Search papers, labs, and topics across Lattice.
This paper introduces a generalized Quantal Stackelberg Equilibrium (QSE) that incorporates decision-making noise to better model attacker behavior in Stackelberg Security Games (SSG). By replacing the assumption of perfect best-response with a logit choice mechanism, the authors demonstrate that QSE serves as a robust form of insurance against model specification errors and uncertainty. The empirical evaluation reveals that QSE significantly outperforms traditional Stackelberg strategies in cybersecurity scenarios, achieving defender utility gains of 46% to 175% across various configurations and conditions.
QSE outperforms traditional Stackelberg strategies in cybersecurity, delivering up to 175% higher defender utility in realistic scenarios with model uncertainty.
Stackelberg Security Games (SSG) assume that an attacker observes the defender's strategy and chooses the target that maximizes their expected utility perfectly. In most realistic applications this is not plausible, and in the case of cyber deception (e.g., using decoys) the purpose of the game is to induce uncertainty and mistakes. Quantal response is a common way to represent noise and mistakes in decision-making; here it replaces perfect best-response with a logit choice with rationality parameter $位$ and results in a generalized Quantal Stackelberg Equilibrium (QSE), which recovers the classical solution exactly as $位\rightarrow \infty$. We conduct a deeper analysis of how QSE can function as a generalized form of insurance against a variety of forms of model specification error/uncertainty; our analysis shows that QSE provides a practical way to address the important role of tie-breaking rules and model uncertainty in SSG from both a theoretical and practical perspective. We conduct an empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System (CVSS). QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations, with gains of 46\% to 175\% showing a substantial advantage in a wide variety of realistic cases.