2016 · 48 citations · 22 references
Artificial IntelligenceEngineeringInformation SecurityGame TheoryInformation ForensicsAdversarial Machine LearningRecent AttacksMechanism DesignGame DesignThreat DetectionData PrivacyComputer ScienceOpponent ModellingGamesData SecurityReward HackingAttack ModelBusinessGame ConfrontationSecurity Games
Recent attacks show that threats to cyber infrastructure are not only increasing in volume, but are getting more sophisticated. The attacks may comprise multiple actions that are hard to differentiate from benign activity, and therefore common detection techniques have to deal with high false positive rates. Because of the imperfect performance of automated detection techniques, responses to such attacks are highly dependent on human-driven decision-making processes. While game theory has been applied to many problems that require rational decisionmaking, we find limitation on applying such method on security games when the defender has limited information about the opponent's strategies and payoffs. In this work, we propose Q-Learning to react automatically to the adversarial behavior of a suspicious user to secure the system. This work compares variations of Q-Learning with a traditional stochastic game. Simulation results show the possibility of Naive Q-Learning, despite restricted information on opponents.
22
Christopher J. Watkins, Peter Dayan · Machine Learning · 1992 · 8.9K citations · Full text
Lloyd S. Shapley · Proceedings of the National Academy of Sciences · 1953 · 2.4K citations · Full text
Unraveling in Guessing Games: An Experimental Study
Rosemarie Nagel · American Economic Review · 2007 · 1.5K citations