Pith. sign in

REVIEW 2 major objections 5 minor 33 references

A class of Markov processes with resetting and applications to cybersecurity

T0 review · 2 major / 5 minor · reviewed 2026-07-14 · grok-4.5

Pith's one-line read A new class of self-exciting Markov processes with endogenous resetting has an explicit invariant density and yields an optimal cyber-intervention threshold.

desk verdict Solid, explicit PDMP construction with endogenous resetting and a clean special-case control solution; the only real caveat is the already-flagged finiteness assumption on reset times. read the letter →

arxiv 2607.10708 v1 pith:VADC3GDL submitted 2026-07-12 math.PR

classification math.PR MSC 60J2560G5593E2091B30
keywords piecewise-deterministicMarkovprocessendogenousresettingself-excitingintensityHarrisrecurrenceinvariantmeasurecyber-riskcontrollong-runaveragecost
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper builds a piecewise-deterministic Markov process that tracks the number of cyber attacks, their stochastic intensity, and cumulative loss, with intensity jumps that are self-exciting and with an endogenous reset that fires the moment intensity hits a chosen threshold A. Under conditions resembling the Cramér–Lundberg condition of ruin theory, the process regenerates almost surely, is Harris recurrent, and admits a unique (up to scaling) invariant measure whose density is written out by recursive integral formulae. Because the long-run average loss is then simply the stationary mean intensity times mean jump size, the firm’s problem of choosing A reduces to a one-dimensional calculus exercise that balances the cost of a more sensitive detection posture against that average intensity. When intensity jumps are exponential the density becomes closed-form, the stationary mean intensity is elementary, and the optimal A can be displayed explicitly.

What carries the argument

The endogenous resetting construction together with the Harris-recurrence argument of Kaspi–Mandelbaum: regeneration at the first hitting time of the intensity threshold supplies both uniqueness of the invariant measure and an explicit integral formula for its density.

What would settle it

Take the concrete counter-example of Section 3 (uniform jumps of size at most 2^{-n} and A larger than the sum of all possible jumps): if the intensity path never reaches A, the empirical occupation measure of (N, Λ) fails to converge to the claimed Π.

Watch

Extended reading notes

Core claim

Under the assumption that the endogenous reset time TA is almost surely finite, the two-dimensional process Y = (N, Λ) is Harris recurrent and possesses a unique (up to scaling) invariant measure Π whose density is given explicitly by the recursive integral expressions of Theorems 4.2–4.4; for exponential jumps the density and the optimal intervention threshold are available in closed form.

Load-bearing premise

The whole invariant-measure construction collapses if intensity jumps are too small relative to the chosen threshold, so that the process never hits the reset boundary.

Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. The paper constructs a piecewise-deterministic Markov process X=(N,Λ,C) with endogenous resetting of the intensity Λ at a threshold A, motivated by self-exciting cyber-attack models. Existence of the process is obtained via Hille–Yosida (Theorem 2.1). Under the assumption that the reset time TA is a.s. finite, Y=(N,Λ) is shown to be Harris recurrent with unique (up to scaling) invariant measure Π whose density is given by explicit recursive integral formulae (Theorems 4.2–4.4). For exponential jumps with λ o=β the density is closed-form (Theorem 5.1), and the long-run average control problem of choosing A is solved explicitly in a special case (Proposition 5.1).

Significance. The construction fills a genuine gap in the PDMP literature: classical Davis theory does not allow boundary-to-boundary transitions of the type required here (Remark 2.3). The regeneration structure is exploited cleanly via Kaspi–Mandelbaum to obtain both uniqueness and explicit densities without Lyapunov functions, which is a non-trivial technical contribution. The cyber-security control problem is reduced rigorously to the stationary mean of Λ (Corollary 2.1), and the exponential case yields a fully closed-form optimiser. These results are of interest both to pure PDMP theory and to applied cyber-risk modelling.

