Pith. sign in

REVIEW 3 major objections 5 minor 55 references

Dynamic Contract Design for Systemic Cyber Risk Management of Interdependent Enterprise Networks

T0 review · 3 major / 5 minor · reviewed 2026-08-14 · deepseek-v4-flash

Pith's one-line read A principal who cannot observe a cyber risk manager's effort can still control systemic risk by designing a dynamic pay-for-outcome contract, and in the linear-quadratic case the optimal contract is explicit.

desk verdict A solid, genuinely useful application of continuous-time contract theory to cyber risk, but the LQ lemma overstates its domain and a few proofs need tightening. read the letter →

arxiv 1908.04431 v1 pith:6VQ7AU3P submitted 2019-08-12 eess.SY cs.SY

classification eess.SYcs.SY MSC 91A2393E2091B43
keywords systemiccyberriskdynamiccontractdesignprincipal-agentmoralhazardstochasticdifferentialgamesincentivecompatibilitycertaintyequivalenceinterdependentnetworks
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper argues that an asset owner who cannot observe a cyber risk manager's effort can still control systemic risk by designing a dynamic compensation contract tied to observed risk outcomes. The central device is an incentive-compatible estimator of the hidden effort, built from a martingale representation of the manager's expected cost. The principal's design problem is recast as a standard stochastic optimal control problem, and in the linear-quadratic case an explicit contract is obtained. If the paper is right, moral hazard need not prevent effective cyber risk management, and the optimal contract can be computed from network data.

What carries the argument

The load-bearing object is the incentive-compatible estimator: a process $\zeta_t$, adapted to the principal's observation of $Y$, that appears both in the manager's first-order condition $E_t^* = \arg\max_E (\zeta_t^T E - f_A(t,p_t,E))$ and in the contract's incentive term $\zeta_t^T(dY_t - AY_t\,dt + E_t\,dt)$. Its existence rests on the martingale representation of the manager's total expected cost $U_t$, which is what lets the principal back out the hidden effort from realized risk outcomes. The reformulated principal problem $(O-P')$ is a standard stochastic optimal control problem in the state $(Y_t, h_t)$, and the separation principle splits it into an estimation subproblem for $\zeta_t$ and a control subproblem for $p_t$.

What would settle it

Simulate the LQ contract (36) with a diffusion matrix that has a zero entry or with $Y_t$ observed only through an additional noise, and check whether the manager's best response still equals $R_t^{-1}K_t$; if a deviating effort yields the manager a lower cost, the claimed incentive compatibility fails.

Watch

Extended reading notes

Core claim

The paper claims that under hidden effort the principal retains rational controllability: by choosing the payment flow and terminal compensation so that the manager's best response coincides with the suggested effort, the principal indirectly drives the risk dynamics $dY_t = AY_t\,dt - E_t\,dt + \Sigma_t(Y_t)\,dB_t$. The key step is to show that the suggested effort $E_t^*$ is incentive compatible exactly when $E_t^* = \arg\max_E \zeta_t^T E - f_A(t,p_t,E)$, where $\zeta_t$ is the payment sensitivity to the effort-adjusted risk innovation. This turns the bilateral game into a single-agent stochastic control problem for the principal, with the hidden-effort estimator $\zeta_t$ and the compensation $p_t$ as controls. In the linear-quadratic case the optimal contract is $dc_t = (r c_t - \tfrac12 K_t^T R_t^{-1} K_t)\,dt - K_t^T(dY_t - AY_t\,dt)$, with $K_t$ the solution of $\dot K_t + (A - rI)^T K_t + \rho = 0$, $K_T = \rho$, and the paper claims this achieves the same cost as if the principal saw the effort, so information rent is zero.

Load-bearing premise

The whole derivation assumes the owner sees the risk outcomes perfectly and that the random shocks hitting each node are independent and always present, which is what lets the contract be conditioned on the exact risk surprise.

