Network and Device Level Cyber Deception for Contested Environments Using RL and LLMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sahu, Abhijeet, Paul, Shuva, Macwan, Richard
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908899420930048
author Sahu, Abhijeet
Paul, Shuva
Macwan, Richard
author_facet Sahu, Abhijeet
Paul, Shuva
Macwan, Richard
contents Cyber deception assists in increasing the attacker's budget in reconnaissance or any early phases of threat intrusions. In the past, numerous methods of cyber deception have been adopted, such as IP address randomization, the creation of honeypots and honeynets mimicking an actual set of services, and networks deployed within an enterprise or operational technology(OT) network. These types of strategies follow naive approaches of recreating services that are expensive and that need a lot of human intervention. The advent of cloud services and other automations of containerized applications, such as Kubernetes, makes cyber defense easier. Yet, there remains a lot of potential to improve the accuracy of these deception strategies and to make them cost-effective using artificial intelligence (AI)-based solutions by making the deception more dynamic. Hence, in this work, we review various AI-based solutions in building network- and device-level cyber deception methods in contested environments. Specifically, we focus on leveraging the fusion of large language models (LLMs) and reinforcement learning(RL) in optimally learning these cyber deception strategies and validating the efficacy of such strategies in some stealthy attacks against OT systems in the literature.
format Preprint
id arxiv_https___arxiv_org_abs_2603_17272
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Network and Device Level Cyber Deception for Contested Environments Using RL and LLMs
Sahu, Abhijeet
Paul, Shuva
Macwan, Richard
Cryptography and Security
Emerging Technologies
Cyber deception assists in increasing the attacker's budget in reconnaissance or any early phases of threat intrusions. In the past, numerous methods of cyber deception have been adopted, such as IP address randomization, the creation of honeypots and honeynets mimicking an actual set of services, and networks deployed within an enterprise or operational technology(OT) network. These types of strategies follow naive approaches of recreating services that are expensive and that need a lot of human intervention. The advent of cloud services and other automations of containerized applications, such as Kubernetes, makes cyber defense easier. Yet, there remains a lot of potential to improve the accuracy of these deception strategies and to make them cost-effective using artificial intelligence (AI)-based solutions by making the deception more dynamic. Hence, in this work, we review various AI-based solutions in building network- and device-level cyber deception methods in contested environments. Specifically, we focus on leveraging the fusion of large language models (LLMs) and reinforcement learning(RL) in optimally learning these cyber deception strategies and validating the efficacy of such strategies in some stealthy attacks against OT systems in the literature.
title Network and Device Level Cyber Deception for Contested Environments Using RL and LLMs
topic Cryptography and Security
Emerging Technologies
url https://arxiv.org/abs/2603.17272