代表性偏差作为对抗性网络威胁的防御策略研究
密码学与安全
2025-04-30 v1
摘要
网络空间是一个不断演化的战场,威胁方寻求规避现有防御措施,而防御方则致力于预测和缓解下一威胁。现有缓解策略主要关注软件或硬件层面,往往忽视人因。本文致力于心理学导向的主动防御策略,针对人类在不确定条件下易受偏好的认知偏差。通过赛俱比赛事件构建真实挑战,聚焦特定认知偏差——代表性偏差。研究发现,该偏差可被触发以遏制黑客攻击,使其转向非易受攻击的攻击路径。受试者面临两种不同设计的挑战,其中一种代表性挑战显著推动攻击者远离脆弱的攻击向量,转向不易受攻击的路径,表明有效的基于偏差的防御机制。该工作为利用额外的人类偏差遏制未来复杂对抗攻击开辟了道路。
引用
@article{arxiv.2504.20245,
title = {A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber Threats},
author = {Briland Hitaj and Grit Denker and Laura Tinnel and Michael McAnally and Bruce DeBruhl and Nathan Bunting and Alex Fafard and Daniel Aaron and Richard D. Roberts and Joshua Lawson and Greg McCain and Dylan Starink},
journal= {arXiv preprint arXiv:2504.20245},
year = {2025}
}
备注
To appear in the 4th Workshop on Active Defense and Deception (ADnD), co-located with the 10th IEEE European Symposium on Security and Privacy (EuroS&P 2025)