major comments (2)
  1. Assumption 4.1 (P(TA<∞)=1 for every starting point) is load-bearing for Harris recurrence and for the densities of Theorems 4.2–4.4. The paper correctly supplies necessary and sufficient conditions (Theorems 3.1–3.3) and a counter-example (Section 3). For the control problem of Section 5, however, the reader is left without a practical check that the chosen A and the Exp(θ) jumps satisfy the Cramér-type condition of Theorem 3.2. A short remark or corollary verifying that, under Assumption 5.1, E[TA]<∞ for every A>β would close this gap and make the explicit optimiser of Proposition 5.1 fully rigorous.
  2. In the proof of Theorem 4.2 (Appendix A.2) the singular measure bπ' is asserted to be supported only at {β}. While the argument via separation of measures is standard, the subsequent claim that limλ↑β(β−λ)π(n,λ)=0 (needed for integrability) relies on an induction that is only sketched. A one-line verification that the induction base holds for the explicit π(0,·) of (A.7) would remove any residual doubt about the construction of the probability measure.
minor comments (5)
  1. Page 1 and throughout: several references carry future dates (IBM 2025, NCSC 2025, WEF 2026, UK Cyber Action Plan 2026). These should be checked for consistency with the arXiv submission date or replaced by the latest publicly available versions.
  2. Equation (2.11) and the subsequent generator of Y (4.1): the notation Gℓ(n,(A−λ)-) for the left limit is used without a formal definition; a short sentence after (2.12) would help.
  3. Figure 1 caption: the parameter values β=1, A=2, θ=0.1, α=1.1 produce a density that appears to explode near β; a brief comment on the integrable singularity (cf. (A.54)) would aid the reader.
  4. Proposition 5.1: the lengthy algebraic expression for A* (5.7) is hard to verify by hand. Supplying a short Mathematica/SymPy notebook or a numerical check against the first-order condition would increase reproducibility.
  5. Typographical: “formulates and solves a control problem about the tractable case” (end of Introduction) should read “formulates and solves a control problem for the tractable case”; “looses” (p. 5) should be “losses”.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: invariant densities and optimal threshold are derived from the generator and regeneration structure under explicit assumptions, with no fitted inputs or load-bearing self-citation chains.

full rationale

The paper constructs a PDMP via its infinitesimal generator (Theorem 2.1, Hille–Yosida), obtains martingale decompositions and the long-run cost identity lim Ct/t = μ_Z lim (∫Λs ds)/t (Corollary 2.1), gives necessary/sufficient conditions for finite reset time TA (Theorems 3.1–3.3, with a counter-example), then under Assumption 4.1 invokes Harris recurrence (Kaspi–Mandelbaum) and solves ΠQα = 0 to obtain explicit recursive densities (Theorems 4.2–4.4) and a closed form for exponential jumps (Theorem 5.1). The control problem minimises η(A)+μ_Z EA[Λ∞] by ordinary calculus on that closed form (Proposition 5.1). None of these steps defines the target in terms of itself, fits a parameter and renames it a prediction, or rests on an unverified uniqueness theorem by the same authors. The only self-citation of substance is Callegaro et al. [5], used as related-work contrast (different control variable and finite-horizon criterion), not as a load-bearing premise. The derivation is self-contained against its stated assumptions.

Assumptions & free parameters 0 free parameters · 5 assumptions · 1 invented entities

The central claims rest on standard Markov-process machinery (Hille–Yosida, Harris recurrence), domain modelling choices for cyber intensity, and the technical assumption that resets occur almost surely. No free parameters are fitted to data; the only free objects are the model primitives (α,β,λo,A,G,ℓ) that define the process. The invented entity is the endogenous-resetting PDMP itself.

assumptions (5)
  • standard math Hille–Yosida theorem for strongly continuous contraction semigroups on Banach spaces
    Used in Theorem 2.1 / Appendix A.1 to obtain existence of the Markov process from the formal generator.
  • standard math Harris recurrence criterion of Kaspi & Mandelbaum (1994) for continuous-time processes with a regeneration time
    Invoked in Theorem 4.1 to conclude uniqueness of the invariant measure once TA is a.s. finite.
  • standard math Kolmogorov three-series theorem
    Used in Theorem 3.1 to characterise a.s. finiteness of the reset time when α=0.
  • domain assumption Attack intensity follows a mean-reverting self-exciting SDE with state-dependent jumps and is instantaneously reset to λo upon hitting A
    Core modelling hypothesis stated in Section 2; without it the process is not defined.
  • ad hoc to paper P(TA < ∞)=1 for every starting point (Assumption 4.1)
    Standing hypothesis for all stationary-measure results; sufficient conditions are given in Theorems 3.1–3.3 but the assumption itself is not automatic.
invented entities (1)
  • Self-exciting PDMP with endogenous boundary-to-boundary resetting
    purpose: Provides a Markovian state process whose intensity is reset by the firm’s intervention threshold, enabling ergodic analysis of long-run cyber cost.
    Classical PDMP theory forbids boundary-to-boundary jumps; the construction is therefore new to the paper and is the object whose invariant measure is computed.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A class of Markov processes with resetting and applications to cybersecurity." pith.science (2026). https://pith.science/paper/VADC3GDL

@misc{pith2026260710708,
  author       = {Pith},
  title        = {Pith review of: A class of Markov processes with resetting and applications to cybersecurity},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/VADC3GDL}},
  note         = {Machine review of arXiv:2607.10708}
}
read the original abstract

We introduce a class of piecewise deterministic Markov processes with resetting, motivated by self-exciting models of cyber attacks. Under assumptions reminiscent of ruin theory, we prove the existence and uniqueness of an invariant distribution and derive its density explicitly, thereby establishing ergodicity of the process. We then formulate an associated long-run average control problem in which resetting acts as the intervention mechanism. For exponentially distributed jump sizes, the model becomes analytically tractable, allowing an explicit characterization of the invariant distribution and of the optimal intervention policy.

