arXiv:2509. 20008v2 Announce Type: replace Abstract: Penetration testing, the simulation of cyberattacks to identify security vulnerabilities, presents a sequential decision-making problem well-suited for reinforcement learning (RL) automation.
By Raphael Simon, Pieter Libin, Wim Mees
The paper introduces a new method for generating universal adversarial perturbations (UAPs) against deep reinforcement learning (DRL)-based intrusion detection systems (IDS). It leverages Probabilistic Robustness (PR) as a post‑hoc metric to guide UAP creation, integrating PR directly into the optimization objective. The authors further develop PX‑UAP, which incorporates explainable AI (XAI) to shape perturbations within realistic domain constraints, and provide a theoretical analysis of its design. Experiments show PX‑UAP outperforms existing UAP techniques in attack effectiveness.
By Hongsen Zhang, Lu Zhang, Mingjing Xu, Yi Zhang, Gregory Epiphaniou, Carsten Maple
arXiv:2608.22075v2 Announce Type: replace-cross
Abstract: Adversaries now move faster than manual response processes can absorb. The average eCrime breakout time, that is, the interval between initia...
By Alexandre Amaral, Fernando Moro, Ana Malheiro
The study evaluates autonomous agents that respond to network intrusions within a cyber range designed for human operator training. Using an emulated network with variable topology, red‑team attacks, and simulated users, the agents aim to block unauthorized access while minimizing defensive costs. Experiments compare heuristic policies with reinforcement‑learning‑derived policies, finding that the latter generally defend more efficiently, though performance varies with adversary strategy and user simulation.
By Jakob Nyberg, Teodor Sommestad, Andrei Buhaiu, Joakim Loxdal, Pontus Johnson, Mathias Ekstedt
arXiv:2606. 18223v1 Announce Type: cross Abstract: With sophisticated cyber-attacks becoming increasingly prevalent, modern networks require intelligent autonomous cyber-defense agents trained via Reinforcement Learning (RL).
By Ankita Samaddar, Sandeep Neema, Daniel Balasubramanian, Xenofon Koutsoukos
arXiv:2606. 06347v1 Announce Type: cross Abstract: This paper addresses the problem of attack detection in cyber-physical systems without any knowledge of the plant model or its structure.
By Sribalaji C. Anand, Anh Tung Nguyen, George J. Pappas
arXiv:2606. 14987v1 Announce Type: cross Abstract: Internet of Things (IoT) and Cyber-physical systems (CPS) increasingly rely on continual learning (CL) to adapt to evolving environments, device heterogeneity, and concept drift, thereby improving overall utility.
By Oxana Salish, Kuniyilh S
arXiv:2608. 15016v1 Announce Type: cross Abstract: Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands.
By Yiran Gao, Juntao Chen, Tao Li
arXiv:2608. 12977v1 Announce Type: cross Abstract: The expanding operational capabilities of large language model (LLM) agents introduce sophisticated security threats.
By Jiajun Ruan, Peiyang Li, Yukun Chen, Fengting Li, Chao Feng
arXiv:2606. 19023v1 Announce Type: cross Abstract: The growing reliance on pre-trained Machine Learning (ML) models has introduced new attack surfaces.
By Gabriele Digregorio, Marco Di Gennaro, Francesco Pastore, Stefano Zanero, Stefano Longari, Michele Carminati
arXiv:2607. 11649v1 Announce Type: cross Abstract: Network-based anomaly detection for IoT devices has matured to the point of reporting strong detection accuracy, yet most published systems stop at raising an alert and leave the question of automated enforcement to future work or to a programmable data plane that few real networks operate.
By Muhammet Emir Korkmaz, Kemal Bicakci, Yusuf Uzunay
Future-Back Threat Modeling (FBTM) is a predictive security framework that starts with envisioned future threat states and works backward to uncover assumptions, gaps, blind spots, and vulnerabilities in current defense architectures. It aims to reveal both known unknowns and unknown unknowns, including emerging tactics, techniques, and procedures, thereby improving the predictability of adversary behavior under future uncertainty. By anticipating future threats such as AI, information warfare, and supply chain attacks, FBTM helps security leaders make informed decisions today to build more resilient security postures for the future.
By Vu Van Than