REVIEW 3 cited by
Inroads into Autonomous Network Defence using Explained Reinforcement Learning
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Computer network defence is a complicated task that has necessitated a high degree of human involvement. However, with recent advancements in machine learning, fully autonomous network defence is becoming increasingly plausible. This paper introduces an end-to-end methodology for studying attack strategies, designing defence agents and explaining their operation. First, using state diagrams, we visualise adversarial behaviour to gain insight about potential points of intervention and inform the design of our defensive models. We opt to use a set of deep reinforcement learning agents trained on different parts of the task and organised in a shallow hierarchy. Our evaluation shows that the resulting design achieves a substantial performance improvement compared to prior work. Finally, to better investigate the decision-making process of our agents, we complete our analysis with a feature ablation and importance study.
Forward citations
Cited by 3 Pith papers
-
Optimal Security Response to Network Intrusions in IT Systems
A combination of digital-twin emulation and simulation-based game-theoretic optimization yields near-optimal automated security response strategies for IT infrastructures, demonstrated in emulation.
-
Multi-Objective Reinforcement Learning for Automated Resilient Cyber Defence
In a two-objective CybORG defence game, MOPPO produced policies that trade off network defence against user access, while Pareto Conditioned Networks did not respond reliably to preference prompts.
-
Inherently Interpretable and Uncertainty-Aware Models for Online Learning in Cyber-Security Problems
Rolling-buffer Additive Gaussian Processes deliver competitive, interpretable, uncertainty-aware URL phishing classification in an online setting.
Discussion (0). Continue with ORCID to comment.