Cybersecurity Learning Hub — From Knowledge to Practice
Cyber Hiroshima

How AI Could Change Cybersecurity Learning — The AI Learning Cyber Hiroshima Is Working Towards

Cybersecurity is an extremely broad field, and even deciding “what do I not understand?” or “what should I learn next?” can be difficult. At Cyber Hiroshima, we aim to use AI not as a tool that simply gives learners the answer, but as a way to connect CyBOK with practical exercises and support deeper understanding.

The value of AI is not only in “giving answers”

Generative AI can provide explanations of many different technologies in a very short time.

That is a major advantage for learning.

However, Cyber Hiroshima believes that in cybersecurity education, what matters more is:

not simply “giving the answer”, but helping the learner understand what they need to understand next.

Imagine, for example, that during an exercise a learner asks:

“What does this error mean?”

If AI simply returns the correct command, the immediate problem may be solved.

But if the learner can also understand:

  • why the error occurred
  • which technology sits behind it
  • which area of CyBOK it relates to
  • what they should review

then that experience can be applied to the next problem as well.

It is important to use AI not as a mechanism for producing answers on the learner’s behalf, but as a Tutor that helps deepen understanding.

Cybersecurity learning needs a large Knowledge Base

Cybersecurity includes many different fields:

networking, cryptography, software, operating systems, Web, malware, forensics, risk, law, privacy and more.

It is not easy for an individual learner to organise all of this alone.

Cyber Hiroshima uses CyBOK as the foundation for structuring this knowledge.

Rather than allowing AI to respond without constraint, we aim to create a learning environment in which explanations refer to trusted bodies of knowledge such as CyBOK, allowing the learner to check:

“What is this explanation based on?”

In other words, the idea is:

AI × Knowledge Base

There is no need to wait for a Private LLM to be completed

Cyber Hiroshima is considering the future development of a cybersecurity-focused Knowledge Base and Private LLM.

However, AI-supported learning does not have to wait until such an environment is complete.

Existing LLMs can be combined with:

  • CyBOK
  • a Japanese-language Knowledge Base
  • SudoRange
  • AI Agent technologies

to build capabilities in stages.

The specification describes a first stage beginning with a simple AI Tutor that follows a flow such as:

Ask a question → Search CyBOK → Explain in Japanese → Show the source → Suggest what to learn next

The important point is that this does not mean that a completed, dedicated AI service is already available today.

Cyber Hiroshima will work towards this direction through step-by-step validation and environment development.

AI can support a Learning Path

Imagine that a learner asks:

“I want to study Web security.”

Rather than simply explaining Web Security, AI could first help assess the learner’s current level of knowledge and then show related areas such as:

Web & Mobile Security
Software Security
Authentication
Network Security

This could make it easier to build a Learning Path within the much broader map provided by CyBOK.

If the guidance can then extend to:

“Which SudoRange exercise should I try next?”

it becomes possible to create a flow of:

Knowledge → AI Guidance → Practice

In the future, it may also be possible to suggest review topics after an exercise based on:

“Where did the learner get stuck?”

Separating roles through AI Agents

There is no need for one AI to perform every role.

As one possible future structure, Cyber Hiroshima is considering separating functions into roles such as:

  • CyBOK Agent
  • Learning Path Agent
  • SudoRange Navigator
  • Quiz Agent
  • Cyber News Agent

The specification also considers architectures in which specialist agents work together using combinations of Skills, Tools, Memory and Handoffs in Robutler / WebAgents.

The important point is not any particular platform itself.

It is the idea of:

separating the knowledge and functions required for different roles, and coordinating them according to the learner’s objectives.

There are also things we should not leave to AI

When using AI in cybersecurity, its answers cannot always be assumed to be correct.

Generative AI may:

  • generate incorrect information
  • rely on outdated information
  • misunderstand context
  • provide an incorrect explanation with apparent confidence

For this reason, Cyber Hiroshima considers it important that learning does not end with an AI response alone, but that learners can:

return to the source.

AI-supported learning is also not a substitute for specialists or official primary sources when making real security decisions, legal judgements or responding to incidents.

Learning to “think” with AI

AI has made it possible to ask immediately about unfamiliar terms.

But Cyber Hiroshima is not aiming to create:

an environment in which AI solves problems for the learner.

What we aim to create is:

an environment in which learners can develop their own thinking through dialogue with AI.

Understand the overall structure through CyBOK.

Try things in practice with SudoRange.

Ask AI about what you do not understand.

Return to the source and verify it.

Then use Cyber Challenge to test your own ability.

Within this Learning Loop, AI becomes a supporting tool that helps learners identify their next step.

5. Read Next

Learn with AI

An introduction to the AI Learning Assistant and future technical architecture being considered by Cyber Hiroshima.

Turning Knowledge into Practice — What Can You Learn with a Cyber Range and SudoRange?

An introduction to the practical environment that can be combined with AI-supported understanding.