論文の概要: Beyond Best Response: Quantal Stackelberg Deception as Insurance Against Attacker Misspecification
- arxiv url: http://arxiv.org/abs/2608.08865v1
- Date: Sun, 09 Aug 2026 19:03:18 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-08-11 19:16:36.976809
- Title: Beyond Best Response: Quantal Stackelberg Deception as Insurance Against Attacker Misspecification
- Title(参考訳): クァンタル・シュケルベリ氏:攻撃者の過小評価に対する保険適用で虚偽の疑い
- Authors: Asif Rahman, Md. Abu Sayed, Ahmed Ann Noor Ryen, Ahmed Hemida, Charles A. Kamhoua, Christopher Kiekintveld,
- Abstract要約: 定量応答は、意思決定におけるノイズとミスを表現する一般的な方法である。
ここでは、完全ベストレスポンスを、合理性パラメータ$$でロジット選択に置き換える。
2つのネットワークと実際の脆弱性を用いたサイバーセキュリティケーススタディにおいて、実証的な評価を行う。
- 参考スコア(独自算出の注目度): 2.667221859880545
- License: http://creativecommons.org/licenses/by/4.0/
- Abstract: Stackelberg Security Games (SSG) assume that an attacker observes the defender's strategy and chooses the target that maximizes their expected utility perfectly. In most realistic applications this is not plausible, and in the case of cyber deception (e.g., using decoys) the purpose of the game is to induce uncertainty and mistakes. Quantal response is a common way to represent noise and mistakes in decision-making; here it replaces perfect best-response with a logit choice with rationality parameter $λ$ and results in a generalized Quantal Stackelberg Equilibrium (QSE), which recovers the classical solution exactly as $λ\rightarrow \infty$. We conduct a deeper analysis of how QSE can function as a generalized form of insurance against a variety of forms of model specification error/uncertainty; our analysis shows that QSE provides a practical way to address the important role of tie-breaking rules and model uncertainty in SSG from both a theoretical and practical perspective. We conduct an empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System (CVSS). QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations, with gains of 46\% to 175\% showing a substantial advantage in a wide variety of realistic cases.
- Abstract(参考訳): Stackelberg Security Games (SSG) は、攻撃者がディフェンダーの戦略を観察し、期待されるユーティリティを完全に最大化するターゲットを選択すると仮定する。
ほとんどの現実的なアプリケーションでは、これは不可能であり、サイバー詐欺(例:デコイ)の場合、ゲームの目的は不確実性と間違いを誘発することである。
量子応答は、意思決定におけるノイズや誤りを表す一般的な方法である; ここでは、完全ベストレスポンスをロジット選択に置き換え、有理性パラメータ$λ$で、結果として一般化された量子スタックルバーグ平衡 (QSE) となり、古典解を$λ\rightarrow \infty$として正確に回復する。
我々は、QSEが様々なモデル仕様の誤り/不確実性に対して、一般的な保険形態としてどのように機能するかをより深く分析し、理論的・実践的な観点から、QSEがタイブブレイクルールの重要な役割とSSGにおけるモデル不確実性に対処する実践的な方法を提供することを示す。
我々は,CVEから引き出された2つのネットワークと実際の脆弱性を用いたサイバーセキュリティケーススタディにおいて,CVSS(Common Vulnerability Scoring System)を用いて実証的な評価を行った。
QSEは、仕様エラーと25のパラメータ設定を含む144のシナリオにまたがる現実的なディフェンダーユーティリティでStackelbergを破り、46\%から175\%のゲインは、さまざまな現実的なケースで大きな優位性を示している。
関連論文リスト
- CRESS: Quantifying Vulnerabilities of Attack Scenarios in Hardware Reverse Engineering [37.28207335223867]
ハードウェアのリバースエンジニアリングの結果は、マイクロエレクトロニクスに対する攻撃において重要な役割を果たす。
新たなRE関連攻撃は共通のREスコアシステム(CRESS)の開発を動機づけた
CRESSスコアは、業界標準のCVSS(Common Vulnerability Scoring System)よりもはるかに表現力が高いことが証明されている。
論文 参考訳(メタデータ) (2026-06-03T21:34:57Z) - Benchmarking Large Language Models for Quebec Insurance: From Closed-Book to Retrieval-Augmented Generation [0.0]
大規模言語モデル(LLM)は、自動アドバイザリサービスのためのスケーラブルなソリューションを提供する。
しかし、高度なドメインへの展開は、厳格な法的正確性と信頼性にかかっている。
クローズドブック生成と検索強化生成という,2つのパラダイムにわたる51 LLMの包括的評価を行う。
2)RAGは知識等化剤として機能し、パラメトリック知識の弱いモデルの精度を35ポイント以上向上するが、パラドックス的に「コンテキストの散逸」を引き起こす。
論文 参考訳(メタデータ) (2026-03-08T22:02:32Z) - URAG: A Benchmark for Uncertainty Quantification in Retrieval-Augmented Large Language Models [35.441039437111606]
URAGは、医療、プログラミング、科学、数学、一般的なテキストなど、さまざまな分野にわたるRAGシステムの不確実性を評価するために設計されたベンチマークである。
評価パイプラインを8つの標準RAG手法に適用し,LACとAPSの計測値に基づいて,精度と予測セットのサイズを両立させ,その性能を計測する。
論文 参考訳(メタデータ) (2026-03-02T00:22:06Z) - ReasAlign: Reasoning Enhanced Safety Alignment against Prompt Injection Attack [52.17935054046577]
本稿では、間接的インジェクション攻撃に対する安全性アライメントを改善するためのモデルレベルのソリューションであるReasAlignを提案する。
ReasAlignには、ユーザクエリの分析、競合する命令の検出、ユーザの意図したタスクの継続性を維持するための構造化された推論ステップが組み込まれている。
論文 参考訳(メタデータ) (2026-01-15T08:23:38Z) - Prompting the Priorities: A First Look at Evaluating LLMs for Vulnerability Triage and Prioritization [0.8388262599725365]
セキュリティアナリストは、大規模で複雑な脆弱性バックログをトリアージする圧力が高まっている。
半構造化および非構造化の脆弱性情報を解釈するために,12種類のプロンプト技術を用いて4つのモデルを評価する。
我々は165,000以上のクエリを発行し、ワンショット、少数ショット、チェーンオブソートなどのプロンプトスタイルでパフォーマンスを評価する。
論文 参考訳(メタデータ) (2025-10-21T10:48:14Z) - IntentionReasoner: Facilitating Adaptive LLM Safeguards through Intent Reasoning and Selective Query Refinement [35.904652937034136]
IntentionReasonerは、専用ガードモデルを利用して意図的推論を行う新しいセーフガード機構である。
IntentionReasonerは、複数のセーフガードベンチマーク、生成品質評価、ジェイルブレイク攻撃シナリオに優れています。
論文 参考訳(メタデータ) (2025-08-27T16:47:31Z) - Jailbreaking as a Reward Misspecification Problem [80.52431374743998]
本稿では,この脆弱性をアライメントプロセス中に不特定性に対処する新たな視点を提案する。
本稿では,報酬の相違の程度を定量化し,その有効性を実証する指標ReGapを紹介する。
ReMissは、報酬ミスの空間で敵のプロンプトを生成する自動レッドチームリングシステムである。
論文 参考訳(メタデータ) (2024-06-20T15:12:27Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。