Pith. sign in

REVIEW 2 cited by

Training Automated Defense Strategies Using Graph-based Cyber Attack Simulations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2304.11084 v1 pith:XUQEB7HO submitted 2023-04-17 cs.CR cs.LGcs.NI

classification cs.CRcs.LGcs.NI
keywords agentattackenvironmentpoliciesdefensivetrainedcyberdefender
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We implemented and evaluated an automated cyber defense agent. The agent takes security alerts as input and uses reinforcement learning to learn a policy for executing predefined defensive measures. The defender policies were trained in an environment intended to simulate a cyber attack. In the simulation, an attacking agent attempts to capture targets in the environment, while the defender attempts to protect them by enabling defenses. The environment was modeled using attack graphs based on the Meta Attack Language language. We assumed that defensive measures have downtime costs, meaning that the defender agent was penalized for using them. We also assumed that the environment was equipped with an imperfect intrusion detection system that occasionally produces erroneous alerts based on the environment state. To evaluate the setup, we trained the defensive agent with different volumes of intrusion detection system noise. We also trained agents with different attacker strategies and graph sizes. In experiments, the defensive agent using policies trained with reinforcement learning outperformed agents using heuristic policies. Experiments also demonstrated that the policies could generalize across different attacker strategies. However, the performance of the learned policies decreased as the attack graphs increased in size.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SoK: The Pitfalls of Deep Reinforcement Learning for Cybersecurity

    cs.LG 2026-02 accept novelty 6.0 of 10

    Across 66 DRL-for-cybersecurity papers, the authors identify 11 recurring methodological pitfalls—averaging 5.8 per paper—and demonstrate their impact in four environments.

  2. Training RL Agents for Multi-Objective Network Defense Tasks

    cs.LG 2025-05 conditional novelty 6.0 of 10

    Diverse, dynamically ordered training tasks make network-defense RL agents generalize to unseen attacks better than single-task training.

Pith tools