Editorial extensions

If this is right

  • Under the optimal contract, the manager's effort and the systemic risk level both decrease over time, with effort converging to a positive constant so risk stays low.
  • Stronger network interdependencies require more effort and larger terminal compensation, so connectivity is priced into the contract.
  • In the LQ case each node's allocated effort depends on its out-degree, that is, its risk influence on other nodes, which supports distributed, self-accountable risk mitigation.
  • In the LQ setting and more generally when relevant cost functions are linear, the asymmetric-information contract matches the full-information benchmark: the information rent is zero and a certainty equivalence principle holds.
  • When the principal values money more than the agent does ($\delta_P - \delta_A \ge 1$), intermediate payments vanish and the contract reduces to a terminal payment.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If risk outcomes are observed with noise, the martingale representation that identifies hidden effort breaks down; a natural extension would filter $Y$ before applying the contract, and the separation principle would likely fail in a way the paper does not address.
  • The exact formula for $K_t$ makes the contract directly computable from the network influence matrix $A$, discount rate $r$, and loss vector $\rho$; one could calibrate these from incident data and test whether the prescribed effort actually lowers realized risk.
  • The zero-information-rent result suggests the hidden-action friction disappears whenever payoffs are linear in the state, which may extend to risk-sharing arrangements beyond cybersecurity, such as outsourced infrastructure monitoring.
  • Because $\Sigma_t$ disappears from the optimal contract only under linear costs, a nonlinear loss function would make risk volatility contractible; an empirical question is whether volatility clustering in cyber incidents creates measurable compensation variance.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper studies a continuous-time principal–agent problem for systemic cyber risk management. The principal observes the risk outcome Y_t but not the risk manager's effort E_t; the agent's effort reduces the drift of a linear SDE for systemic risk. The authors derive a class of dynamic contracts with a terminal-payment representation, characterize incentive compatibility through an auxiliary process ζ_t (Theorem 1 and condition (21)), reformulate the principal's problem as a standard stochastic control problem (Theorem 2), and obtain a separation principle under separability assumptions (Theorem 3). In the LQ case they give an explicit optimal contract (Lemma 4, Eq. (36)) driven by the solution K_t of the linear ODE (28), and they compare this with a full-information benchmark, claiming zero information rent and a certainty equivalence principle (Lemma 5, Corollary 4). The paper closes with one-node and networked case studies illustrating the effort, risk, and compensation trajectories.

Significance. If the claims are correct, the paper provides a useful and reasonably self-contained bridge between dynamic contract theory and control-theoretic systemic risk management. The main strengths are that the derivations are analytic and checkable: the HJB verification in Theorem 4 is explicit, the ODEs (28) and (30) have closed-form solutions, and the LQ contract (36) gives a falsifiable prediction about effort and compensation. The separation principle and the zero-information-rent result are also conceptually appealing and would be of interest to both control and applied-theory audiences. However, the paper overstates the domain of its LQ and certainty-equivalence results, and two foundational proofs are too terse to support the claims as stated. These issues are local and reparable, but they need to be addressed before the results can be published in their current form.

