CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jiang, Yuning, Oo, Nay, Meng, Qiaoran, Lin, Lu, Niyato, Dusit, Xiong, Zehui, Lim, Hoon Wei, Sikdar, Biplab
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916875161567232
author Jiang, Yuning
Oo, Nay
Meng, Qiaoran
Lin, Lu
Niyato, Dusit
Xiong, Zehui
Lim, Hoon Wei
Sikdar, Biplab
author_facet Jiang, Yuning
Oo, Nay
Meng, Qiaoran
Lin, Lu
Niyato, Dusit
Xiong, Zehui
Lim, Hoon Wei
Sikdar, Biplab
contents Modern cyber attacks unfold through multiple stages, requiring defenders to dynamically prioritize mitigations under uncertainty. While game-theoretic models capture attacker-defender interactions, existing approaches often rely on static assumptions and lack integration with real-time threat intelligence, limiting their adaptability. This paper presents CyGATE, a game-theoretic framework modeling attacker-defender interactions, using large language models (LLMs) with retrieval-augmented generation (RAG) to enhance tactic selection and patch prioritization. Applied to a two-agent scenario, CyGATE frames cyber conflicts as a partially observable stochastic game (POSG) across Cyber Kill Chain stages. Both agents use belief states to navigate uncertainty, with the attacker adapting tactics and the defender re-prioritizing patches based on evolving risks and observed adversary behavior. The framework's flexible architecture enables extension to multi-agent scenarios involving coordinated attackers, collaborative defenders, or complex enterprise environments with multiple stakeholders. Evaluated in a dynamic patch scheduling scenario, CyGATE effectively prioritizes high-risk vulnerabilities, enhancing adaptability through dynamic threat integration, strategic foresight by anticipating attacker moves under uncertainty, and efficiency by optimizing resource use.
format Preprint
id arxiv_https___arxiv_org_abs_2508_00478
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization
Jiang, Yuning
Oo, Nay
Meng, Qiaoran
Lin, Lu
Niyato, Dusit
Xiong, Zehui
Lim, Hoon Wei
Sikdar, Biplab
Cryptography and Security
Artificial Intelligence
91A10, 91A43, 68T01, 94A60
C.2.0; I.2.6; K.6.5
Modern cyber attacks unfold through multiple stages, requiring defenders to dynamically prioritize mitigations under uncertainty. While game-theoretic models capture attacker-defender interactions, existing approaches often rely on static assumptions and lack integration with real-time threat intelligence, limiting their adaptability. This paper presents CyGATE, a game-theoretic framework modeling attacker-defender interactions, using large language models (LLMs) with retrieval-augmented generation (RAG) to enhance tactic selection and patch prioritization. Applied to a two-agent scenario, CyGATE frames cyber conflicts as a partially observable stochastic game (POSG) across Cyber Kill Chain stages. Both agents use belief states to navigate uncertainty, with the attacker adapting tactics and the defender re-prioritizing patches based on evolving risks and observed adversary behavior. The framework's flexible architecture enables extension to multi-agent scenarios involving coordinated attackers, collaborative defenders, or complex enterprise environments with multiple stakeholders. Evaluated in a dynamic patch scheduling scenario, CyGATE effectively prioritizes high-risk vulnerabilities, enhancing adaptability through dynamic threat integration, strategic foresight by anticipating attacker moves under uncertainty, and efficiency by optimizing resource use.
title CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization
topic Cryptography and Security
Artificial Intelligence
91A10, 91A43, 68T01, 94A60
C.2.0; I.2.6; K.6.5
url https://arxiv.org/abs/2508.00478