This paper introduces GAMBiT (Guarding Against Malicious Biased Threats), a cognitive-informed cyber defense framework that leverages deviations from human rationality as a defensive surface. Conventional cyber defenses often assume rational, utility-maximizing attackers, yet real-world adversaries exhibit cognitive constraints and biases that shape their interactions with complex digital systems. GAMBiT embeds insights from cognitive science into cyber environments through cognitive triggers, which activate biases such as loss aversion, base-rate neglect, and sunk-cost fallacy, and through newly developed cognitive sensors that infer attackers’ cognitive states from behavioral and network data. Three rounds of human-subject experiments (total n=61) are conducted in a simulated small business network; the control condition uses the identical network topology and simulation setup, except for cognitive trigger artifacts. The results demonstrate that these manipulations significantly disrupt attacker performance, including reducing mission progress, diverting actions off the true attack path, and increasing detectability. These results demonstrate that cognitive biases can be systematically triggered to degrade the attacker’s efficiency and enhance the defender’s advantage. GAMBiT advances the paradigm in which the attacker’s mind becomes part of the battlefield, and cognitive manipulation becomes a proactive vector for cyber defense, complementing existing approaches through systematic trigger and sensor design as well as the collection of multimodal experimental data.
Decision makers often leverage causal and predictive scientific models, enabling them to better estimate the behavior of a physical or social system and explore several possible outcomes of a policy before actually enacting it. However, these models are only useful insofar as decision makers can effectively interpret the model behaviors, their outputs, and their inherent limitations. In this paper, we describe a methodological approach for uncertainty quantification in stochastic models of sociocultural systems via application of sensitivity analysis techniques, enabling decision makers to explicitly account for uncertainties in model validity or stability when using them as decision support tools. To demonstrate the efficacy of this approach, we present a case study analysis of food security challenges in Gambella, Ethiopia. Using a Bayesian modeling approach, we represent the stochastic interaction of meteorological, agroeconomic, political, and social factors influencing the likelihood of famine in the region and examine the impact of possible mitigating courses of action. Leveraging several sensitivity analysis approaches, we provide evidence of improvements to the decision-making process by making our models more transparent, highlighting the impact that model uncertainty may have when determining the optimal course of action and indicating to the decision maker what questions they need to ask, what data they need to gather, or where to focus their attention to identify and implement the best policy to prevent famine conditions.
The use of causal analysis graphs for developing and evaluating strategies in complex problems is illustrated through two case studies: agricultural production in Gambella, Ethiopia and the crisis in the South China Sea. A Timed Influence net tool called Pythia is used to analyze and evaluate possible courses of action for each case.
To better understand and describe sociocultural systems, it is critical that we can create, analyze, and validate social, political, and economic models that capture causal and predictive dynamics. Causality is, however, notoriously difficult to analyze, a challenge amplified by the complexity of sociocultural systems. Accurately modeling causal relationships in these systems requires incorporating multiple domains of study and a variety of analytic methods. There are numerous approaches to integrating insights from social, natural, and computational sciences to better understand and reason about causality. For example, applying insights from machine learning where ensembles consistently outperform individual approaches, we are developing an ensemble approach to modeling causal relationships. Similarly, we can integrate aspects of rational choice, psychology, and computational simulation to model intergroup dynamics, such as conflict, negotiation, or the value of societal goods. However, while these ensemble and integrated models enable rich representations of complex sociocultural systems and advanced reasoning capabilities, a major challenge is striking the right balance between leveraging computational resources and applying social theory. In this chapter, we will explore some of these technical approaches, discuss the challenges to using them effectively, and provide examples of different interactions between theory-driven and data-driven causal models.
As networked and computer technologies continue to pervade all aspects of our lives, the threat from cyber attacks has also increased. However, detecting attacks, much less predicting them in advance, is a non-trivial task due to the anonymity of cyber attackers and the ambiguity of network data collected within an organization; often, by the time an attack pattern is recognized, the damage has already been done. Evidence suggests that the public discourse in external sources, such as news and social media, is often correlated with the occurrence of larger phenomena, such as election results or violent attacks. In this paper, we propose an approach that uses sentiment polarity as a sensor to analyze the social behavior of groups on social media as an indicator of cyber at-tack behavior. We developed an unsupervised sentiment prediction method that uses emotional signals to enhance the sentiment signal from sparse textual indicators. To explore the efficacy of sentiment polarity as an indicator of cyber-attacks, we performed experiments using real-world data from Twitter that corresponds to attacks by a well-known hacktivist group.
