Modeling Cognitive Biases in Decision-theoretic Planning for Active Cyber Deception

Aditya Shinde (The University of Georgia), Prashant Doshi (The University of Georgia)

Abstract

This paper presents an approach to modeling and exploiting cognitive biases of cyber attackers in planning for active deception. Sophisticated cyber attacks are primarily orchestrated by human actors. Hence, we focus on the human aspect of the attacker's decision-making process. Humans deviate from rational decisionmaking due to various cognitive biases. Here, we focus on fundamental attribution error (FAE) and confirmation bias and their role in cyber deception because these biases contribute to humans being deceived. We use the decision-theoretic planning framework of finitely-nested factored I-POMDP (I-POMDP X), which allows us to explicitly model FAE in multi-agent settings and build cognitive models of the attackers. We show how these biases impact their beliefs as they act and obtain more information about the environment and the adversary. The tractability of the I-POMDP X also allows for modeling agents at a higher strategy level where the optimal policy relies on induction and exploitation of these biases. Hence, we also present an I-POMDP X-based rational defender agent that can model the attacker's beliefs under the influence of FAE and confirmation bias from a higher strategic level, and exploit them. Our experiments in simulated interactions show that the I-POMDP X-based defender agent can induce FAE in an attacker to distort the attacker's beliefs. Consequently, the defender agent can exploit the attacker's cognitive biases to extend the duration of the attack to facilitate the attacker's intent recognition in a controlled environment. Our work provides a general decision-theoretic formulation of FAE and confirmation bias, and demonstrates its role in planning for agent-based active cyber deception.