arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

有界推理:人机对抗网络防御中的认知层级

Bounded Reasoning: Cognitive Hierarchy in Human-versus-AI Cyber Defense

Zahra Aref, Sheng Wei, Narayan B. Mandayam

arXiv 2610.04878首次发表:更新:

发表机构

Rutgers University(罗格斯大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究通过攻击图上的序贯网络防御博弈,比较人类与自动化防御者,发现人类适应行为符合前景理论,且仅用平均分数评估会掩盖有界推理的差异。

AI 中文摘要

人机评估常常将交互压缩为单一性能分数,即使人类和自动化策略随时间以不同方式适应。我们在攻击图上的序贯网络防御博弈中研究这一问题,其中人类或强化学习防御者保护云资产免受深度Q网络(DQN)攻击者的攻击。我们比较四种防御者设置:仅奖励人类博弈(操作化DQN信息结构)、奖励加转移人类博弈(操作化认知层级理论驱动的DQN(CHT-DQN)信息结构)、自动化DQN防御者以及自动化CHT-DQN防御者。在仅奖励博弈中,参与者接收收益和奖励反馈。在奖励加转移博弈中,他们还看到来自CHT-DQN模型的攻击者感知转移概率。在80名Mechanical Turk参与者和匹配的自动化模拟中,人类防御者以自动化防御者未有的方式适应结果:在两种博弈中,他们在成功防御后比失败后更可能重新选择节点,这种不对称性我们解释为与前景理论和累积前景理论一致。40轮平均值也混合了早期轮次(DQN攻击者大多随机行动)和晚期轮次(其大多利用漏洞);在最后阶段,平均保护排名将奖励加转移人类博弈置于仅奖励人类博弈之上,然后是自动化CHT-DQN防御者,再是自动化DQN防御者,这一顺序被总体平均值掩盖。相比之下,奖励加转移博弈在加权数据保护方面并未比仅奖励博弈产生统计上可靠的总体增益。这些结果表明,仅通过平均任务分数评估人机网络防御系统可能遗漏适应、行动分配和有界人类推理中行为上有意义的差异。

英文摘要

Human-agent evaluations often compress interaction into a single performance score, even when human and automated policies adapt differently over time. We study this in a sequential cyber-defense game on an attack graph, where a human or reinforcement-learning defender protects cloud assets against a Deep Q-Network (DQN) attacker. We compare four defender settings: a human reward-only game operationalizing the DQN information structure, a human reward-plus-transition game operationalizing the Cognitive Hierarchy Theory-driven DQN (CHT-DQN) information structure, an automated DQN defender, and an automated CHT-DQN defender. In the reward-only game, participants receive payoff and reward feedback. In the reward-plus-transition game, they also see attacker-aware transition probabilities from the CHT-DQN model. Across 80 Mechanical Turk participants and matched automated simulations, human defenders adapted to outcomes in a way the automated defenders did not: they were more likely to reselect a node after a successful defense than after a failure, in both games, an asymmetry we interpret as consistent with Prospect Theory and Cumulative Prospect Theory. The 40-round average also mixes early rounds, where the DQN attacker acts mostly at random, with late rounds, where it mostly exploits; in the final stage, mean protection ranks the reward-plus-transition human game above the reward-only human game, then the automated CHT-DQN defender, then the automated DQN defender, an ordering the overall mean hides. By contrast, the reward-plus-transition game does not produce a statistically reliable overall gain in weighted data protection over the reward-only game. These results suggest that evaluating human-agent cyber-defense systems only by an averaged task score can miss behaviorally meaningful differences in adaptation, action allocation, and bounded human reasoning.

Comments9 pages, accepted at the NeurIPS 2026 Workshop on Human-AI Coevolution (HAIC)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