[Paper Review] Attack--Defense Trees and Two-Player Binary Zero-Sum Extensive Form Games Are Equivalent - Technical Report with Proofs
This paper establishes a formal equivalence between attack–defense trees (ADTerms) and two-player binary zero-sum extensive form games, showing that they have equivalent expressive power in terms of satisfiability. The authors define bidirectional mappings between ADTerms and games, preserving outcomes and structural relationships, enabling the application of game-theoretic analysis to security modeling while maintaining intuitive tree representations.
Attack--defense trees are used to describe security weaknesses of a system and possible countermeasures. In this paper, the connection between attack--defense trees and game theory is made explicit. We show that attack--defense trees and binary zero-sum two-player extensive form games have equivalent expressive power when considering satisfiability, in the sense that they can be converted into each other while preserving their outcome and their internal structure.
Motivation & Objective
- To formally establish the equivalence between attack–defense trees (ADTerms) and two-player binary zero-sum extensive form games.
- To enable the application of well-developed game-theoretic analysis techniques to security modeling via ADTerms.
- To resolve structural mismatches between ADTerms and games, particularly regarding conjunctive nodes and refinements.
- To preserve both outcome and internal structure during the transformation between the two formalisms.
Proposed method
- Define ADTerms as typed ground terms over a signature with propositional operators for attacker (p) and defender (o), including disjunction, conjunction, and countermeasure nodes.
- Construct a mapping from games to ADTerms using game structure rules that transform decision nodes, chance moves, and outcome nodes into corresponding ADTerm constructs.
- Define a reverse mapping from ADTerms to games by recursively transforming subterms into game subtrees, introducing dummy moves to model refinements.
- Use a strategy transformation function J·KG to map basic assignments in ADTerms to strategies in games, ensuring that satisfiability corresponds to winning outcomes.
- Prove that a player wins the game if and only if the corresponding ADTerm is satisfiable under the same assignment.
- Handle non-corresponding elements—conjunctive nodes and refinements—by transforming them into equivalent disjunctive or dummy-structured game components.
Experimental results
Research questions
- RQ1Can attack–defense trees be formally mapped to two-player extensive form games while preserving outcome and structure?
- RQ2How can conjunctive nodes in ADTerms be semantically mapped to game-theoretic constructs?
- RQ3How can the refinement mechanism in ADTerms be represented in games without losing expressiveness?
- RQ4Is there a bidirectional, structure-preserving transformation between ADTerms and games?
- RQ5Can game-theoretic analysis techniques be meaningfully applied to ADTerm-based security models?
Key findings
- A bidirectional transformation exists between ADTerms and two-player binary zero-sum extensive form games that preserves both outcome and internal structure.
- An ADTerm is satisfiable for a player if and only if the corresponding game has a winning strategy for that player.
- Conjunctive nodes for one player are transformed into disjunctive nodes for the opponent, enabling semantic equivalence despite structural differences.
- Refinements in ADTerms are modeled using intermediate dummy moves with a single option for the opposing player, preserving the logical flow.
- The transformation is not invertible in the strict sense, as [[t]G]AD ≠ t and [[t]AD]G ≠ t, indicating that the mappings are not inverses.
- The equivalence allows for the application of mature game-theoretic analysis to ADTerm-based security models, enhancing formal verification and strategic reasoning.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.