Can LLMs effectively provide game-theoretic-based scenarios for cybersecurity?

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Proverbio, Daniele, Buscemi, Alessio, Di Stefano, Alessandro, Han, The Anh, Castignani, German, Liò, Pietro
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910025936535552
author Proverbio, Daniele
Buscemi, Alessio
Di Stefano, Alessandro
Han, The Anh
Castignani, German
Liò, Pietro
author_facet Proverbio, Daniele
Buscemi, Alessio
Di Stefano, Alessandro
Han, The Anh
Castignani, German
Liò, Pietro
contents Game theory has long served as a foundational tool in cybersecurity to test, predict, and design strategic interactions between attackers and defenders. The recent advent of Large Language Models (LLMs) offers new tools and challenges for the security of computer systems; In this work, we investigate whether classical game-theoretic frameworks can effectively capture the behaviours of LLM-driven actors and bots. Using a reproducible framework for game-theoretic LLM agents, we investigate two canonical scenarios -- the one-shot zero-sum game and the dynamic Prisoner's Dilemma -- and we test whether LLMs converge to expected outcomes or exhibit deviations due to embedded biases. Our experiments involve four state-of-the-art LLMs and span five natural languages, English, French, Arabic, Vietnamese, and Mandarin Chinese, to assess linguistic sensitivity. For both games, we observe that the final payoffs are influenced by agents characteristics such as personality traits or knowledge of repeated rounds. Moreover, we uncover an unexpected sensitivity of the final payoffs to the choice of languages, which should warn against indiscriminate application of LLMs in cybersecurity applications and call for in-depth studies, as LLMs may behave differently when deployed in different countries. We also employ quantitative metrics to evaluate the internal consistency and cross-language stability of LLM agents, to help guide the selection of the most stable LLMs and optimising models for secure applications.
format Preprint
id arxiv_https___arxiv_org_abs_2508_05670
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Can LLMs effectively provide game-theoretic-based scenarios for cybersecurity?
Proverbio, Daniele
Buscemi, Alessio
Di Stefano, Alessandro
Han, The Anh
Castignani, German
Liò, Pietro
Cryptography and Security
Artificial Intelligence
Computers and Society
Computer Science and Game Theory
Game theory has long served as a foundational tool in cybersecurity to test, predict, and design strategic interactions between attackers and defenders. The recent advent of Large Language Models (LLMs) offers new tools and challenges for the security of computer systems; In this work, we investigate whether classical game-theoretic frameworks can effectively capture the behaviours of LLM-driven actors and bots. Using a reproducible framework for game-theoretic LLM agents, we investigate two canonical scenarios -- the one-shot zero-sum game and the dynamic Prisoner's Dilemma -- and we test whether LLMs converge to expected outcomes or exhibit deviations due to embedded biases. Our experiments involve four state-of-the-art LLMs and span five natural languages, English, French, Arabic, Vietnamese, and Mandarin Chinese, to assess linguistic sensitivity. For both games, we observe that the final payoffs are influenced by agents characteristics such as personality traits or knowledge of repeated rounds. Moreover, we uncover an unexpected sensitivity of the final payoffs to the choice of languages, which should warn against indiscriminate application of LLMs in cybersecurity applications and call for in-depth studies, as LLMs may behave differently when deployed in different countries. We also employ quantitative metrics to evaluate the internal consistency and cross-language stability of LLM agents, to help guide the selection of the most stable LLMs and optimising models for secure applications.
title Can LLMs effectively provide game-theoretic-based scenarios for cybersecurity?
topic Cryptography and Security
Artificial Intelligence
Computers and Society
Computer Science and Game Theory
url https://arxiv.org/abs/2508.05670