Hierarchical Multi-agent Reinforcement Learning for Cyber Network Defense

Aditya Vikram Singh (Northeastern University), Ethan Rathbun (Northeastern University), Emma Graham (Dartmouth College), Lisa Oakley (Northeastern University), Simona Boboila (Northeastern University), Peter Chin (Dartmouth College), Alina Oprea (Northeastern University)

Abstract

Multi-agent Reinforcement Learning (MARL) offers new opportunities in the cyber defense domain. We propose a hierarchical MARL architecture that decomposes defense strategies into specialized sub-tasks like network investigation and host recovery. A master defense policy coordinates these sub-tasks, enabling efficient adaptation to shifting attacker strategies with minimal fine-tuning. Evaluation in the CybORG CAGE 4 cyber defense environment shows that our hierarchical learning approach achieves high performance in terms of convergence speed, episodic return, and several interpretable metrics relevant to cybersecurity.