BASCPS: How does behavioral decision making impact the security of cyber-physical systems?
Mustafa Abdallah, Daniel Woods, Parinaz Naghizadeh, Issa Khalil,, Timothy Cason, Shreyas Sundaram, and Saurabh Bagchi

TL;DR
This paper investigates how human-like behavioral biases in decision making affect the security of interconnected cyber-physical systems, revealing that such biases lead to suboptimal resource allocation and increased security risks.
Contribution
It introduces behavioral security games modeling human decision biases, supported by empirical experiments, and analyzes their impact on security outcomes in real-world CPS scenarios.
Findings
Behavioral decision making causes suboptimal security resource allocation.
Interdependency among subsystems amplifies the negative effects of behavioral biases.
Selfish and biased decisions significantly increase security risks.
Abstract
We study the security of large-scale cyber-physical systems (CPS) consisting of multiple interdependent subsystems, each managed by a different defender. Defenders invest their security budgets with the goal of thwarting the spread of cyber attacks to their critical assets. We model the security investment decisions made by the defenders as a security game. While prior work has used security games to analyze such scenarios, we propose behavioral security games, in which defenders exhibit characteristics of human decision making that have been identified in behavioral economics as representing typical human cognitive biases. This is important as many of the critical security decisions in our target class of systems are made by humans. We provide empirical evidence for our behavioral model through a controlled subject experiment. We then show that behavioral decision making leads to a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Infrastructure Resilience and Vulnerability Analysis
