Skip to content
AI Atlas
PaperActive

Learning Intrusion Response Strategies for OT Systems

arxiv.org/abs/2609.10298

Updated 51 min ago · first seen 11 Sept 2026

paper_01M294GNE4H20KV50EFNX8T4Q5

Published
11 Sept 2026
T1 · 51 min ago
arXiv
2609.10298
T1 · 51 min ago
Category
cs.CR
T1 · 51 min ago

Abstract

Cyberattacks against Operational Technology (OT) systems, which monitor and control industrial processes, pose an increasing threat to essential societal services. For this reason, developing automated intrusion response strategies is highly important. In this paper, we present a formal model of an OT intrusion response use case using the POMDP framework. It includes a realistic model of partial observability that is based on traffic measurements. This approach allows us to develop tractable, learning-based solution methods for automated intrusion response, which are based on PPO. We evaluate the obtained response strategies on an emulated OT system and find that they are effective against several types of MITRE attacks for the studied use case.

Authors 2

Duc Huy Le, Rolf Stadler

Specification

Official page

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

Arxiv announce type
cross

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

arXiv id
2609.10298

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

Categories
cs.CR, cs.AI

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

PDF

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

Primary category
cs.CR

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

Published
11 Sept 2026

Source:arXiv (Atom API + RSS)T1observed 51 min agohigh

Each value shows its source, tier and observation time. Conflicting claims are kept side by side and flagged — never averaged. How AI Atlas records facts →

Provenance

Attributed facts

9

Source tiers

T19

Freshest observation

51 min ago

Conflicts

None