From data security to decision security
“The human is the weakest link” has too often served as a conclusion rather than the beginning of an analysis. These incidents share a structure: no firewall rule failed, and the decisive failure was a decision.
A meeting of synthetic colleagues
A finance employee joins a video conference, sees and hears the chief financial officer, and executes a series of transfers. The colleagues were synthetic, and the firm stated its internal systems were not compromised.
Alerts that exhaust the analyst
An informational denial-of-service attack floods a security operations center, so that real incidents cannot be triaged inside the deadline. Nothing is breached; the defender simply runs out of attention.
An agent told what to believe
An AI assistant reads untrusted content that carries instructions for it. The manipulation enters through the model's input, not through its permissions.
A vulnerability that is attributed to people, and left there, cannot be engineered.
MERIDIAN, one winter night
A notional regional utility carries the models through the book, so that chapters can be compared in one setting. It is a teaching construct, not a real organization.
A storm, a payment request, and a rumor
A storm cuts power to 310,000 customers. Within the hour the security operations center queue triples and the call center is saturated. A message that appears to come from the chief financial officer asks the finance office to expedite an emergency payment to a restoration contractor. At the same time, a post claiming the tap water is unsafe begins to circulate among the utility's 240,000 social media followers.
No firewall rule fails and no server is compromised. Whether MERIDIAN serves its customers well that night depends on what its analysts notice, what its finance staff believe, what its AI copilot recommends, and what the public trusts.
Where a cognitive attack lands
Every problem in the book has an address: a level of the Cognitive Security Stack, a stage of the cognitive loop, and a phase of resilience. Together they form the Cognitive Security Cube, which shows at a glance which cells your controls cover and which are empty.
| Level | Sense | Model | Decide | Act | Learn |
|---|---|---|---|---|---|
| L5 Society | B | ||||
| L4 Organization | A | ||||
| L3 Human–AI team | |||||
| L2 AI agent | C | ||||
| L1 Individual |
A: deepfake payment fraud, at the organization's Act stage. B: a false official post, at society's Model stage. C: an injected instruction, at the agent's Model stage. Each cell also carries a resilience phase.
The four phases of resilience
What the frameworks buy you
- A unit of analysis above the individual: manipulation propagates across people, teams, agents, organizations, and society.
- A coverage map: placing controls in the Cube exposes cells with no control at all.
- A measurable objective: decision quality Q(t) over time, rather than awareness or click rates alone.
- A strategic adversary: attacker and defender act on predictions about each other, so defenses are designed against adaptation, not a fixed attack.
The resilience curve
A single measurement of decision quality describes a moment; security concerns trajectories. Drag the sliders to shape an incident at MERIDIAN's operations center and watch the resilience functional respond. Time to detect splits into time to alert, how fast the defender senses, and time to act, how fast it decides, so an alert raised quickly and acted on slowly shows up as a cognitive problem, not a sensor problem.
Piecewise-linear illustration of the book's definition over a 12-hour horizon, with a single manipulation. In the book, R is the worst case over a whole set of manipulations, which is what makes it a design criterion rather than a description of one incident.
Seven parts
Twenty-two chapters and two appendices, about 810 pages. Each chapter can be read on its own and closes with worked examples, case studies, an ethics and limits section, exercises, and a computational lab with companion code. Part I is in the free sample, together with the preface, the notation, and the contents of the whole book.