major comments (3)
  1. [Section 4.4 and Lemma 4] The LQ optimal-contract statement in Lemma 4, Eq. (36), is unconditional, but it is valid only in the regime δP−δA ≥ 1. In the displayed minimization immediately before Theorem 4, the principal must minimize ∫0^T e^{-rt}(δP−δA−e^{-r(T−t)})p_t dt. The coefficient is nonnegative for every t exactly when δP−δA ≥ 1. When δP−δA < 1, the coefficient is negative on an interval ending at t=T, so with an unbounded feasible set P there is no finite minimizer, and with a compact P the optimum puts p_t at its upper bound near T. In neither case is p_t=0 optimal, and Eq. (36) would be replaced by a contract containing the additional −p_t dt term from (16). Lemma 4 should therefore be stated with the hypothesis δP−δA ≥ 1, and the same qualification must be carried into Lemmas 5–7, which also assume the p_t=0 regime without stating it.
  2. [Section 3.1, Lemma 1] The proof of Lemma 1 is not valid as written. The manuscript says that if the agent's cost is strictly below J̄_A, the principal can reduce his cost by paying less. But p_t enters both the agent's running cost f_A(t,p_t,E_t) in (3) and the incentive-compatibility condition (21), so reducing the payment can change the implemented effort and the principal's risk cost. The IR-binding result can be repaired by varying only the constant c0, which shifts J_A without altering the IC condition, or by a perturbation argument that holds ζ_t and p_t fixed; the current one-sentence proof does not supply such an argument. Since the equality J_A = h_A(c0) is used to set h0=JA in Theorem 2, this gap is load-bearing and should be fixed in the text.
  3. [Section 5.1, Corollary 4] Corollary 4 asserts zero information rent and coincidence of the contracts for a general class of linear functions, with a one-sentence proof. The claim is not supported by the derivation. To obtain the equivalence, one needs, at minimum, the separation structure of (S1)–(S2), invertibility and strict convexity of f_{A,E}, linearity of h_A, and the p_t=0 regime identified in Section 4.4; none of these hypotheses appears in Corollary 4, and the proof does not compare the feasible sets of (O−P′) and (O−B′). The certainty-equivalence principle should either be proved in detail or restricted to the LQ setting with the stated parameter condition.
minor comments (5)
  1. [Section 6.2 and Figure 8] The case study in Figure 8 uses Σ_t(Y_t) = [1,1,0,0; 0,1,1,0; 0,0,1,1; 1,0,0,1], which is not a diagonal matrix, while Section 2.1 defines Σ_t : R^N → D^{N×N}_+ as diagonal. Either relax the standing assumption formally before the case study or revise the example to stay within the stated model.
  2. [Equation (41)] The scalar solution (41) has a removable singularity at A=r. The authors should either state the limiting solution K_t = ρ(1+T−t) for A=r or note that the displayed formula is understood by continuity.
  3. [Corollary 2] Corollary 2 (larger variance under more complex interdependencies) is stated as a formal result but no proof is given; it is used mainly as an interpretation of the case studies. It should be labeled explicitly as an observation or provided with a short argument.
  4. [Throughout] The manuscript contains numerous typos and grammar errors, including 'This feature a reflection' near the end of Section 2.1, 'inluding' in Section 2.1, 'propogate' in the introduction, and 'excepted minimum cost' in Section 6.1. A careful copyedit is needed.
  5. [Section 2.1] The model assumes perfect observation of Y_t and a diagonal positive diffusion coefficient. This is a legitimate modeling choice, but the broad framing of the introduction should explicitly acknowledge that the method does not extend to noisy or partially observed risk outcomes, which are not covered by Proposition 1 or the separation results.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the contract formulas are derived from the stated model assumptions and HJB equations, not fitted or self-referential.

full rationale

The derivation chain is self-contained. The agent's IC constraint is characterized in Theorem 1 from the HJB equation of the agent's problem, and the principal's problem is reformulated in Theorem 2 as a standard stochastic control problem whose solution is then computed in the LQ case (Theorem 4 and Lemma 4). The contract (36) follows by substituting the HJB-optimal ζ*_t = K_t into the payment process (22), with the ODE for K_t obtained by coefficient matching in the principal's HJB equation (31)-(35). The structural relation W_t = h_A(M_t) in Lemma 2 is an explicit contract-form assumption ('we adopt the form Wt = hA(Mt ) and aim to characterize the contract that yields this form'), not a hidden use of the target contract; the paper does not claim it is an external theorem. Self-citations [20] and [6,7,12] are used for context or for an analogous construction, but the relevant proofs (e.g., Lemma 7) are carried out in the paper, so no load-bearing claim reduces to a self-citation. The case studies use chosen parameter values for illustration rather than fitting parameters to outcomes. The p_t-regime concern raised in review concerns whether Lemma 4's unconditional zero-payment statement covers δP−δA<1; that is a correctness/parameter-regime issue, not circularity, because Eq. (36) is still derived from the model equations rather than from its own conclusion. No fitted input is renamed as a prediction, and no known result is merely relabeled.