Figures

Figures reproduced from arXiv: 2607.10708 by the authors.

Figure 1
Figure 1. Plot of the density π(λ) given in (5.2) with parameters β = 1, A = 2, θ = 0.1 and α = 1.1. Now, since (N,Λ) is ergodic, it follows from, e.g., Théorème on p.30 in Azéma, Duflo and Revuz [2] that lim t→+∞ 1 t Z t 0 Λsds = EA[Λ∞] := X∞ n=0 Z λΠA(n, dλ), (5.4) where ΠA is the invariant distribution when the intensity is reset at TA. Thus, our problem reads: V = inf A∈R+  c A + µZEA[Λ∞]  . (5.5) Proposition 5.1. Under… view at source ↗
Figure 2
Figure 2. Optimal threshold A∗ as a function of α = 1/θ, given in (5.7) with parameters β = 1, η(A) = c/A, c = 2. and then, recalling Eq. (A.52), we obtain Z A β λ λ − β Z A λ  u − β λ − β − β α du! dλ = α(A − β)(A + 2α + β) 2(α + β) and so EA[Λ∞] = K0 + K0 θ α Z A β λ λ − β Z A λ  u − β λ − β − β α du! dλ = αβ α + A − β + β α + A − β (A − β)(A + 2α + β) 2(α + β) = β(2α 2 + A2 + 2αA − β 2 ) 2(α + β)(α + A − β) . (5.8) It … view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

33 extracted references · 9 canonical work pages

  1. [1]

    Awiszus, T

    K. Awiszus, T. Knispel, I. Penner, G. Svindland, A. Voß, and S. Weber. Modeling and pricing cyber insurance: Idiosyncratic, systematic, and sys- temic risks.European Actuarial Journal, 13(1):1–53, 2023. doi: 10.1007/ s13385-023-00341-9

  2. [2]

    Azéma, M

    J. Azéma, M. Duflo, and D. Revuz. Mesure invariante des processus de Markov récurrents. InSéminaire de Probabilités III Université de Strasbourg: Octobre 1967–Juin 1968, pages 24–33. Springer, 2006. MARKOV PROCESSES WITH RESETTING AND CYBER SECURITY 19

  3. [3]

    Baldwin, I

    A. Baldwin, I. Gheyas, C. Ioannidis, D. Pym, and J. Williams. Contagion in cyber security attacks.Journal of the Operational Research Society, 68(7): 780–791, 2017. doi: 10.1057/jors.2016.37

  4. [4]

    Bessy-Roland, A

    Y. Bessy-Roland, A. Boumezoued, and C. Hillairet. Multivariate Hawkes process for cyber insurance.Annals of Actuarial Science, 15(1):14–39, 2021. doi: 10.1017/S1748499520000093

  5. [5]

    Callegaro, C

    G. Callegaro, C. Fontana, C. Hillairet, and B. Ongarato. A stochastic Gordon–Loeb model for optimal cybersecurity investment under clustered attacks. Preprint, arXiv:2505.01221, 2025

  6. [6]

    Chafaï, F

    D. Chafaï, F. Malrieu, and K. Paroux. On the long time behavior of the TCP window size process.Stochastic Processes and their Applications, 120 (8):1518–1534, 2010. doi: 10.1016/j.spa.2010.05.007

  7. [7]

    O. L. V. Costa and F. Dufour. Stability and ergodicity of piecewise determ- inistic Markov processes.SIAM Journal on Control and Optimization, 47 (2):1053–1077, 2008. doi: 10.1137/060670109

  8. [8]

    M. H. A. Davis. Piecewise-deterministic Markov processes: a general class of non-diffusion stochastic models.Journal of the Royal Statistical Society. Series B (Methodological), 46(3):353–388, 1984

Show all 33 references
  1. [9]

    M. H. A. Davis.Markov Models and Optimization, volume 49 ofMonographs on Statistics and Applied Probability. Chapman & Hall, London, 1993

  2. [10]

    Govern- ment cyber action plan

    Department for Science, Innovation and Technology. Govern- ment cyber action plan. Technical report, UK Government, Jan

  3. [11]

    Available athttps://www.gov.uk/government/publications/ government-cyber-action-plan

  4. [12]

    Dufour and O

    F. Dufour and O. L. V. Costa. Stability of piecewise-deterministic Markov processes.SIAM Journal on Control and Optimization, 37(5):1483–1502,

  5. [13]

    doi: 10.1137/S0363012997330890

  6. [14]

