Pith. sign in

REVIEW 7 cited by

Automated Cyber Defence: A Review

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2303.04926 v1 pith:HSR4I63A submitted 2023-03-08 cs.CR cs.AI

classification cs.CRcs.AI
keywords cyberautomateddefenceagentsanalysisdevelopmentgymsrequirement
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Within recent times, cybercriminals have curated a variety of organised and resolute cyber attacks within a range of cyber systems, leading to consequential ramifications to private and governmental institutions. Current security-based automation and orchestrations focus on automating fixed purpose and hard-coded solutions, which are easily surpassed by modern-day cyber attacks. Research within Automated Cyber Defence will allow the development and enabling intelligence response by autonomously defending networked systems through sequential decision-making agents. This article comprehensively elaborates the developments within Automated Cyber Defence through a requirement analysis divided into two sub-areas, namely, automated defence and attack agents and Autonomous Cyber Operation (ACO) Gyms. The requirement analysis allows the comparison of automated agents and highlights the importance of ACO Gyms for their continual development. The requirement analysis is also used to critique ACO Gyms with an overall aim to develop them for deploying automated agents within real-world networked systems. Relevant future challenges were addressed from the overall analysis to accelerate development within the area of Automated Cyber Defence.

Discussion (0). Sign in to comment.

Forward citations

Cited by 7 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Beyond Rewards in Reinforcement Learning for Cyber Defence

    cs.LG 2026-02 conditional novelty 6.0 of 10

    Sparse, goal-aligned rewards outperform dense engineered rewards for training cyber-defence RL agents, but the advantage depends on the evaluation metric and is not uniformly confirmed in the more complex CAGE environment.

  2. Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response

    cs.CR 2025-07 conditional novelty 6.0 of 10

    The paper defines a D3FEND-based security intent tuple and a two-agent (IDA and IEA) methodology to integrate intent-based cyber defense with decision-theoretic autonomic response.

  3. Interpreting Agent Behaviors in Reinforcement-Learning-Based Cyber-Battle Simulation Platforms

    cs.CR 2025-06 conditional novelty 6.0 of 10

    By tracking per-host ground-truth states, the authors measure how often each CAGE Challenge 2 action actually changes a host's state, finding that top agents waste many actions and that decoys correlate with fewer suc...

  4. Open Security Benchmark: Towards Autonomous Enterprise Cyber Defense

    cs.CR 2026-07 conditional novelty 5.0 of 10

    OSB proposes frozen synthetic-enterprise snapshots with gold posture answers so AI agents can be benchmarked on security investigation via SQL or native vendor APIs.

  5. Strategic Cyber Defense via Reinforcement Learning-Guided Combinatorial Auctions

    cs.GT 2025-09 conditional novelty 5.0 of 10

    RL Q-values are used as bids in a learned combinatorial auction that allocates defensive actions in the DARPA CAGE 2 simulation, giving revenue near an oracle and allocations loosely aligned with defender activity.

  6. Online Incident Response Planning under Model Misspecification through Bayesian Learning and Belief Quantization

    cs.LG 2025-08 conditional novelty 5.0 of 10

    MOBAL learns a model of an ongoing cyberattack with Bayesian updates and computes incident responses with a quantized version of that model, giving robustness to model misspecification on CAGE-2.

  7. Learning to Communicate in Multi-Agent Reinforcement Learning for Autonomous Cyber Defence

    cs.MA 2025-07 conditional novelty 5.0 of 10

    Adapting the DIAL communication algorithm to CybORG, the authors report that one-bit messaging between defenders beats a global-state QMix baseline in harder simulated cyber attack scenarios.

Pith tools