A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber Threats

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hitaj, Briland, Denker, Grit, Tinnel, Laura, McAnally, Michael, DeBruhl, Bruce, Bunting, Nathan, Fafard, Alex, Aaron, Daniel, Roberts, Richard D., Lawson, Joshua, McCain, Greg, Starink, Dylan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913812080230400
author Hitaj, Briland
Denker, Grit
Tinnel, Laura
McAnally, Michael
DeBruhl, Bruce
Bunting, Nathan
Fafard, Alex
Aaron, Daniel
Roberts, Richard D.
Lawson, Joshua
McCain, Greg
Starink, Dylan
author_facet Hitaj, Briland
Denker, Grit
Tinnel, Laura
McAnally, Michael
DeBruhl, Bruce
Bunting, Nathan
Fafard, Alex
Aaron, Daniel
Roberts, Richard D.
Lawson, Joshua
McCain, Greg
Starink, Dylan
contents Cyberspace is an ever-evolving battleground involving adversaries seeking to circumvent existing safeguards and defenders aiming to stay one step ahead by predicting and mitigating the next threat. Existing mitigation strategies have focused primarily on solutions that consider software or hardware aspects, often ignoring the human factor. This paper takes a first step towards psychology-informed, active defense strategies, where we target biases that human beings are susceptible to under conditions of uncertainty. Using capture-the-flag events, we create realistic challenges that tap into a particular cognitive bias: representativeness. This study finds that this bias can be triggered to thwart hacking attempts and divert hackers into non-vulnerable attack paths. Participants were exposed to two different challenges designed to exploit representativeness biases. One of the representativeness challenges significantly thwarted attackers away from vulnerable attack vectors and onto non-vulnerable paths, signifying an effective bias-based defense mechanism. This work paves the way towards cyber defense strategies that leverage additional human biases to thwart future, sophisticated adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2504_20245
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber Threats
Hitaj, Briland
Denker, Grit
Tinnel, Laura
McAnally, Michael
DeBruhl, Bruce
Bunting, Nathan
Fafard, Alex
Aaron, Daniel
Roberts, Richard D.
Lawson, Joshua
McCain, Greg
Starink, Dylan
Cryptography and Security
Cyberspace is an ever-evolving battleground involving adversaries seeking to circumvent existing safeguards and defenders aiming to stay one step ahead by predicting and mitigating the next threat. Existing mitigation strategies have focused primarily on solutions that consider software or hardware aspects, often ignoring the human factor. This paper takes a first step towards psychology-informed, active defense strategies, where we target biases that human beings are susceptible to under conditions of uncertainty. Using capture-the-flag events, we create realistic challenges that tap into a particular cognitive bias: representativeness. This study finds that this bias can be triggered to thwart hacking attempts and divert hackers into non-vulnerable attack paths. Participants were exposed to two different challenges designed to exploit representativeness biases. One of the representativeness challenges significantly thwarted attackers away from vulnerable attack vectors and onto non-vulnerable paths, signifying an effective bias-based defense mechanism. This work paves the way towards cyber defense strategies that leverage additional human biases to thwart future, sophisticated adversarial attacks.
title A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber Threats
topic Cryptography and Security
url https://arxiv.org/abs/2504.20245