ExploitFlow, cyber security exploitation routes for Game Theory and AI research in robotics
V\'ictor Mayoral-Vilches, Gelei Deng, Yi Liu, Martin Pinzger and, Stefan Rass

TL;DR
ExploitFlow is a modular AI and Game Theory-driven library designed to automate cyber security exploits, enabling advanced research in robotics and AI security with promising results from reinforcement learning agents.
Contribution
Introduction of ExploitFlow, a novel modular library that automates cyber exploits and facilitates AI and Game Theory research in cybersecurity and robotics.
Findings
EF effectively explores machine learning in robot cybersecurity.
Reinforcement Learning agents using EF outperform brute-force and human experts.
Identified limitations include overfitting and dataset scarcity.
Abstract
This paper addresses the prevalent lack of tools to facilitate and empower Game Theory and Artificial Intelligence (AI) research in cybersecurity. The primary contribution is the introduction of ExploitFlow (EF), an AI and Game Theory-driven modular library designed for cyber security exploitation. EF aims to automate attacks, combining exploits from various sources, and capturing system states post-action to reason about them and understand potential attack trees. The motivation behind EF is to bolster Game Theory and AI research in cybersecurity, with robotics as the initial focus. Results indicate that EF is effective for exploring machine learning in robot cybersecurity. An artificial agent powered by EF, using Reinforcement Learning, outperformed both brute-force and human expert approaches, laying the path for using ExploitFlow for further research. Nonetheless, we identified…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Advanced Malware Detection Techniques
