REVIEW 2 major objections 5 minor 33 references
A class of Markov processes with resetting and applications to cybersecurity
T0 review · 2 major / 5 minor · reviewed 2026-07-14 · grok-4.5
Pith's one-line read A new class of self-exciting Markov processes with endogenous resetting has an explicit invariant density and yields an optimal cyber-intervention threshold.
desk verdict Solid, explicit PDMP construction with endogenous resetting and a clean special-case control solution; the only real caveat is the already-flagged finiteness assumption on reset times. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The endogenous resetting construction together with the Harris-recurrence argument of Kaspi–Mandelbaum: regeneration at the first hitting time of the intensity threshold supplies both uniqueness of the invariant measure and an explicit integral formula for its density.
What would settle it
Take the concrete counter-example of Section 3 (uniform jumps of size at most 2^{-n} and A larger than the sum of all possible jumps): if the intensity path never reaches A, the empirical occupation measure of (N, Λ) fails to converge to the claimed Π.
Extended reading notes
Core claim
Under the assumption that the endogenous reset time TA is almost surely finite, the two-dimensional process Y = (N, Λ) is Harris recurrent and possesses a unique (up to scaling) invariant measure Π whose density is given explicitly by the recursive integral expressions of Theorems 4.2–4.4; for exponential jumps the density and the optimal intervention threshold are available in closed form.
Load-bearing premise
The whole invariant-measure construction collapses if intensity jumps are too small relative to the chosen threshold, so that the process never hits the reset boundary.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper constructs a piecewise-deterministic Markov process X=(N,Λ,C) with endogenous resetting of the intensity Λ at a threshold A, motivated by self-exciting cyber-attack models. Existence of the process is obtained via Hille–Yosida (Theorem 2.1). Under the assumption that the reset time TA is a.s. finite, Y=(N,Λ) is shown to be Harris recurrent with unique (up to scaling) invariant measure Π whose density is given by explicit recursive integral formulae (Theorems 4.2–4.4). For exponential jumps with λ o=β the density is closed-form (Theorem 5.1), and the long-run average control problem of choosing A is solved explicitly in a special case (Proposition 5.1).
Significance. The construction fills a genuine gap in the PDMP literature: classical Davis theory does not allow boundary-to-boundary transitions of the type required here (Remark 2.3). The regeneration structure is exploited cleanly via Kaspi–Mandelbaum to obtain both uniqueness and explicit densities without Lyapunov functions, which is a non-trivial technical contribution. The cyber-security control problem is reduced rigorously to the stationary mean of Λ (Corollary 2.1), and the exponential case yields a fully closed-form optimiser. These results are of interest both to pure PDMP theory and to applied cyber-risk modelling.
major comments (2)
- Assumption 4.1 (P(TA<∞)=1 for every starting point) is load-bearing for Harris recurrence and for the densities of Theorems 4.2–4.4. The paper correctly supplies necessary and sufficient conditions (Theorems 3.1–3.3) and a counter-example (Section 3). For the control problem of Section 5, however, the reader is left without a practical check that the chosen A and the Exp(θ) jumps satisfy the Cramér-type condition of Theorem 3.2. A short remark or corollary verifying that, under Assumption 5.1, E[TA]<∞ for every A>β would close this gap and make the explicit optimiser of Proposition 5.1 fully rigorous.
- In the proof of Theorem 4.2 (Appendix A.2) the singular measure bπ' is asserted to be supported only at {β}. While the argument via separation of measures is standard, the subsequent claim that limλ↑β(β−λ)π(n,λ)=0 (needed for integrability) relies on an induction that is only sketched. A one-line verification that the induction base holds for the explicit π(0,·) of (A.7) would remove any residual doubt about the construction of the probability measure.
minor comments (5)
- Page 1 and throughout: several references carry future dates (IBM 2025, NCSC 2025, WEF 2026, UK Cyber Action Plan 2026). These should be checked for consistency with the arXiv submission date or replaced by the latest publicly available versions.
- Equation (2.11) and the subsequent generator of Y (4.1): the notation Gℓ(n,(A−λ)-) for the left limit is used without a formal definition; a short sentence after (2.12) would help.
- Figure 1 caption: the parameter values β=1, A=2, θ=0.1, α=1.1 produce a density that appears to explode near β; a brief comment on the integrable singularity (cf. (A.54)) would aid the reader.
- Proposition 5.1: the lengthy algebraic expression for A* (5.7) is hard to verify by hand. Supplying a short Mathematica/SymPy notebook or a numerical check against the first-order condition would increase reproducibility.
- Typographical: “formulates and solves a control problem about the tractable case” (end of Introduction) should read “formulates and solves a control problem for the tractable case”; “looses” (p. 5) should be “losses”.
