Simulation-Informed Bayesian Stackelberg Defense for Multi-Stage Cyber Attacks
Zhao Shen, Rulong He, Xiao ZhangWe examine whether simulated attack-action evidence can inform a defender that they must commit before an attacker’s type is known. We formulate a five-stage Bayesian Stackelberg security game with five stage-specific actions per player. A Monte Carlo predictor produces type-conditioned action likelihoods on an enterprise graph, while prediction confidence weights the next Bayesian update. The defender strategy is computed by exact follower-response enumeration and linear programming. Evaluation used a simulated 10-node enterprise network, 30 paired trials, bootstrap confidence intervals, and Holm-adjusted Wilcoxon tests. Against a fixed-prior Bayesian Strong Stackelberg Equilibrium, mean gross defense utility increased from 2.141 to 2.197. Mean attack success decreased from 0.691 to 0.686. The paired differences remained significant after multiplicity correction. Outcomes did not differ significantly from an equilibrium updated with coarse reference likelihoods, and the simulation cost reduced net utility by 0.08. Maximum follower regret and constraint violation remained at the specified numerical tolerance. Runtime remained near 0.39 s across networks of 10–100 nodes. An action/type experiment showed rapid growth as follower-response profiles increased. Exact commitment and sequential updating were feasible in the abstraction; simulation was not automatically cost-effective when a usable reference model was available.