Finding Needles in a Moving Haystack: Prioritizing Alerts with Adversarial Reinforcement Learning
Liang Tong, Aron Laszka, Chao Yan, Ning Zhang, Yevgeniy Vorobeychik
摘要
Detection of malicious behavior is a fundamental problem in security. One of the major challenges in using detection systems in practice is in dealing with an overwhelming number of alerts that are triggered by normal behavior (the so-called false positives), obscuring alerts resulting from actual malicious activity. While numerous methods for reducing the scope of this issue have been proposed, ultimately one must still decide how to prioritize which alerts to investigate, and most existing prioritization methods are heuristic, for example, based on suspiciousness or priority scores. We introduce a novel approach for computing a policy for prioritizing alerts using adversarial reinforcement learning. Our approach assumes that the attacker knows the full state of the detection system and the defender's alert prioritization policy, and will dynamically choose an optimal attack. The first step of our approach is to capture the interaction between the defender and attacker in a game theoretic model. To tackle the computational complexity of solving this game to obtain a dynamic stochastic alert prioritization policy, we propose an adversarial reinforcement learning framework. In this framework, we use neural reinforcement learning to compute best response policies for both the defender and the adversary to an arbitrary stochastic policy of the other. We then use these in a double-oracle framework to obtain an approximate equilibrium of the game, which in turn yields a robust stochastic policy for the defender. Extensive experiments using case studies in fraud and intrusion detection demonstrate that our approach is effective in creating robust alert prioritization policies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- DrSec: Flexible Distributed Representations for Efficient Endpoint SecurityMahmood Sharif, Pubali Datta, Andy Riddle, Kim Westfall 等S&P 2024 · 被引用 8 次
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos 等USENIX Security 2026 · 被引用 7 次
- Principled Data-Driven Decision Support for Cyber-Forensic InvestigationsSoodeh Atefi, Sakshyam Panda, Emmanouil Panaousis, Aron LaszkaAAAI 2023 · 被引用 6 次
- Beyond Rewards in RL for Cyber DefenceElizabeth Bates, Chris Hicks, Vasilios MavroudisICML 2026 · 被引用 3 次
它引用的顶会 Paper1
相关 Paper
- Optimal Attack and Defense for Reinforcement LearningJeremy McMahan, Young Wu, Xiaojin Zhu, Qiaomin XieAAAI 2024 · 被引用 25 次
- Topic-oriented Adversarial Attacks against Black-box Neural Ranking ModelsYu-An Liu, Ruqing Zhang, Jiafeng Guo, Maarten de Rijke 等SIGIR 2023 · 被引用 20 次
- Beyond Conventional Defenses: Proactive and Adversarial-Resilient Hardware Malware Detection using Deep Reinforcement LearningZhangying He, Houman Homayoun, Hossein SayadiDAC 2024 · 被引用 9 次
- PoisonRec: An Adaptive Data Poisoning Framework for Attacking Black-box Recommender SystemsJunshuai Song, Zhao Li, Zehong Hu, Yucheng Wu 等ICDE 2020 · 被引用 83 次
- Actor Critic Deep Reinforcement Learning for Neural Malware ControlYu Wang, Jack W. Stokes, Mady MarinescuAAAI 2020 · 被引用 11 次