Assumptions & free parameters 1 free parameters · 7 assumptions · 0 invented entities

The central derivation rests on standard stochastic calculus tools and on the stated convexity and separability assumptions. The only assumptions introduced specifically for this paper's results are the separability conditions (S1)-(S2) and linearity (L1), which limit the generality of the separation and certainty equivalence theorems. No unaccounted fitted parameters support the theory; the numeric values in Section 6 are illustrative only.

free parameters (1)
  • Case-study numeric parameter set (ρ, r, R_t, T, y0, J̄_A, A, Σ) = None; values chosen for illustration
    Section 6 parameters (e.g., ρ=5, r=0.3, R_t=1.5, T=1, y0=5, J̄_A=-10) generate the figures but are not estimated from data and do not enter the theoretical results.
assumptions (7)
  • standard math Martingale representation theorem and Itô calculus
    Used in Proposition 1 and Lemma 2 to rewrite the agent's expected cost as a stochastic integral and to derive the contract dynamics (13).
  • standard math Dynamic programming and HJB verification theorem
    Invoked in Section 3.2 for the agent's optimal effort and in Section 4.4 for the principal's value function; the paper assumes standard regularity conditions.
  • domain assumption Risk dynamics (1): dY_t = AY_t dt - E_t dt + Σ_t(Y_t) dB_t with diagonal positive Σ_t
    Stated in Section 2.1; invertibility of the diffusion is needed for the principal's filtration to reveal the noise and for the martingale representation (10).
  • domain assumption Cost functions satisfy Assumptions 1 and 2 (convexity, monotonicity)
    These assumptions in Section 2.1 guarantee the agent's minimization and the principal's cost structure are well-posed.
  • ad hoc to paper Separability conditions (S1)-(S2) and linear terminal cost (L1)
    Introduced in Section 4.3 to obtain the separation principle; they are not derived from the cyber-risk application.
  • ad hoc to paper LQ functional forms in Section 4.4 (quadratic effort cost, linear risk and payment costs)
    Imposed to obtain explicit closed-form contracts; a standard tractability assumption.
  • domain assumption Existence and uniqueness of solutions to the reformulated stochastic control problem, cited to Yong-Zhou [51]
    The remark after Theorem 2 defers existence and uniqueness to the cited monograph; the paper does not verify the technical conditions itself.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Dynamic Contract Design for Systemic Cyber Risk Management of Interdependent Enterprise Networks." pith.science (2026). https://pith.science/paper/6VQ7AU3P

@misc{pith2026190804431,
  author       = {Pith},
  title        = {Pith review of: Dynamic Contract Design for Systemic Cyber Risk Management of Interdependent Enterprise Networks},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/6VQ7AU3P}},
  note         = {Machine review of arXiv:1908.04431}
}
read the original abstract

The interconnectivity of cyber and physical systems and Internet of things has created ubiquitous concerns of cyber threats for enterprise system managers. It is common that the asset owners and enterprise network operators need to work with cybersecurity professionals to manage the risk by remunerating them for their efforts that are not directly observable. In this paper, we use a principal-agent framework to capture the service relationships between the two parties, i.e., the asset owner (principal) and the cyber risk manager (agent). Specifically, we consider a dynamic systemic risk management problem with asymmetric information where the principal can only observe cyber risk outcomes of the enterprise network rather than directly the efforts that the manager expends on protecting the resources. Under this information pattern, the principal aims to minimize the systemic cyber risks by designing a dynamic contract that specifies the compensation flows and the anticipated efforts of the manager by taking into account his incentives and rational behaviors. We formulate a bi-level mechanism design problem for dynamic contract design within the framework of a class of stochastic differential games. We show that the principal has rational controllability of the systemic risk by designing an incentive compatible estimator of the agent's hidden efforts. We characterize the optimal solution by reformulating the problem as a stochastic optimal control program which can be solved using dynamic programming. We further investigate a benchmark scenario with complete information and identify conditions that yield zero information rent and lead to a new certainty equivalence principle for principal-agent problems. Finally, case studies over networked systems are carried out to illustrate the theoretical results obtained.