In today's increasingly connected world, cyber attacks have become a serious threat with detrimental effects on individuals, businesses, and broader society. Truly mitigating the negative impacts of these attacks requires a deeper understanding of malicious cyber activities and the capability of predicting these attacks before they occur. However, detecting the occurrence of cyber attacks is non-trivial due to the anonymity of cyber attacks and the ambiguity or unavailability of network data collected within organizations. Thus, we need to explore more nuanced auxiliary information that can provide improved predictive power and insight into the behavioral factors involved in planning and executing a cyber attack. Evidence suggests that public discourse in online sources, such as social media, is strongly correlated with the occurrence of real-world behavior; we believe this same premise can provide predictive indicators of cyber attacks. For example, extreme negative sentiments towards an organization may indicate a higher probability that it will be the target of a cyber attack. In this paper, we propose to use sentiment in social media as a sensor to better understand, detect, and predict cyber attacks. We develop an effective unsupervised sentiment predictor model utilizing emotional signals, such as emoticons or punctuation, common in social media communications, and a method for using this model as part of a logistic regression predictor to correlate changes in sentiment to the probability of an attack. Experiments on real-world social media data around well-known hacktivist attacks demonstrate the efficacy of the proposed sentiment model for cyber attack understanding and prediction.
Analyzing the political, military, economic, social, information, and infrastructure (PMESII) effects in a sociocultural system requires models that capture the causal and predictive dynamics. However, given the complexity of PMESII factors and the diversity of available data sources, accurately modeling causal relationships requires incorporating multiple domains of study and a variety of analytic methods. In this paper, we present an ensemble approach to modeling causal relationships of sociocultural systems, applying insights from machine learning where ensembles consistently outperform individual approaches. We describe three different types of ensemble models and combinations and explore the application of this approach in experiments using both synthetic and real-world datasets.
Cyber adversaries continue to become more proficient and sophisticated, increasing the vulnerability of the network systems that pervade all aspects of our lives. While there are many approaches to modeling network behavior and identifying anomalous and potentially malicious traffic, most of these approaches detect attacks once they have already occurred, enabling reaction only after the damage has been done. In traditional security studies, mitigating attacks has been a focus of many research and planning efforts, leading to a rich field of adversarial modeling to represent and predict what an adversary might do. In this paper, we present an analogous approach to modeling cyber adversaries to gain a deeper understanding of the behavioral dynamics underlying cyber attacks and enable predictive analytics and proactive defensive planning. We present a hybrid modeling approach that combines aspects of cognitive modeling, decision-theory, and reactive planning to capture different facets of adversary decision making and behavior.
Social media for news consumption is a double-edged sword. On the one hand, its low cost, easy access, and rapid dissemination of information lead people to seek out and consume news from social media. On the other hand, it enables the wide spread of \fake news", i.e., low quality news with intentionally false information. The extensive spread of fake news has the potential for extremely negative impacts on individuals and society. Therefore, fake news detection on social media has recently become an emerging research that is attracting tremendous attention. Fake news detection on social media presents unique characteristics and challenges that make existing detection algorithms from traditional news media ine ective or not applicable. First, fake news is intentionally written to mislead readers to believe false information, which makes it difficult and nontrivial to detect based on news content; therefore, we need to include auxiliary information, such as user social engagements on social media, to help make a determination. Second, exploiting this auxiliary information is challenging in and of itself as users' social engagements with fake news produce data that is big, incomplete, unstructured, and noisy. Because the issue of fake news detection on social media is both challenging and relevant, we conducted this survey to further facilitate research on the problem. In this survey, we present a comprehensive review of detecting fake news on social media, including fake news characterizations on psychology and social theories, existing algorithms from a data mining perspective, evaluation metrics and representative datasets. We also discuss related research areas, open problems, and future research directions for fake news detection on social media.
There is a broad consensus that understanding causality is important for comprehending the world and making decisions. However, causality is notoriously difficult to understand and analyze, a challenge amplified in complex sociocultural systems. These challenges can be categorized as interactions among three critical areas of operationalizing causal analysis: Computational Formalisms, Mental Models, and Objective Truth. We provide a survey of causal research across these three key areas and identify existing gaps between objective truth, the way people understand and think about causality in mental models, and the modeling formalisms that have been developed to support representation and reasoning about causality. To bridge these gaps, we present a preliminary conceptual Meta-Causal Models framework to capture the semantic relationships between these three categories of causal analysis and identify the most effective combination of causal reasoning approaches to support decision-making requirements.
