CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866916875161567232 |
|---|---|
| author | Jiang, Yuning Oo, Nay Meng, Qiaoran Lin, Lu Niyato, Dusit Xiong, Zehui Lim, Hoon Wei Sikdar, Biplab |
| author_facet | Jiang, Yuning Oo, Nay Meng, Qiaoran Lin, Lu Niyato, Dusit Xiong, Zehui Lim, Hoon Wei Sikdar, Biplab |
| contents | Modern cyber attacks unfold through multiple stages, requiring defenders to dynamically prioritize mitigations under uncertainty. While game-theoretic models capture attacker-defender interactions, existing approaches often rely on static assumptions and lack integration with real-time threat intelligence, limiting their adaptability. This paper presents CyGATE, a game-theoretic framework modeling attacker-defender interactions, using large language models (LLMs) with retrieval-augmented generation (RAG) to enhance tactic selection and patch prioritization. Applied to a two-agent scenario, CyGATE frames cyber conflicts as a partially observable stochastic game (POSG) across Cyber Kill Chain stages. Both agents use belief states to navigate uncertainty, with the attacker adapting tactics and the defender re-prioritizing patches based on evolving risks and observed adversary behavior. The framework's flexible architecture enables extension to multi-agent scenarios involving coordinated attackers, collaborative defenders, or complex enterprise environments with multiple stakeholders. Evaluated in a dynamic patch scheduling scenario, CyGATE effectively prioritizes high-risk vulnerabilities, enhancing adaptability through dynamic threat integration, strategic foresight by anticipating attacker moves under uncertainty, and efficiency by optimizing resource use. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2508_00478 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization Jiang, Yuning Oo, Nay Meng, Qiaoran Lin, Lu Niyato, Dusit Xiong, Zehui Lim, Hoon Wei Sikdar, Biplab Cryptography and Security Artificial Intelligence 91A10, 91A43, 68T01, 94A60 C.2.0; I.2.6; K.6.5 Modern cyber attacks unfold through multiple stages, requiring defenders to dynamically prioritize mitigations under uncertainty. While game-theoretic models capture attacker-defender interactions, existing approaches often rely on static assumptions and lack integration with real-time threat intelligence, limiting their adaptability. This paper presents CyGATE, a game-theoretic framework modeling attacker-defender interactions, using large language models (LLMs) with retrieval-augmented generation (RAG) to enhance tactic selection and patch prioritization. Applied to a two-agent scenario, CyGATE frames cyber conflicts as a partially observable stochastic game (POSG) across Cyber Kill Chain stages. Both agents use belief states to navigate uncertainty, with the attacker adapting tactics and the defender re-prioritizing patches based on evolving risks and observed adversary behavior. The framework's flexible architecture enables extension to multi-agent scenarios involving coordinated attackers, collaborative defenders, or complex enterprise environments with multiple stakeholders. Evaluated in a dynamic patch scheduling scenario, CyGATE effectively prioritizes high-risk vulnerabilities, enhancing adaptability through dynamic threat integration, strategic foresight by anticipating attacker moves under uncertainty, and efficiency by optimizing resource use. |
| title | CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization |
| topic | Cryptography and Security Artificial Intelligence 91A10, 91A43, 68T01, 94A60 C.2.0; I.2.6; K.6.5 |
| url | https://arxiv.org/abs/2508.00478 |