Beyond Best Response: Quantal Stackelberg Deception as Insurance Against Attacker Misspecification
arXiv SecurityArchived Aug 11, 2026✓ Full text saved
arXiv:2608.08865v1 Announce Type: new Abstract: Stackelberg Security Games (SSG) assume that an attacker observes the defender's strategy and chooses the target that maximizes their expected utility perfectly. In most realistic applications this is not plausible, and in the case of cyber deception (e.g., using decoys) the purpose of the game is to induce uncertainty and mistakes. Quantal response is a common way to represent noise and mistakes in decision-making; here it replaces perfect best-re
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Cryptography and Security
[Submitted on 9 Aug 2026]
Beyond Best Response: Quantal Stackelberg Deception as Insurance Against Attacker Misspecification
Asif Rahman, Md. Abu Sayed, Ahmed Ann Noor Ryen, Ahmed Hemida, Charles A. Kamhoua, Christopher Kiekintveld
Stackelberg Security Games (SSG) assume that an attacker observes the defender's strategy and chooses the target that maximizes their expected utility perfectly. In most realistic applications this is not plausible, and in the case of cyber deception (e.g., using decoys) the purpose of the game is to induce uncertainty and mistakes. Quantal response is a common way to represent noise and mistakes in decision-making; here it replaces perfect best-response with a logit choice with rationality parameter
λ
and results in a generalized Quantal Stackelberg Equilibrium (QSE), which recovers the classical solution exactly as
λ→∞
. We conduct a deeper analysis of how QSE can function as a generalized form of insurance against a variety of forms of model specification error/uncertainty; our analysis shows that QSE provides a practical way to address the important role of tie-breaking rules and model uncertainty in SSG from both a theoretical and practical perspective. We conduct an empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System (CVSS). QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations, with gains of 46\% to 175\% showing a substantial advantage in a wide variety of realistic cases.
Comments: Accepted at Gamesec 2026
Subjects: Cryptography and Security (cs.CR)
Cite as: arXiv:2608.08865 [cs.CR]
(or arXiv:2608.08865v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.08865
Focus to learn more
Submission history
From: Asif Rahman [view email]
[v1] Sun, 9 Aug 2026 19:03:18 UTC (201 KB)
Access Paper:
HTML (experimental)
view license
Current browse context:
cs.CR
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)