The Dual Node Decision Wheels (DNDW) architecture concept was previously described as a novel approach toward integrating analytic and decision-making processes in joint human/automation systems in highly complex sociotechnical settings. In this paper, we extend the DNDW construct with a description of components in this framework, combining structures of the Dual Node Network (DNN) for Information Fusion and Resource Management with extensions on Rasmussen's Decision Ladder (DL) to provide guidance on constructing information systems that better serve decision-making support requirements. The DNN takes a component-centered approach to system design, decomposing each asset in terms of data inputs and outputs according to their roles and interactions in a fusion network. However, to ensure relevancy to and organizational fitment within command and control (C2) processes, principles from cognitive systems engineering emphasize that system design must take a human-centered systems view, integrating information needs and decision making requirements to drive the architecture design and capabilities of network assets. In the current work, we present an approach for structuring and assessing DNDW systems that uses a unique hybrid DNN top-down system design with a human-centered process design, combining DNN node decomposition with artifacts from cognitive analysis (i.e., system abstraction decomposition models, decision ladders) to provide work domain and task-level insights at different levels in an example intelligence, surveillance, and reconnaissance (ISR) system setting. This DNDW structure will ensure not only that the information fusion technologies and processes are structured effectively, but that the resulting information products will align with the requirements of human decision makers and be adaptable to different work settings
The Dual Node Decision Wheels (DNDW) architecture is a new approach to information fusion and decision support systems. By combining cognitive systems engineering organizational analysis tools, such as decision trees, with the Dual Node Network (DNN) technical architecture for information fusion, the DNDW can align relevant data and information products with an organization’s decision-making processes. In this paper, we present the Compositional Inference and Machine Learning Environment (CIMLE), a prototype framework based on the principles of the DNDW architecture. CIMLE provides a flexible environment so heterogeneous data sources, messaging frameworks, and analytic processes can interoperate to provide the specific information required for situation understanding and decision making. It was designed to support the creation of modular, distributed solutions over large monolithic systems. With CIMLE, users can repurpose individual analytics to address evolving decision-making requirements or to adapt to new mission contexts; CIMLE’s modular design simplifies integration with new host operating environments. CIMLE’s configurable system design enables model developers to build analytical systems that closely align with organizational structures and processes and support the organization’s information needs.
Probabilistic programming provides the means to represent and reason about complex probabilistic models using programming language constructs. Even simple probabilistic programs can produce models with infinitely many variables. Factored inference algorithms are widely used for probabilistic graphical models, but cannot be applied to these programs because all the variables and factors have to be enumerated. In this paper, we present a new inference framework, lazy factored inference (LFI), that enables factored algorithms to be used for models with infinitely many variables. LFI expands the model to a bounded depth and uses the structure of the program to precisely quantify the effect of the unexpanded part of the model, producing lower and upper bounds to the probability of the query.
To better understand and describe the world around them, and ultimately produce theories that can facilitate better decision making or policy interventions, social scientists need to be able to create, analyze, and validate social, political, and economic models that include causal and predictive elements. Causality is, however, notoriously difficult to analyze. This is especially true in social science due to the complexity of the phenomena being studied. To address this complexity, we describe a suite of causal/predictive analysis techniques adapted from a variety of social, natural, and computational science applications, specifically chosen for their unique applicability to the problems of analyzing temporally offset causes and effects. In particular, we describe four methods for analyzing predictive/causal claims: (1) Granger causality is a well-established method from econometrics that can identify relationships between temporally offset causes and effects when the offsets are fixed; (2) forward-only dynamic time-warping (DTW) addresses uneven temporal offsets; (3) convergent cross mapping (CCM) can be used to analyze bi-directional causality produced by the feedback relationships present in many social systems; (4) finally, we describe a novel feature-based qualitative pattern-recognition approach to identify and explain qualitative causal/predictive relationships that don’t fit more traditional correlation-based analysis techniques. Social scientists can use this mix of analytic techniques to validate (or more-precisely, to invalidate) their causal/predictive hypotheses and produce more robust understandings of complex systems. We present prototype software implementations of these analytic techniques and demonstrate the efficacy of our proposed approaches.
As the modern information environment continues to expand with new technologies, military Command and Control (C2) has increasing access to unprecedented amounts of data and analytic resources to support military decision making However, with the increasing quantity and heterogeneity of multi-TNT data from new collection platforms, new sensors, and new analytic tools comes a growing information fusion challenge. For example, increasingly distributed processing, exploitation, and dissemination (PED) capabilities and analyst intelligence resources must identify and integrate the most relevant data sources to support and improve operational command and control and situation awareness without becoming overwhelmed by data and potentially missing critical information. We present an innovative new information fusion and organizational decision-making architecture Dual Node Decision Wheels (DNDW) that integrates multi-TNT PED, information analysis, and C2 processes through a novel combination of goal-directed information fusion and data-driven decision making, helping alleviate "big data" challenges through more fluid coordination of organizations and technologies. DNDW applies the dual node network for fusion and resource management with semantic links between organizational processes and decision aides, ensuring that each organizational role has access to the right information. DNDW can map fusion onto any organizational structure and provide a cost-effective solution methodology for integrating new technologies.
In this chapter, we formalize the notion of a state change attempt. The idea is that a state change attempt, when successfully applied to a given tuple, will change the action attributes with the hope that these changes will result in a change in the state. For instance, considering the school data described in the previous chapter, SCAs represent policies Policy designed with a certain goal in mind; we provide an example in which a change in the action variables that decreases class size may lead to better proficiency scores.
In this chapter we introduce several sorts of effect estimator, which yield the likelihood of a given action tuple satisfying a given goal condition G. An effect estimator essentially answers the question: “if I succeed in changing the environment in this way, what is the probability that the environment satisfies my goal?”. We also present the TOSCA algorithm, an optimized approach to computing State Change Attempt Trie-enhanced Optimal optimal state change attempts when using a special kind of effect estimator.
Massimiliano Albanese合作论文数George Mason University2