Skip to main content
QUICK REVIEW

[论文解读] Modeling and Analysis of Leaky Deception using Signaling Games with Evidence

Jeffrey Pawlick, E. J. M. Colbert|arXiv (Cornell University)|Apr 18, 2018
Network Security and Intrusion Detection参考文献 23被引用 5
一句话总结

本文通过整合概率性欺骗检测器来扩展信号博弈,以建模可检测的欺骗行为,推导出汇聚均衡与部分分离均衡。研究发现,高质量的检测器会消除某些纯策略均衡,且出人意料的是,欺骗性发送方由于策略性信号激励,反而可能从高度准确的检测器中获益。

ABSTRACT

Deception plays critical roles in economics and technology, especially in emerging interactions in cyberspace. Holistic models of deception are needed in order to analyze interactions and to design mechanisms that improve them. Game theory provides such models. In particular, existing work models deception using signaling games. But signaling games inherently model deception that is undetectable. In this paper, we extend signaling games by including a detector that gives off probabilistic warnings when the sender acts deceptively. Then we derive pooling and partially-separating equilibria of the game. We find that 1) high-quality detectors eliminate some pure-strategy equilibria, 2) detectors with high true-positive rates encourage more honest signaling than detectors with low false-positive rates, 3) receivers obtain optimal outcomes for equal-error-rate detectors, and 4) surprisingly, deceptive senders sometimes benefit from highly accurate deception detectors. We illustrate these results with an application to defensive deception for network security. Our results provide a quantitative and rigorous analysis of the fundamental aspects of detectable deception.

研究动机与目标

  • 为战略互动中可检测欺骗缺乏整体性、定量化的建模提供解决方案。
  • 通过引入提供欺骗证据的概率检测器,将传统信号博弈(此前仅限于不可检测欺骗)进行扩展。
  • 分析检测器准确率与误报率如何影响战略沟通中的均衡结果。
  • 为评估网络安全与信任管理中的防御性欺骗提供严谨的博弈论框架。

提出的方法

  • 引入一个信号博弈模型,其中发送方(S)拥有私有信息并向接收方(R)发送消息,同时存在一个可生成欺骗概率证据的检测器。
  • 将检测器建模为证据(e)的来源,利用贝叶斯法则更新接收方对发送方诚实性的信念。
  • 推导不同检测器类型下的均衡:保守型(低假阳性)、激进型(低假阴性)以及等错误率检测器。
  • 通过求解满足无差异条件与信念一致性的发送方策略(q, r)和接收方策略(x, y, w, z),分析汇聚均衡与部分分离均衡。
  • 采用效用框架,其中双方的收益取决于发送方类型(θ)、消息(m)、证据(e)及接收方行动(a)。
  • 将模型应用于网络安全领域,说明蜜罐与欺骗机制可通过战略均衡行为进行分析。

实验结果

研究问题

  • RQ1不同检测器特性(真正例率与假正例率)如何影响可检测欺骗信号博弈中均衡的存在性与性质?
  • RQ2在何种条件下,高质量欺骗检测器会消除纯策略均衡?
  • RQ3欺骗性发送方是否可能从高度准确的欺骗检测器中获益?若能,原因是什么?
  • RQ4当欺骗证据以概率方式提供时,接收方的信念形成与行动选择将如何变化?
  • RQ5检测器的误报率对诚实与欺骗的整体战略激励有何影响?

主要发现

  • 高质量检测器通过使欺骗在策略上不可行,消除了某些纯策略均衡。
  • 真正例率高的检测器比假阳性率低的检测器更能促进诚实信号传递。
  • 当使用等错误率检测器时,接收方能实现最优结果,实现检测灵敏度与特异性的平衡。
  • 出人意料的是,欺骗性发送方可能因高度准确的欺骗检测器而受益,这是由于均衡中存在策略性信号激励。
  • 在汇聚均衡中,接收方的行动对偏离均衡的消息保持不变,从而对消息偏离具有鲁棒性。
  • 该模型表明,真相诱导效应取决于检测器类型:保守型检测器在中间区间诱导说真话,而激进型检测器在零主导与一主导区间诱导说真话。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。