English
Related papers

Related papers: Toward a Theory of Cyber Attacks

200 papers

Stackelberg security games are a critical tool for maximizing the utility of limited defense resources to protect important targets from an intelligent adversary. Motivated by green security, where the defender may only observe an…

Computer Science and Game Theory · Computer Science 2020-06-24 Andrew Perrault , Bryan Wilder , Eric Ewing , Aditya Mate , Bistra Dilkina , Milind Tambe

Cyber-security breaches inflict significant costs on organizations. Hence, the development of an information-systems defense capability through cyber-security investment is a prerequisite. The question of how to determine the optimal amount…

Cryptography and Security · Computer Science 2021-12-09 Dimitri Percia David , Alain Mermoud , Sébastien Gillard

Modeling and analyzing security of networked systems is an important problem in the emerging Science of Security and has been under active investigation. In this paper, we propose a new approach towards tackling the problem. Our approach is…

Cryptography and Security · Computer Science 2016-03-29 Gaofeng Da , Maochao Xu , Shouhuai Xu

We empirically evaluate whether AI systems are more effective at attacking or defending in cybersecurity. Using CAI (Cybersecurity AI)'s parallel execution framework, we deployed autonomous agents in 23 Attack/Defense CTF battlegrounds.…

We study automated intrusion prevention using reinforcement learning. Following a novel approach, we formulate the interaction between an attacker and a defender as an optimal stopping game and let attack and defense strategies evolve…

Machine Learning · Computer Science 2022-05-31 Kim Hammar , Rolf Stadler

We implemented and evaluated an automated cyber defense agent. The agent takes security alerts as input and uses reinforcement learning to learn a policy for executing predefined defensive measures. The defender policies were trained in an…

Cryptography and Security · Computer Science 2023-04-24 Jakob Nyberg , Pontus Johnson

The recent advancement in real-world critical infrastructure networks has led to an exponential growth in the use of automated devices which in turn has created new security challenges. In this paper, we study the robust and adaptive…

Computer Science and Game Theory · Computer Science 2020-11-10 Supriyo Ghosh , Patrick Jaillet

Adversarial attacks expose important vulnerabilities of deep learning models, yet little attention has been paid to settings where data arrives as a stream. In this paper, we formalize the online adversarial attack problem, emphasizing two…

This paper provides an efficient computational scheme to handle general security games from an adversarial risk analysis perspective. Two cases in relation to single-stage and multi-stage simultaneous defend-attack games motivate our…

Computer Science and Game Theory · Computer Science 2025-06-04 Jose Manuel Camacho , Roi Naveiro , David Rios Insua

Offensive Robot Cybersecurity introduces a groundbreaking approach by advocating for offensive security methods empowered by means of automation. It emphasizes the necessity of understanding attackers' tactics and identifying…

Robotics · Computer Science 2025-06-19 Víctor Mayoral-Vilches

In this work, we introduce a game-theoretic model that assesses the cyber-security risk of cloud networks and informs security experts on the optimal security strategies. Our approach combines game theory, combinatorial optimization, and…

Optimization and Control · Mathematics 2024-04-17 Gabriele Dragotto , Amine Boukhtouta , Andrea Lodi , Mehdi Taobane

We introduce a formal notion of defendability against backdoors using a game between an attacker and a defender. In this game, the attacker modifies a function to behave differently on a particular input known as the "trigger", while…

Machine Learning · Computer Science 2025-02-12 Paul Christiano , Jacob Hilton , Victor Lecomte , Mark Xu

Intrusion detection is only a starting step in securing IT infrastructure. Prediction of intrusions is the next step to provide an active defense against incoming attacks. Current intrusion prediction methods focus mainly on prediction of…

Cryptography and Security · Computer Science 2016-10-25 Udaya Sampath K. Perera Miriya Thanthrige , Jagath Samarabandu , Xianbin Wang

Modern cyber attacks unfold through multiple stages, requiring defenders to dynamically prioritize mitigations under uncertainty. While game-theoretic models capture attacker-defender interactions, existing approaches often rely on static…

Cryptography and Security · Computer Science 2025-08-04 Yuning Jiang , Nay Oo , Qiaoran Meng , Lu Lin , Dusit Niyato , Zehui Xiong , Hoon Wei Lim , Biplab Sikdar

Though deep neural networks perform challenging tasks excellently, they are susceptible to adversarial examples, which mislead classifiers by applying human-imperceptible perturbations on clean inputs. Under the query-free black-box…

Machine Learning · Computer Science 2020-11-05 Zifei Zhang , Kai Qiao , Jian Chen , Ningning Liang

Probabilistic model checking is a useful technique for specifying and verifying properties of stochastic systems including randomized protocols and reinforcement learning models. Existing methods rely on the assumed structure and…

Cryptography and Security · Computer Science 2022-08-02 Lisa Oakley , Alina Oprea , Stavros Tripakis

We consider two-player games over graphs and give tight bounds on the memory size of strategies ensuring safety objectives. More specifically, we show that the minimal number of memory states of a strategy ensuring a safety objective is…

Computer Science and Game Theory · Computer Science 2024-08-07 Thomas Colcombet , Nathanaël Fijalkow , Florian Horn

Measuring the information leakage is critical for evaluating the practical security of cryptographic devices against side-channel analysis. Information-theoretic measures can be used (along with Fano's inequality) to derive upper bounds on…

Information Theory · Computer Science 2022-05-17 Wei Cheng , Yi Liu , Sylvain Guilley , Olivier Rioul

This paper studies the security of cyber-physical systems under attacks. Our goal is to design system parameters, such as a set of initial conditions and input bounds so that it is secure by design. To this end, we propose new sufficient…

Systems and Control · Electrical Eng. & Systems 2022-01-03 Kunal Garg , Ricardo G. Sanfelice , Alvaro A. Cardenas

We focus on adversarial patrolling games on arbitrary graphs, where the Defender can control a mobile resource, the targets are alarmed by an alarm system, and the Attacker can observe the actions of the mobile resource of the Defender and…

Artificial Intelligence · Computer Science 2018-06-20 Giuseppe De Nittis , Nicola Gatti