Figures

Figures reproduced from arXiv: 1908.04431 by the authors.

Figure 6
Figure 6. The system parameters are the same as those in the 2-node case except for [PITH_FULL_IMAGE:figures/full_fig_p027_6.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

55 extracted references · 54 canonical work pages

  1. [1]

    American Economic Review 105(2), 564–608 (2015)

    Acemoglu, D., Ozdaglar, A., Tahbaz-Salehi, A.: Systemic risk and stability in financial networks. American Economic Review 105(2), 564–608 (2015)

  2. [2]

    Econometrica 81(6), 2463–2485 (2013)

    Athey, S., Segal, I.: An efficient dynamic mechanism. Econometrica 81(6), 2463–2485 (2013)

  3. [3]

    MIT press (1995)

    Aumann, R.J., Maschler, M., Stearns, R.E.: Repeated games with incomplete information. MIT press (1995)

  4. [4]

    IEEE Transactions on Automatic Control 30(2), 118–132 (1985)

    Bas ¸ar, T.: An equilibrium theory for multiperson decision making with multiple probabilistic models. IEEE Transactions on Automatic Control 30(2), 118–132 (1985)

  5. [5]

    Bansal, R., Bas ¸ar, T.: Stochastic teams with nonclassical information revisited: When is an affine law optimal? IEEE Transactions on Automatic Control 32(6), 554–559 (1987)

  6. [6]

    SIAM Journal on Control and Optimization 22(2), 199–210 (1984)

    Bas ¸ar, T.: Affine incentive schemes for stochastic systems with dynamic information. SIAM Journal on Control and Optimization 22(2), 199–210 (1984)

  7. [7]

    European Journal of Political Economy 5(2-3), 203–217 (1989)

    Bas ¸ar, T.: Stochastic incentive problems with partial dynamic information and multiple levels of hier- archy. European Journal of Political Economy 5(2-3), 203–217 (1989)

  8. [8]

    In: Dynamic Games in Economics, pp

    Bas ¸ar, T.: Stochastic differential games and intricacy of information structures. In: Dynamic Games in Economics, pp. 23–49. Springer, Berlin, Heidelberg (2014)

Show all 55 references
  1. [9]

    European Journal of Operational Research 73(2), 226–236 (1994)

    Bas ¸ar, T., Bansal, R.: Optimum design of measurement channels and control policies for linear- quadratic stochastic systems. European Journal of Operational Research 73(2), 226–236 (1994)

  2. [10]

    Econometrica 78(1), 73–118 (2010)

    Biais, B., Mariotti, T., Rochet, J.C., Villeneuve, S.: Large risks, limited liability, and dynamic moral hazard. Econometrica 78(1), 73–118 (2010)

  3. [11]

    Bisias, D., Flood, M., Lo, A.W., Valavanis, S.: A survey of systemic risk analytics. Annu. Rev. Financ. Econ. 4(1), 255–296 (2012)

  4. [12]

    Systems & Control Letters 6(1), 69–75 (1985)

    Cansever, D.H., Bas ¸ar, T.: On stochastic incentive control problems with partial dynamic information. Systems & Control Letters 6(1), 69–75 (1985)

  5. [13]

    SIAM journal on Control and Optimization 46(3), 816–838 (2007) Dynamic Contract Design for Systemic Cyber Risk Management

