Automated tactics planning for cyber attack and defense based on large language model agents.

Ren, Yimo; Wang, Jinfa; Zhao, Zhihui; Wen, Hui; Li, Hong; Zhu, Hongsong · Neural Netw · 2025

basic_science · Level V

Where this comes from

Abstract

In recent years, the complexity and frequency of cyber incidents have escalated, necessitating more advanced and automated solutions for all attackers and defenders in cybersecurity, while traditional methods cannot provide timely and effective tactics planning for attackers and defenders. At this situation, this paper explores the abilities of Large Language Models (LLMs) from the Reinforcement Learning (RL) perspective to achieve automated tactics planning for cyber attack and defense. By leveraging the natural language understanding and generation capabilities of popular LLMs, this paper aims to formulate and develop more complex tactics for the specific network. This paper constructs a publicly available simulation environment of cyber attack and defense, and proposes tactic agents based on LLMs used from the RL perspective. Then, this paper conducts nearly a thousand experiments on the constructed environment. Experimental results verify that the proposed tactic agents could significantly improve the effectiveness and adaptability of automated tactics planning for cyber attack and defense, offering a promising direction for future research in cybersecurity.

Medical subject headings