Governed research artifact · Published 29 August 2026

AI in Cyberattacks: Dataset and Downloads

Analysis-ready exports behind the statistical study and interactive dashboard, with publication-level provenance, source-linked candidate tags, review controls, and explicit interpretation limits.

116retrieved records
111deduplicated publications
108usable references
103primary denominator

Twelve governed artifacts

Choose the right export

The public package supports recalculating the published distributions and inspecting source IDs, offsets, and provenance fields. The downloaded third-party HTML and PDF archive is intentionally not redistributed.

ArtifactGrainPurposeSize
Dataset guideREADME.mdDocumentationSchema, field definitions, interpretation cautions, and reproducibility boundary.5.0 KB
Publicationspublications.csvOne publicationWide analysis table with eligibility, provenance, tags, metrics, and IOC counts.135 KB
Source-linked normalized tagstags_long.csvOne tag occurrenceNormalized dimensions, confidence, extraction method, source IDs, and source-text offsets.531 KB
Metric candidatesmetrics_long.csvOne candidate metricUnvalidated percentages, durations, costs, dwell, and blast-radius strings linked by source ID.66 KB
IOC candidatesiocs_long.csvOne candidate observableHashes, public IPv4 addresses, and defanged-domain candidates linked by source ID for analyst review.36 KB
Quality and inclusionquality.csvOne publicationCompleteness, statistical inclusion, AI relevance, and review-state controls.7.9 KB
Tag dictionarytag_dictionary.csvOne tag typeDefinitions and interpretation safeguards for normalized statistical dimensions.3.0 KB
Snapshot summarysummary.jsonOne dataset snapshotMachine-readable corpus, quality, and all-record extraction totals.1.3 KB
SQLite databaseai_attack_statistics.sqliteRelational snapshotQueryable publication, tag, metric, IOC, and quality tables; private source records are excluded.1.3 MB
Research workbookai_attack_statistics.xlsxMulti-sheet workbookSanitized, filterable analysis package for spreadsheet workflows.374 KB
Collection reportsource-collection-report.mdCollection auditRetrieval and archive-quality summary without copied third-party source documents.2.7 KB
Uniqueness auditsource-uniqueness-report.tsvOne source comparisonDuplicate and near-duplicate evidence for the publication entities.25 KB

Start here

Analysis workflow

  1. Use publications.csv for the 111-row publication inventory and inclusion controls.
  2. Filter to the 103 include_with_manual_validation rows before reproducing primary percentages.
  3. Join the long-form tag, metric, and IOC tables on publication_id.
  4. Use source IDs and source-text offsets to locate the original passage, then review the canonical publisher source before operational use.

Spreadsheet safety

Formula-neutral exports

Text beginning with =, +, -, or @ is prefixed with an ASCII apostrophe in public CSV and XLSX files. Release tests verify that CSV cells retain no formula-capable prefix and the workbook contains no formula nodes.

Read the full dataset guide →

Interpret carefully

Counts are not prevalence

Publication coverage, multi-label co-mentions, extracted metrics, and candidate observables do not establish unique incidents, causal relations, attribution, provider use, victim geography, or attack rates.

Review all study limitations →

Provenance and uniqueness

Audit the collection boundary