Pith. sign in

REVIEW 3 cited by

Beyond CAGE: Investigating Generalization of Learned Autonomous Network Defense Policies

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2211.15557 v2 pith:QAYKVTST submitted 2022-11-28 cs.LG cs.CR

classification cs.LGcs.CR
keywords networkapproachesautonomousdefensemodelsstrategyadvancementsbuild
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Advancements in reinforcement learning (RL) have inspired new directions in intelligent automation of network defense. However, many of these advancements have either outpaced their application to network security or have not considered the challenges associated with implementing them in the real-world. To understand these problems, this work evaluates several RL approaches implemented in the second edition of the CAGE Challenge, a public competition to build an autonomous network defender agent in a high-fidelity network simulator. Our approaches all build on the Proximal Policy Optimization (PPO) family of algorithms, and include hierarchical RL, action masking, custom training, and ensemble RL. We find that the ensemble RL technique performs strongest, outperforming our other models and taking second place in the competition. To understand applicability to real environments we evaluate each method's ability to generalize to unseen networks and against an unknown attack strategy. In unseen environments, all of our approaches perform worse, with degradation varied based on the type of environmental change. Against an unknown attacker strategy, we found that our models had reduced overall performance even though the new strategy was less efficient than the ones our models trained on. Together, these results highlight promising research directions for autonomous network defense in the real world.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Interpreting Agent Behaviors in Reinforcement-Learning-Based Cyber-Battle Simulation Platforms

    cs.CR 2025-06 conditional novelty 6.0 of 10

    By tracking per-host ground-truth states, the authors measure how often each CAGE Challenge 2 action actually changes a host's state, finding that top agents waste many actions and that decoys correlate with fewer suc...

  2. Strategic Cyber Defense via Reinforcement Learning-Guided Combinatorial Auctions

    cs.GT 2025-09 conditional novelty 5.0 of 10

    RL Q-values are used as bids in a learned combinatorial auction that allocates defensive actions in the DARPA CAGE 2 simulation, giving revenue near an oracle and allocations loosely aligned with defender activity.

  3. Online Incident Response Planning under Model Misspecification through Bayesian Learning and Belief Quantization

    cs.LG 2025-08 conditional novelty 5.0 of 10

    MOBAL learns a model of an ongoing cyberattack with Bayesian updates and computes incident responses with a quantized version of that model, giving robustness to model misspecification on CAGE-2.

Pith tools