arXiv AI

Learning Intrusion Response Strategies for OT Systems

The paper presents a formal model for responding to cyber intrusions in Operational Technology (OT) systems using a Partially Observable Markov Decision Process (POMDP) framework. It incorporates realistic partial observability derived from traffic measurements and develops learning‑based solution methods based on Proximal Policy Optimization (PPO). The resulting response strategies are evaluated on an emulated OT system and shown to be effective against several MITRE attack types for the studied use case.

arXiv Machine Learning
5d ago

Probabilistic Robustness-driven Universal Adversarial Perturbations with Explainability against Deep Reinforcement Learning-based Intrusion Detection System

The paper introduces a new method for generating universal adversarial perturbations (UAPs) against deep reinforcement learning (DRL)-based intrusion detection systems (IDS). It leverages Probabilistic Robustness (PR) as a post‑hoc metric to guide UAP creation, integrating PR directly into the optimization objective. The authors further develop PX‑UAP, which incorporates explainable AI (XAI) to shape perturbations within realistic domain constraints, and provide a theoretical analysis of its design. Experiments show PX‑UAP outperforms existing UAP techniques in attack effectiveness.

By Hongsen Zhang, Lu Zhang, Mingjing Xu, Yi Zhang, Gregory Epiphaniou, Carsten Maple
arXiv AI
Sep 16

A Cyber Range Evaluation of Autonomous Network Incident Response Agents

The study evaluates autonomous agents that respond to network intrusions within a cyber range designed for human operator training. Using an emulated network with variable topology, red‑team attacks, and simulated users, the agents aim to block unauthorized access while minimizing defensive costs. Experiments compare heuristic policies with reinforcement‑learning‑derived policies, finding that the latter generally defend more efficiently, though performance varies with adversary strategy and user simulation.

By Jakob Nyberg, Teodor Sommestad, Andrei Buhaiu, Joakim Loxdal, Pontus Johnson, Mathias Ekstedt
arXiv Machine Learning
Jun 16

Continual Backdoor Training in IoT/CPS

arXiv:2606. 14987v1 Announce Type: cross Abstract: Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility.

By Oxana Salish, Kuniyilh S
arXiv AI
Jul 14

Closing the Loop: An Access-Control Architecture for Automated, Anomaly-Driven Network Revocation in IoT Deployments

arXiv:2607. 11649v1 Announce Type: cross Abstract: Network-based anomaly detection for IoT devices has matured to the point of reporting strong detection accuracy, yet most published systems stop at raising an alert and leave the question of automated enforcement to future work or to a programmable data plane that few real networks operate.

By Muhammet Emir Korkmaz, Kemal Bicakci, Yusuf Uzunay
arXiv AI
Aug 19

Future-Back Threat Modeling: A Foresight-Driven Security Framework

Future-Back Threat Modeling (FBTM) is a predictive security framework that starts with envisioned future threat states and works backward to uncover assumptions, gaps, blind spots, and vulnerabilities in current defense architectures. It aims to reveal both known unknowns and unknown unknowns, including emerging tactics, techniques, and procedures, thereby improving the predictability of adversary behavior under future uncertainty. By anticipating future threats such as AI, information warfare, and supply chain attacks, FBTM helps security leaders make informed decisions today to build more resilient security postures for the future.

By Vu Van Than