IFoundationsin sample
- 1The Cognitive Domain as a Security Frontier
- 2Cognitive Systems and Assets: Humans, Machines, Teams, and Institutions
- 3Cognitive Vulnerabilities, Threats, and the Cognitive Attack Chain
- 4Cognitive Security Objectives, Risk, and Resilience Metrics
IIModels and Defense Engineering
- 5System-Theoretic Models of Cognition
- 6Games, Bounded Rationality, and Information Design
- 7Cognitive Defense Engineering: Mechanisms, Controls, and Risk Management
IIIDefending Individual Cognition
- 8Social Engineering, Phishing, and Cognitive Fraud
- 9Defending Against Inattention and Vigilance Attacks
- 10Defending Against Attentional Denial-of-Service Attacks
- 11Cognitive Resilience: Inoculation, Metacognition, and Recovery
IVDefending Organizational and Societal Cognition
- 12Insider Threats and Organizational Decision Integrity Through Mechanism Design
- 13Misinformation, Disinformation, and Platform Manipulation
- 14Information Operations and Cognitive Warfare
VCognitive Mechanisms for Defensive Advantage
- 15Cognitive Triggers, Indicators, and Sensors
- 16Cognitive-Aware Cyber Deception
VIArtificial and Hybrid Cognition
- 17AI-Enabled Cognitive Attacks and Deception
- 18Cognitive Vulnerabilities of AI and Agentic Systems
- 19Bilateral Human-AI Cognitive Security
- 20Cognitive-Cyber-Physical Security: Humans and AI in the Control Loop
VIIIntegration, Governance, and Frontiers
- 21Evaluation, Red Teaming, Cognitive Digital Twins, and Case Studies
- 22Ethics, Law, Governance, and Research Frontiers
A·BAppendices
- AFrameworks, Standards, and Glossary
- BTest Case Scenarios and Agentic AI Benchmarks
The quantitative toolkit
Reading paths
Courses on cognitive security, human factors and security operations, AI security and human–AI teaming, game theory and deception, security studies, and professional training.
Ethics and limits
Every chapter states them. Questions of autonomy, privacy, and legitimate influence are treated as seriously as the technical ones.
Computational labs
Companion code per chapter, with test scenarios and benchmarks in Appendix B.
For whom
Researchers from psychology, computer science, engineering, and the social sciences, and practitioners in industry and government entering the field.
The work behind the book
The book grew out of a decade of research on modeling human vulnerabilities as system components, beginning with Linan Huang's doctoral work at NYU on attention and alert management.
- Cognitive Security: A System Science ApproachL. Huang and Q. Zhu · SpringerBriefs, 2023 · DOI — the seed from which this book grew
- ADVERT: An Adaptive and Data-Driven Attention Enhancement Mechanism for Phishing PreventionL. Huang, S. Jia, E. Balcetis, and Q. Zhu · IEEE Transactions on Information Forensics and Security, 2022 · DOI
- RADAMS: Resilient and Adaptive Alert and Attention Management Strategy against Informational Denial-of-Service AttacksL. Huang and Q. Zhu · Computers & Security, 2022 · DOI
- Combating Informational Denial-of-Service (IDoS) Attacks: Modeling and Mitigation of Attentional Human VulnerabilityL. Huang and Q. Zhu · GameSec 2021, Best Student Paper · DOI
- Guarding Against Malicious Biased Threats (GAMBiT): Experimental Design of Cognitive Sensors and Triggers with Behavioral Impact AnalysisB. Beltz, P.-Y. Chen, …, Y.-T. Yang, and Q. Zhu · Computational Brain & Behavior, 2026
- GAMBiT datasets: Revealing Cognitive Bias in Human-Subjects Red-Team Cyber Range OperationsB. Beltz et al. · Data in Brief, 2026 · DOI
- Transparent Tagging for Strategic Social Nudges on User-Generated MisinformationY.-T. Yang, T. Li, and Q. Zhu · IEEE Transactions on Network Science and Engineering, 2025 · DOI
- Stuck on a Phishing Lure: Differential Use of Base Rates in Self and Social Judgments of Susceptibility to Cyber RiskE. Cox, Q. Zhu, and E. Balcetis · Comprehensive Results in Social Psychology, 2020
- Bi-Level Game-Theoretic Planning of Cyber Deception for Cognitive ArbitrageY.-T. Yang and Q. Zhu · arXiv:2509.05498, 2025
- LLM-Stackelberg Games: Conjectural Reasoning Equilibria and Their Applications to SpearphishingQ. Zhu · arXiv:2507.09407, 2025