    Cardaliaguet, P.: Differential games with asymmetric information. SIAM journal on Control and Optimization 46(3), 816–838 (2007) Dynamic Contract Design for Systemic Cyber Risk Management

  6. [14]

    Mathematics of Operations Research 34(4), 769–794 (2009)

    Cardaliaguet, P., Rainer, C.: On a continuous-time game with incomplete information. Mathematics of Operations Research 34(4), 769–794 (2009)

  7. [15]

    Communications in Mathematical Sciences 13(4), 911–933 (2015)

    Carmona, R., Fouque, J.P., Sun, L.H.: Mean field games and systemic risk. Communications in Mathematical Sciences 13(4), 911–933 (2015)

  8. [16]

    IEEE Transactions on Automatic Control 42(8), 1163– 1170 (1997)

    Charalambous, C.D.: The role of information state and adjoint in relating nonlinear output feedback risk-sensitive control and dynamic games. IEEE Transactions on Automatic Control 42(8), 1163– 1170 (1997)

  9. [17]

    IEEE Transactions on Information Forensics and Security, To Appear (2019)

    Chen, J., Touati, C., Zhu, Q.: A dynamic game approach to strategic design of secure and resilient infrastructure network. IEEE Transactions on Information Forensics and Security, To Appear (2019). DOI 10.1109/TIFS.2019.2924130

  10. [18]

    IEEE Transactions on Control of Network Systems, To Appear (2019)

    Chen, J., Touati, C., Zhu, Q.: Optimal secure two-layer IoT network design. IEEE Transactions on Control of Network Systems, To Appear (2019). DOI 10.1109/TCNS.2019.2906893

  11. [19]

    IEEE Transactions on Information Forensics and Secu- rity 12(11), 2736–2750 (2017)

    Chen, J., Zhu, Q.: Security as a service for cloud-enabled internet of controlled things under advanced persistent threats: a contract design approach. IEEE Transactions on Information Forensics and Secu- rity 12(11), 2736–2750 (2017)

  12. [20]

    In: 56th Annual Allerton Conference on Communication, Control, and Computing (Allerton), pp

    Chen, J., Zhu, Q.: A linear quadratic differential game approach to dynamic contract design for sys- temic cyber risk management under asymmetric information. In: 56th Annual Allerton Conference on Communication, Control, and Computing (Allerton), pp. 575–582 (2018)

  13. [21]

    IEEE Transactions on Information Forensics and Security 14(11), 2958–2971 (2019)

    Chen, J., Zhu, Q.: Interdependent strategic security risk management with bounded rationality in the Internet of things. IEEE Transactions on Information Forensics and Security 14(11), 2958–2971 (2019)

  14. [22]

    Computers & Security 56, 1–27 (2016)

    Cherdantseva, Y ., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., Stoddart, K.: A review of cyber security risk assessment methods for SCADA systems. Computers & Security 56, 1–27 (2016)

  15. [23]

    The Quarterly Journal of Economics 102(2), 179–221 (1987)

    Cho, I.K., Kreps, D.M.: Signaling games and stable equilibria. The Quarterly Journal of Economics 102(2), 179–221 (1987)

  16. [24]

    Systems Engineering 8(4), 323– 341 (2005)

    Crowther, K.G., Haimes, Y .Y .: Application of the inoperability input–output model (IIM) for systemic risk assessment and management of interdependent infrastructures. Systems Engineering 8(4), 323– 341 (2005)

  17. [25]

    Springer (2013)

    Cvitanic, J., Zhang, J.: Contract Theory in Continuous-Time Models. Springer (2013)

  18. [26]

    Management Science 47(2), 236–249 (2001)

    Eisenberg, L., Noe, T.H.: Systemic risk in financial systems. Management Science 47(2), 236–249 (2001)

  19. [27]

    American Economic Review 104(10), 3115–53 (2014)

