arXiv:2508.14385cs.LGcs.AI2025-08中稿 · ACM CCS AISec2025被引 6

面对不准确的系统模型,该方法通过贝叶斯学习动态修正假设并量化决策,提升应急响应的适应性。

Online Incident Response Planning under Model Misspecification through Bayesian Learning and Belief Quantization

  • 用贝叶斯学习在线迭代更新对攻击模型的猜想,实现自适应调整
  • 将模型量化为有限马尔可夫链,支持高效动态规划求解响应策略
  • 在CAGE-2数据集上显著优于现有方法,尤其在模型错误时仍具鲁棒性

有效的网络攻击响应需要快速决策,即使攻击信息不完整或不准确。然而,大多数事件响应决策支持框架依赖于详尽的系统模型,限制了实际应用。本文提出一种在线响应规划方法MOBAL(Misspecified Online Bayesian Learning),用于应对模型误设问题。MOBAL通过贝叶斯学习,随新信息不断修正对模型的假设,实现模型自适应。为实现实时响应,将推测模型量化为有限马尔可夫模型,支持动态规划高效求解。理论证明贝叶斯学习在信息反馈下渐近一致,并给出误设与量化误差的边界。在CAGE-2基准测试中,MOBAL在适应性和对模型误设的鲁棒性方面均优于当前最优方法。

原文摘要 · Abstract (English)

Effective responses to cyberattacks require fast decisions, even when information about the attack is incomplete or inaccurate. However, most decision-support frameworks for incident response rely on a detailed system model that describes the incident, which restricts their practical utility. In this paper, we address this limitation and present an online method for incident response planning under model misspecification, which we call MOBAL: Misspecified Online Bayesian Learning. MOBAL iteratively refines a conjecture about the model through Bayesian learning as new information becomes available, which facilitates model adaptation as the incident unfolds. To determine effective responses online, we quantize the conjectured model into a finite Markov model, which enables efficient response planning through dynamic programming. We prove that Bayesian learning is asymptotically consistent with respect to the information feedback. Additionally, we establish bounds on misspecification and quantization errors. Experiments on the CAGE-2 benchmark show that MOBAL outperforms the state of the art in terms of adaptability and robustness to model misspecification.

在线决策贝叶斯学习安全响应模型误设

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。