Circularity Check
No circularity: invariant densities and optimal threshold are derived from the generator and regeneration structure under explicit assumptions, with no fitted inputs or load-bearing self-citation chains.
full rationale
The paper constructs a PDMP via its infinitesimal generator (Theorem 2.1, Hille–Yosida), obtains martingale decompositions and the long-run cost identity lim Ct/t = μ_Z lim (∫Λs ds)/t (Corollary 2.1), gives necessary/sufficient conditions for finite reset time TA (Theorems 3.1–3.3, with a counter-example), then under Assumption 4.1 invokes Harris recurrence (Kaspi–Mandelbaum) and solves ΠQα = 0 to obtain explicit recursive densities (Theorems 4.2–4.4) and a closed form for exponential jumps (Theorem 5.1). The control problem minimises η(A)+μ_Z EA[Λ∞] by ordinary calculus on that closed form (Proposition 5.1). None of these steps defines the target in terms of itself, fits a parameter and renames it a prediction, or rests on an unverified uniqueness theorem by the same authors. The only self-citation of substance is Callegaro et al. [5], used as related-work contrast (different control variable and finite-horizon criterion), not as a load-bearing premise. The derivation is self-contained against its stated assumptions.
Assumptions & free parameters
assumptions (5)
- standard math Hille–Yosida theorem for strongly continuous contraction semigroups on Banach spaces
- standard math Harris recurrence criterion of Kaspi & Mandelbaum (1994) for continuous-time processes with a regeneration time
- standard math Kolmogorov three-series theorem
- domain assumption Attack intensity follows a mean-reverting self-exciting SDE with state-dependent jumps and is instantaneously reset to λo upon hitting A
- ad hoc to paper P(TA < ∞)=1 for every starting point (Assumption 4.1)
invented entities (1)
-
Self-exciting PDMP with endogenous boundary-to-boundary resetting
Cite this review
Pith. "Pith review of A class of Markov processes with resetting and applications to cybersecurity." pith.science (2026). https://pith.science/paper/VADC3GDL
@misc{pith2026260710708,
author = {Pith},
title = {Pith review of: A class of Markov processes with resetting and applications to cybersecurity},
year = {2026},
howpublished = {\url{https://pith.science/paper/VADC3GDL}},
note = {Machine review of arXiv:2607.10708}
}
read the original abstract
We introduce a class of piecewise deterministic Markov processes with resetting, motivated by self-exciting models of cyber attacks. Under assumptions reminiscent of ruin theory, we prove the existence and uniqueness of an invariant distribution and derive its density explicitly, thereby establishing ergodicity of the process. We then formulate an associated long-run average control problem in which resetting acts as the intervention mechanism. For exponentially distributed jump sizes, the model becomes analytically tractable, allowing an explicit characterization of the invariant distribution and of the optimal intervention policy.
Figures
Reference graph
Works this paper leans on
-
[1]
Awiszus, T
K. Awiszus, T. Knispel, I. Penner, G. Svindland, A. Voß, and S. Weber. Modeling and pricing cyber insurance: Idiosyncratic, systematic, and sys- temic risks.European Actuarial Journal, 13(1):1–53, 2023. doi: 10.1007/ s13385-023-00341-9
2023
-
[2]
Azéma, M
J. Azéma, M. Duflo, and D. Revuz. Mesure invariante des processus de Markov récurrents. InSéminaire de Probabilités III Université de Strasbourg: Octobre 1967–Juin 1968, pages 24–33. Springer, 2006. MARKOV PROCESSES WITH RESETTING AND CYBER SECURITY 19
1967
-
[3]
A. Baldwin, I. Gheyas, C. Ioannidis, D. Pym, and J. Williams. Contagion in cyber security attacks.Journal of the Operational Research Society, 68(7): 780–791, 2017. doi: 10.1057/jors.2016.37
-
[4]
Y. Bessy-Roland, A. Boumezoued, and C. Hillairet. Multivariate Hawkes process for cyber insurance.Annals of Actuarial Science, 15(1):14–39, 2021. doi: 10.1017/S1748499520000093
-
[5]
G. Callegaro, C. Fontana, C. Hillairet, and B. Ongarato. A stochastic Gordon–Loeb model for optimal cybersecurity investment under clustered attacks. Preprint, arXiv:2505.01221, 2025
arXiv 2025
-
[6]
D. Chafaï, F. Malrieu, and K. Paroux. On the long time behavior of the TCP window size process.Stochastic Processes and their Applications, 120 (8):1518–1534, 2010. doi: 10.1016/j.spa.2010.05.007
-
[7]
O. L. V. Costa and F. Dufour. Stability and ergodicity of piecewise determ- inistic Markov processes.SIAM Journal on Control and Optimization, 47 (2):1053–1077, 2008. doi: 10.1137/060670109
-
[8]
M. H. A. Davis. Piecewise-deterministic Markov processes: a general class of non-diffusion stochastic models.Journal of the Royal Statistical Society. Series B (Methodological), 46(3):353–388, 1984