    Elliott, M., Golub, B., Jackson, M.O.: Financial networks and contagion. American Economic Review 104(10), 3115–53 (2014)

  20. [28]

    Cambridge University Press (2013)

    Fouque, J.P., Langsam, J.A.: Handbook on Systemic Risk. Cambridge University Press (2013)

  21. [29]

    Handbook on Systemic Risk p

    Garnier, J., Papanicolaou, G., Yang, T.W.: Diversification in financial networks may increase systemic risk. Handbook on Systemic Risk p. 432 (2013)

  22. [30]

    Gershkov, A., Moldovanu, B.: Dynamic Allocation and Pricing: A Mechanism Design Approach, vol. 9. MIT Press (2014)

  23. [31]

    IEEE Transactions on Control of Network Systems 4(1), 71–81 (2016)

    Gupta, A., Langbort, C., Bas ¸ar, T.: Dynamic games with asymmetric information and resource con- strained players with applications to security of cyberphysical systems. IEEE Transactions on Control of Network Systems 4(1), 71–81 (2016)

  24. [32]

    SIAM Journal on Control and Optimization 52(5), 3228–3260 (2014)

    Gupta, A., Nayyar, A., Langbort, C., Bas ¸ar, T.: Common information based Markov perfect equilibria for linear–Gaussian games with asymmetric information. SIAM Journal on Control and Optimization 52(5), 3228–3260 (2014)

  25. [33]

    In: AAAI, vol

    Hansen, E.A., Bernstein, D.S., Zilberstein, S.: Dynamic programming for partially observable stochastic games. In: AAAI, vol. 4, pp. 709–715 (2004)

  26. [34]

    SIAM Journal on Control and Optimization 34(4), 1342– 1364 (1996)

    James, M.R., Baras, J.: Partially observed differential games, infinite-dimensional Hamilton–Jacobi– Isaacs equations, and nonlinear H∞ control. SIAM Journal on Control and Optimization 34(4), 1342– 1364 (1996)

  27. [35]

    IEEE Transactions on Automatic Control 39(4), 780–792 (1994)

    James, M.R., Baras, J.S., Elliott, R.J.: Risk-sensitive control and dynamic games for partially observed discrete-time nonlinear systems. IEEE Transactions on Automatic Control 39(4), 780–792 (1994)

  28. [36]

    Springer (2012)

    Karatzas, I., Shreve, S.: Brownian Motion and Stochastic Calculus. Springer (2012)

  29. [37]

    International journal of critical infrastructure protection 9, 52–80 (2015)

    Knowles, W., Prince, D., Hutchison, D., Disso, J.F.P., Jones, K.: A survey of cyber security manage- ment in industrial control systems. International journal of critical infrastructure protection 9, 52–80 (2015)

  30. [38]

    SIAM Journal on Control and Optimization 28(5), 999–1048 (1990)

    Kushner, H.J.: Numerical methods for stochastic control problems in continuous time. SIAM Journal on Control and Optimization 28(5), 999–1048 (1990)

  31. [39]

    In: Cyber Situational Awareness, pp

    Li, J., Ou, X., Rajagopalan, R.: Uncertainty and risk management in cyber situational awareness. In: Cyber Situational Awareness, pp. 51–68. Springer (2010) Juntao Chen et al

  32. [40]

    In: Annual Allerton Conference on Communication, Control, and Computing, pp

    Miura-Ko, R.A., Yolken, B., Bambos, N., Mitchell, J.: Security investment games of interdependent organizations. In: Annual Allerton Conference on Communication, Control, and Computing, pp. 252–260 (2008)

  33. [41]

    In: IEEE Conference on Game Theory for Networks, pp

    Nguyen, K.C., Alpcan, T., Bas ¸ar, T.: Stochastic games for security in networks with interdependent nodes. In: IEEE Conference on Game Theory for Networks, pp. 697–703 (2009)

