paper-with-me

Papers

Manipulating a Learning Defender and Ways to Counteract

2019-05-28 · NeurIPS 2019 12 · Jiarui Gan, Qingyu Guo, Long Tran-Thanh, Bo An, Michael Wooldridge

In Stackelberg security games when information about the attacker's payoffs is uncertain, algorithms have been proposed to learn the optimal defender commitment by interacting with the attacker and observing their best responses. In this paper, we show that, however, these algorithms can be easily manipulated if the attacker responds untruthfully. As a key finding, attacker manipulation normally leads to the defender learning a maximin strategy, which effectively renders the learning attempt meaningless as to compute a maximin strategy requires no additional information about the other player at all. We then apply a game-theoretic framework at a higher level to counteract such manipulation, in which the defender commits to a policy that specifies her strategy commitment according to the learned information. We provide a polynomial-time algorithm to compute the optimal such policy, and in addition, a heuristic approach that applies even when the attacker's payoff space is infinite or completely unknown. Empirical evaluation shows that our approaches can improve the defender's utility significantly as compared to the situation when attacker manipulation is ignored.

📄 PDF Abstract BibTeX arXiv:1905.11759

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Asymptotic Security by Model-based Incident Handlers for Markov Decision Processes

2021-03-24 · Hampei Sasahara, Henrik Sandberg

This study investigates general model-based incident handler's asymptotic behaviors in time against cyber attacks to control systems. The attacker's and the defender's dynamic decision making is modeled as an equilibrium…

Decision Making

AI Agents May Always Fall for Prompt Injections

2026-05-17 · Sahar Abdelnabi, Eugene Bagdasarian arxiv

Prompt injection is the most critical vulnerability in deployed AI agents. Despite recent progress, we show that the prevailing defense paradigm (data-instruction separation) both fails to detect attacks that operate thr…

Leveraging Static Models for Link Prediction in Temporal Knowledge Graphs

2021-06-29 · Wessel Radstok, Mel Chekol

The inclusion of temporal scopes of facts in knowledge graph embedding (KGE) presents significant opportunities for improving the resulting embeddings, and consequently for increased performance in downstream application…

Graph EmbeddingKnowledge Graph EmbeddingKnowledge GraphsLink Prediction

Minimax Least-Square Policy Iteration for Cost-Aware Defense of Traffic Routing against Unknown Threats

2024-04-07 · Yuzhen Zhan, Li Jin

Dynamic routing is one of the representative control scheme in transportation, production lines, and data transmission. In the modern context of connectivity and autonomy, routing decisions are potentially vulnerable to …

Strategic commitments shape collective cybersecurity under AI inequality

2026-05-10 · Adeela Bashir, Zia Ush Shamszaman, Zhao Song, Matjaz Perc 외 arxiv

The growing integration of AI into cybersecurity is reshaping the balance between attackers and defenders. When access to advanced AI-enabled defence tools is uneven, resource-limited defenders may be unable to adopt eff…