Arrow Research search

Author name cluster

Aditya Shinde

Possible papers associated with this exact author name in Arrow. This page groups case-insensitive exact name matches and is not a full identity disambiguation profile.

4 papers
2 author rows

Possible papers

4

AIJ Journal 2026 Journal Article

Decision-theoretic planning and cognitive modeling for active cyber deception

  • Aditya Shinde
  • Prashant Doshi

Cyber defense is evolving to include deception as a key strategy to thwart adversaries. Cyber deception elevates cyber defense by shifting the focus from intrusion detection and prevention to strategically influencing the attacker’s beliefs and perceptions. However, in its current form, deception is employed passively to mislead and misdirect adversaries using decoy systems called honeypots. We present a decision-theoretic approach to active intent recognition using honeypots. We model cyber deception as a sequential decision-making problem in a two-agent context situated on a single honeypot host. To explicitly reason about the influence of deception on the attacker’s beliefs, we introduce factored finitely-nested interactive POMDPs (I-POMDP X ), a factored variant of the I-POMDP framework. We utilize the I-POMDP X framework to model the problem with multiple candidate attacker types, each of which models a cyber attack across various stages from the attacker’s initial entry to reaching its adversarial objective. Recursive reasoning facilitated by I-POMDPs enables the defender to simulate interactions where the attacker is oblivious of a defender, and also scenarios where the attacker reasons about the defender’s actions. The defending I-POMDP X -based agent uses decoys to engage the attacker at multiple phases to form increasingly accurate predictions of the attacker’s behavior and intent. Subsequently, we leverage the explicit and subjective reasoning capability of the I-POMDP X to model cognitive biases known to play a role in deception. Specifically, we model the fundamental attribution error (FAE) and confirmation bias. We show that the cognitive modeling of these biases using the I-POMDP X framework plays a crucial role in deceiving sophisticated adversaries. We evaluate our framework in both simulations and with the I-POMDP X agent deployed on a honeypot host with instrumentation. Our experiments show that the I-POMDP X -based agent outperforms commonly used deception strategies in intent recognition on honeypots. We explore how the defender’s deception evolves as the attacker becomes more strategic. At higher levels of reasoning, we demonstrate how the defender can leverage the computational modeling of the attacker’s cognitive biases to facilitate deception against sophisticated adversaries. This emerging application of autonomous agents offers a new approach to cyber defense that contrasts with the traditional action-reaction dynamic that has defined interactions between cyber attackers and defenders for years.

ECAI Conference 2025 Conference Paper

Inferring Hidden Behavioral Signatures of Cyber Adversaries Using Inverse Reinforcement Learning

  • Aditya Shinde
  • Prashant Doshi

This paper presents an emerging approach to attacker preference modeling from system-level audit logs using inverse reinforcement learning (IRL). Adversary modeling is an important capability in cybersecurity that lets defenders characterize behaviors of potential attackers, which enables attribution to known cyber adversary groups. Existing approaches rely on documenting an ever-evolving set of attacker tools and techniques to track known threat actors. Although attacks evolve constantly, attacker behavioral preferences are intrinsic and less volatile. Our approach learns the behavioral preferences of cyber adversaries from forensics data on their tools and techniques. We model the attacker as an expert decision-making agent with unknown behavioral preferences situated in a computer host. We leverage attack provenance graphs of audit logs to derive a state-action trajectory of the attack. We test our approach on open datasets of audit logs containing real attack data. Our results demonstrate for the first time that low-level forensics data can automatically reveal an adversary’s subjective preferences, which serves as an additional dimension to modeling and documenting cyber adversaries. Attackers’ preferences tend to be less dynamic despite their different tools and indicate predispositions that are inherent to the attacker. As such, these inferred preferences can potentially serve as unique behavioral signatures of attackers and improve threat attribution.

AAMAS Conference 2024 Conference Paper

Modeling Cognitive Biases in Decision-theoretic Planning for Active Cyber Deception

  • Aditya Shinde
  • Prashant Doshi

This paper presents an approach to modeling and exploiting cognitive biases of cyber attackers in planning for active deception. Sophisticated cyber attacks are primarily orchestrated by human actors. Hence, we focus on the human aspect of the attacker’s decision-making process. Humans deviate from rational decisionmaking due to various cognitive biases. Here, we focus on fundamental attribution error (FAE) and confirmation bias and their role in cyber deception because these biases contribute to humans being deceived. We use the decision-theoretic planning framework of finitely-nested factored I-POMDP (I-POMDPX), which allows us to explicitly model FAE in multi-agent settings and build cognitive models of the attackers. We show how these biases impact their beliefs as they act and obtain more information about the environment and the adversary. The tractability of the I-POMDPX also allows for modeling agents at a higher strategy level where the optimal policy relies on induction and exploitation of these biases. Hence, we also present an I-POMDPX-based rational defender agent that can model the attacker’s beliefs under the influence of FAE and confirmation bias from a higher strategic level, and exploit them. Our experiments in simulated interactions show that the I-POMDPX-based defender agent can induce FAE in an attacker to distort the attacker’s beliefs. Consequently, the defender agent can exploit the attacker’s cognitive biases to extend the duration of the attack to facilitate the attacker’s intent recognition in a controlled environment. Our work provides a general decision-theoretic formulation of FAE and confirmation bias, and demonstrates its role in planning for agent-based active cyber deception.

AAMAS Conference 2021 Conference Paper

Cyber Attack Intent Recognition and Active Deception using Factored Interactive POMDPs

  • Aditya Shinde
  • Prashant Doshi
  • Omid Setayeshfar

This paper presents an intelligent and adaptive agent that employs deception to recognize a cyber adversary’s intent on a honeypot host. Unlike previous approaches to cyber deception, which mainly focus on delaying or confusing the attackers, we focus on engaging with them to learn their intent. We model cyber deception as a sequential decision-making problem in a two-agent context. We introduce factored finitely-nested interactive POMDPs (I-POMDPX) and use this framework to model the problem with multiple attacker types. Our approach models cyber attacks on a single honeypot host across multiple phases from the attacker’s initial entry to reaching its adversarial objective. The defending I-POMDPX-based agent uses decoys to engage with the attacker at multiple phases to form increasingly accurate predictions of the attacker’s behavior and intent. The use of I-POMDPs also enables us to model the adversary’s mental state and investigate how deception affects their beliefs. Our experiments in both simulation and with the agent deployed on a host system show that the I-POMDPX-based agent performs significantly better at intent recognition than commonly used deception strategies on honeypots. This emerging application of autonomous agents offers a new approach that contrasts with the traditional action-reaction dynamic that has defined interactions between cyber attackers and defenders for years.

v2026.09.13