用形式化方法分析网络防御能力,揭示系统能否被有效防护。
Beyond Runtime Enforcement: Shield Synthesis as Defensibility Analysis for Adversarial Networks

- 将安全机制转化为设计阶段的分析工具,通过博弈论评估防御可行性。
- 得到防御性结论及获胜区域,量化网络在攻击下的安全边界。
- 适合网络安全架构师用于评估系统可防御性,而非直接部署安全策略。
受保护的强化学习通常被视为运行时安全机制,将时序逻辑规范编译为自动机以限制智能体行为。我们提出,这并非最优用途。相同的自动机理论框架——规范编译、产品博弈构建、吸引子计算与获胜区域提取——更适合作为设计阶段的分析工具,其输出是系统的结构洞察,而非部署后的运行约束。本文通过一个受限的双人安全博弈实现该思想,用于网络防御场景。两个规范不对称地施加:防御者规范定义博弈中的不安全区域,攻击者规范则在吸引子计算中限制对手的合法动作。求解博弈后获得防御性结论——一种关于拓扑-规范对是否可防御的形式化证明,以及对应的获胜区域和防护盾。除二元结论外,还从吸引子结构中提取拓扑级指标,并结合防护盾约束下对抗性多智能体强化学习的收敛后行为,形成包含形式安全属性与操作表现的防御性指纹。'如果...会怎样'分析表明,形式防御性与实际有效性反映安全的不同维度:微小架构调整可能引发显著操作结果变化,而形式安全裕度几乎不变。因此,防护盾合成最核心价值不在于部署安全智能体,而在于回答系统在何处、如何、是否可被有效防御的架构问题。防御性结论才是输出,而非安全策略。
原文摘要 · Abstract (English)
Shielded reinforcement learning is typically presented as a runtime safety mechanism that compiles temporal-logic specifications into automata restricting an agent's actions. We argue this is the wrong product. The same automata-theoretic machinery -- specification compilation, product game construction, attractor computation, and winning-region extraction -- is better read as a design-time analytical instrument whose outputs are structural insights about a system rather than runtime constraints on a deployed agent. We instantiate this through a constrained two-player safety game for network defense. The two specifications are enforced asymmetrically: the defender specification defines the unsafe region of the game, whereas the attacker specification restricts the adversary's legal actions during attractor computation. Solving the game yields a defensibility verdict -- a formal certificate that a topology-specification pair is or is not defensible -- with the associated winning region and shield. Beyond the binary verdict, we derive topology-level metrics from the attractor structure and combine them with post-convergence behavior from shield-constrained adversarial multi-agent reinforcement learning. Together these form a defensibility fingerprint capturing both a network's formal safety properties and its operational behavior under adaptive play. A what-if analysis shows that formal defensibility and operational effectiveness capture distinct aspects of security: small architectural changes can produce large shifts in operational outcomes while leaving formal safety margins nearly unchanged. Shield synthesis is thus most valuable not as a deployment mechanism for safe agents, but as a framework for answering architectural questions about whether, where, and how a system can be defended. The defensibility verdict is the output, not the safe policy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。