Security Games with Layered Defenses: Adaptive Adversaries and Gittins Indices
Chun Kai Ling, Jakub Cerný, Chin Hui Han, Garud Iyengar, Christian Kroer
Abstract
Real-world security applications (e.g., cybersecurity) often involve multiple attack paths, each with layers of defenses that an attacker needs to sequentially overcome before a successful attack on the entire system. Each defensive resource changes dynamically in efficacy as the attack unfolds. In this paper, we study the case where attackers are adaptive, potentially switching paths over time in response to these changes with the goal of minimizing the expected time until a successful attack. We formalize this as a min-max game and give examples where adaptive attackers are more powerful than non-adaptive ones. We show that defenses that do not account for adaptivity can perform arbitrarily worse. A connection between the attacker's optimal strategy with the classical theory of multi-armed bandits and the Gittins index is made, yielding a simple gradient based algorithm to solve our proposed minmax game. Experiments on synthetic settings validate our approach.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f46c1780-347e-4bc4-9576-e0e9d90c8b6dBuilds on2
- Faster Game Solving via Predictive Blackwell Approachability: Connecting Regret Matching and Mirror DescentGabriele Farina, Christian Kroer, Tuomas SandholmAAAI 2021 · 91 citations
- Provably Efficient Reinforcement Learning for Adversarial Restless Multi-Armed Bandits with Unknown Transitions and Bandit FeedbackGuojun Xiong, Jian LiICML 2024 · 1 citation
Related papers
- Multi-token Markov Game with Switching CostsJian Li, Daogao LiuSODA 2022 · 1 citation
- Behavioral Learning in Security Games: Threat of Multi-Step Manipulative AttacksThanh Hong Nguyen, Arunesh SinhaAAAI 2023
- Adversarial Attacks on Adversarial BanditsYuzhe Ma, Zhijin ZhouICLR 2023 · 199 citations
- Catch Me if You Can: Effective Honeypot Placement in Dynamic AD Attack GraphsHuy Quang Ngo, Mingyu Guo, Hung X. NguyenINFOCOM 2024 · 9 citations
- Adversarial Attacks on Combinatorial Multi-Armed BanditsRishab Balasubramanian, Jiawei Li, Prasad Tadepalli, Huazheng Wang et al.ICML 2024 · 4 citations