    Durrett.Probability: theory and examples, volume 49

    R. Durrett.Probability: theory and examples, volume 49. Cambridge univer- sity press, fifth edition, 2019

  7. [15]

    S. N. Ethier and T. G. Kurtz.Markov processes: characterization and con- vergence. John Wiley & Sons, 2009

  8. [16]

    M. R. Evans and S. N. Majumdar. Diffusion with stochastic resetting. Physical Review Letters, 106:160601, 2011. doi: 10.1103/PhysRevLett.106. 160601

  9. [17]

    M. R. Evans, S. N. Majumdar, and G. Schehr. Stochastic resetting and applications.Journal of Physics A: Mathematical and Theoretical, 53(19): 193001, 2020. doi: 10.1088/1751-8121/ab7cfe

  10. [18]

    M. A. Fahrenwaldt, S. Weber, and K. Weske. Pricing of cyber insurance contracts in a network model.ASTIN Bulletin, 48(3):10175–1218, 2018. doi: 10.1017/asb.2018.23

  11. [19]

    L. A. Gordon and M. P. Loeb. The economics of information security invest- ment.ACM Transactions on Information and System Security, 5(4):438–457,

  12. [20]

    doi: 10.1145/581271.581274

  13. [21]

    A. G. Hawkes. Spectra of some self-exciting and mutually exciting point processes.Biometrika, 58(1):83–90, 1971. doi: 10.1093/biomet/58.1.83

  14. [22]

    R. He, Z. Jin, and J. S.-H. Li. Modeling and management of cyber risk: a cross-disciplinary review.Annals of Actuarial Science, 18(2):270–309, 2024. doi: 10.1017/S1748499523000258. 20 GIORGIA CALLEGARO, UMUT ÇETİN, BERNARDO D’AURIA

  15. [23]

    Hillairet and O

    C. Hillairet and O. Lopez. Propagation of cyber incidents in an insurance portfolio: counting processes combined with compartmental epidemiological models.Scandinavian Actuarial Journal, 2021(8):671–694, 2021. doi: 10. 1080/03461238.2021.1872694

  16. [24]

    Hillairet, O

    C. Hillairet, O. Lopez, L. d’Oultremont, and B. Spoorenberg. Cyber- contagion model with network structure applied to insurance.Insurance: Mathematics and Economics, 107:88–101, 2022. doi: 10.1016/j.insmatheco. 2022.06.005

  17. [25]

    Hillairet, A

    C. Hillairet, A. Réveillac, and M. Rosenbaum. An expansion formula for Hawkes processes and application to cyber-insurance derivatives.Stochastic Processes and their Applications, 160:89–119, 2023. doi: 10.1016/j.spa.2023. 02.012

  18. [26]

    Cost of a data breach report 2025

    IBM Security. Cost of a data breach report 2025. Technical report, IBM Corporation and Ponemon Institute, 2025. Available athttps://www.ibm. com/reports/data-breach

  19. [27]

    Jacobsen.Point Process Theory and Applications: Marked Point and Piecewise Deterministic Processes

    M. Jacobsen.Point Process Theory and Applications: Marked Point and Piecewise Deterministic Processes. Probability and Its Applications. Birkhäuser, Boston, 2006

  20. [28]

    Kaspi and A

    H. Kaspi and A. Mandelbaum. On Harris recurrence in continuous time. Mathematics of Operations Research, 19(1):211–222, 1994. doi: 10.1287/ moor.19.1.211

  21. [29]

    Annual review 2025: It’s time to act

    National Cyber Security Centre. Annual review 2025: It’s time to act. Tech- nical report, NCSC, GCHQ, Oct. 2025. Available athttps://www.ncsc. gov.uk/collection/ncsc-annual-review-2025

  22. [30]

    H. R. K. Skeoch. Expanding the Gordon–Loeb model to cyber-insurance. Computers & Security, 112:102533, 2022. doi: 10.1016/j.cose.2021.102533

  23. [31]

    Cyber security and resilience (network and information systems) bill, 2025

    UK Parliament. Cyber security and resilience (network and information systems) bill, 2025. Introduced to Parliament 12 November 2025. Available athttps://bills.parliament.uk/bills/3870

  24. [32]

    2025 data breach investigations report

    Verizon Business. 2025 data breach investigations report. Technical re- port, Verizon, 2025. Available athttps://www.verizon.com/business/ resources/reports/dbir/

  25. [33]

    Global cybersecurity outlook 2026

    World Economic Forum. Global cybersecurity outlook 2026. Tech- nical report, World Economic Forum, in collaboration with Accen- ture, 2026. Available athttps://www.weforum.org/publications/ global-cybersecurity-outlook-2026. MARKOV PROCESSES WITH RESETTING AND CYBER SECURITY 2...

Pith tools

Reviewed July 14, 2026 · model on record in the stance chip above.