1984
Show all 33 references
-
[9]
M. H. A. Davis.Markov Models and Optimization, volume 49 ofMonographs on Statistics and Applied Probability. Chapman & Hall, London, 1993
1993
-
[10]
Govern- ment cyber action plan
Department for Science, Innovation and Technology. Govern- ment cyber action plan. Technical report, UK Government, Jan
-
[11]
Available athttps://www.gov.uk/government/publications/ government-cyber-action-plan
-
[12]
Dufour and O
F. Dufour and O. L. V. Costa. Stability of piecewise-deterministic Markov processes.SIAM Journal on Control and Optimization, 37(5):1483–1502,
-
[13]
doi: 10.1137/S0363012997330890
-
[14]
Durrett.Probability: theory and examples, volume 49
R. Durrett.Probability: theory and examples, volume 49. Cambridge univer- sity press, fifth edition, 2019
2019
-
[15]
S. N. Ethier and T. G. Kurtz.Markov processes: characterization and con- vergence. John Wiley & Sons, 2009
2009
-
[16]
M. R. Evans and S. N. Majumdar. Diffusion with stochastic resetting. Physical Review Letters, 106:160601, 2011. doi: 10.1103/PhysRevLett.106. 160601
2011 doi
-
[17]
M. R. Evans, S. N. Majumdar, and G. Schehr. Stochastic resetting and applications.Journal of Physics A: Mathematical and Theoretical, 53(19): 193001, 2020. doi: 10.1088/1751-8121/ab7cfe
2020 doi
-
[18]
M. A. Fahrenwaldt, S. Weber, and K. Weske. Pricing of cyber insurance contracts in a network model.ASTIN Bulletin, 48(3):10175–1218, 2018. doi: 10.1017/asb.2018.23
2018 doi
-
[19]
L. A. Gordon and M. P. Loeb. The economics of information security invest- ment.ACM Transactions on Information and System Security, 5(4):438–457,
-
[20]
doi: 10.1145/581271.581274
-
[21]
A. G. Hawkes. Spectra of some self-exciting and mutually exciting point processes.Biometrika, 58(1):83–90, 1971. doi: 10.1093/biomet/58.1.83
1971 doi
-
[22]
R. He, Z. Jin, and J. S.-H. Li. Modeling and management of cyber risk: a cross-disciplinary review.Annals of Actuarial Science, 18(2):270–309, 2024. doi: 10.1017/S1748499523000258. 20 GIORGIA CALLEGARO, UMUT ÇETİN, BERNARDO D’AURIA
2024 doi
-
[23]
Hillairet and O
C. Hillairet and O. Lopez. Propagation of cyber incidents in an insurance portfolio: counting processes combined with compartmental epidemiological models.Scandinavian Actuarial Journal, 2021(8):671–694, 2021. doi: 10. 1080/03461238.2021.1872694
2021
-
[24]
Hillairet, O
C. Hillairet, O. Lopez, L. d’Oultremont, and B. Spoorenberg. Cyber- contagion model with network structure applied to insurance.Insurance: Mathematics and Economics, 107:88–101, 2022. doi: 10.1016/j.insmatheco. 2022.06.005
2022 doi
-
[25]
Hillairet, A
C. Hillairet, A. Réveillac, and M. Rosenbaum. An expansion formula for Hawkes processes and application to cyber-insurance derivatives.Stochastic Processes and their Applications, 160:89–119, 2023. doi: 10.1016/j.spa.2023. 02.012
2023 doi
-
[26]
Cost of a data breach report 2025
IBM Security. Cost of a data breach report 2025. Technical report, IBM Corporation and Ponemon Institute, 2025. Available athttps://www.ibm. com/reports/data-breach
2025
-
[27]
Jacobsen.Point Process Theory and Applications: Marked Point and Piecewise Deterministic Processes
M. Jacobsen.Point Process Theory and Applications: Marked Point and Piecewise Deterministic Processes. Probability and Its Applications. Birkhäuser, Boston, 2006
2006
-
[28]
Kaspi and A
H. Kaspi and A. Mandelbaum. On Harris recurrence in continuous time. Mathematics of Operations Research, 19(1):211–222, 1994. doi: 10.1287/ moor.19.1.211
1994
-
[29]
Annual review 2025: It’s time to act
National Cyber Security Centre. Annual review 2025: It’s time to act. Tech- nical report, NCSC, GCHQ, Oct. 2025. Available athttps://www.ncsc. gov.uk/collection/ncsc-annual-review-2025
2025
-
[30]
H. R. K. Skeoch. Expanding the Gordon–Loeb model to cyber-insurance. Computers & Security, 112:102533, 2022. doi: 10.1016/j.cose.2021.102533
2022 doi
-
[31]
Cyber security and resilience (network and information systems) bill, 2025
UK Parliament. Cyber security and resilience (network and information systems) bill, 2025. Introduced to Parliament 12 November 2025. Available athttps://bills.parliament.uk/bills/3870
2025
-
[32]
2025 data breach investigations report
Verizon Business. 2025 data breach investigations report. Technical re- port, Verizon, 2025. Available athttps://www.verizon.com/business/ resources/reports/dbir/
2025
-
[33]
Global cybersecurity outlook 2026
World Economic Forum. Global cybersecurity outlook 2026. Tech- nical report, World Economic Forum, in collaboration with Accen- ture, 2026. Available athttps://www.weforum.org/publications/ global-cybersecurity-outlook-2026. MARKOV PROCESSES WITH RESETTING AND CYBER SECURITY 2...
2026
Reviewed July 14, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.