of pedagogical effectiveness and technical robustness.
The anticipated impact is multi-faceted and measurable, ensuring both immediate educational benefit and long-term academic contribution. In Workforce Development, the labs will be embedded into Ankara University’s ADM4CYB course, vocational programs, and U.S. master’s curricula, directly addressing the global talent gap. For Open-Source Dissemination, all materials (labs, datasets, models) will be released globally via NAIRR and nationally via TÜBITAK-ULAKBİM and Ankara University Açık Ders, maximizing reach and reproducibility. Community Engagement will be fostered through the organization of national and global CTF competitions with student groups (YAZGİT, AUCS, DIGIWARE). Academic Dissemination is a core component, targeting a minimum of one peer-reviewed journal publication in high-impact venues such as IEEE Transactions on Education and two international conference papers at top-tier education and technology conferences, specifically IEEE FIE, ACM SIGCSE, ACM SIGITE, ASEE, and ISCTürkiye. Furthermore, the project includes a concrete plan to organize a dedicated evaluation lab at the CLEF 2027 Initiative to benchmark the developed modules within the international research community and a tutorial at ISCTürkiye 2027. This comprehensive approach ensures the project's outcomes are sustainable and readily adoptable by other institutions, thereby having the potential to significantly impact cybersecurity education globally, by generating both practical educational tools and foundational academic knowledge.