  34. [42]

    IEEE Transactions on Information Forensics and Security14(6), 1654–1669 (2019)

    Pawlick, J., Chen, J., Zhu, Q.: iSTRICT: An interdependent strategic trust mechanism for the cloud- enabled Internet of controlled things. IEEE Transactions on Information Forensics and Security14(6), 1654–1669 (2019)

  35. [43]

    In: Cyber-Risk Management, pp

    Refsdal, A., Solhaug, B., Stølen, K.: Cyber-risk management. In: Cyber-Risk Management, pp. 33–

  36. [44]

    The Review of Economic Studies 75(3), 957–984 (2008)

    Sannikov, Y .: A continuous-time version of the principal-agent problem. The Review of Economic Studies 75(3), 957–984 (2008)

  37. [45]

    Journal of Economic Theory 61(2), 331–371 (1993)

    Sch ¨attler, H., Sung, J.: The first-order approach to the continuous-time principal–agent problem with exponential utility. Journal of Economic Theory 61(2), 331–371 (1993)

  38. [46]

    Computer networks 76, 146–164 (2015)

    Sicari, S., Rizzardi, A., Grieco, L.A., Coen-Porisini, A.: Security, privacy and trust in Internet of things: The road ahead. Computer networks 76, 146–164 (2015)

  39. [47]

    IEEE Transactions on Automatic Control 37(2), 163–173 (1992)

    Srikant, R., Bas ¸ar, T.: Asymptotic solutions to weakly coupled stochastic teams with nonclassical information. IEEE Transactions on Automatic Control 37(2), 163–173 (1992)

  40. [48]

    IEEE Security & Privacy 8(6), 24–31 (2010)

    Takabi, H., Joshi, J.B., Ahn, G.J.: Security and privacy challenges in cloud computing environments. IEEE Security & Privacy 8(6), 24–31 (2010)

  41. [49]

    Journal of Cryptology 26(4), 655–713 (2013)

    Van Dijk, M., Juels, A., Oprea, A., Rivest, R.L.: Flipit: The game of stealthy takeover. Journal of Cryptology 26(4), 655–713 (2013)

  42. [50]

    Journal of Economic Theory 159, 989–1015 (2015)

    Williams, N.: A solvable continuous time dynamic principal–agent model. Journal of Economic Theory 159, 989–1015 (2015)

  43. [51]

    Yong, J., Zhou, X.Y .: Stochastic controls: Hamiltonian systems and HJB equations, vol. 43. Springer (1999)

  44. [52]

    In: Systems & Control: Foundations and Applications Series

    Y ¨uksel, S., Bas ¸ar, T.: Stochastic networked control systems: Stabilization and optimization under information constraints. In: Systems & Control: Foundations and Applications Series. Birkh ¨auser, Boston, MA (2013)

  45. [53]

    In: Proceedings of the 1st International Conference on High Confidence Networked Systems, pp

    Zhu, Q., Bas ¸ar, T.: A dynamic game-theoretic approach to resilient control system design for cas- cading failures. In: Proceedings of the 1st International Conference on High Confidence Networked Systems, pp. 41–46. ACM (2012)

  46. [54]

    In: IEEE Conference on Decision and Control (CDC), pp

    Zhu, Q., Tembine, H., Bas ¸ar, T.: Heterogeneous learning in zero-sum stochastic games with incom- plete information. In: IEEE Conference on Decision and Control (CDC), pp. 219–224 (2010)

  47. [55]

    IEEE Journal on Selected Areas in Communications 30(10), 2006–2015 (2012)

    Zhu, Q., Yuan, Z., Song, J.B., Han, Z., Bas ¸ar, T.: Interference aware routing game for cognitive radio multi-hop networks. IEEE Journal on Selected Areas in Communications 30(10), 2006–2015 (2012)

Pith tools

Reviewed August 14, 2026 · model on record in the stance chip above.