A book · Springer, forthcoming

Cognitive Security

A Systems Science of Cognitive Defense and Resilience

Ya-Ting Yang (National Taiwan University) · Linan Huang (Tsinghua University) · Quanyan Zhu (New York University)

Attacks increasingly target what people and machines perceive, believe, and decide, rather than the systems they run on. A deepfake call authorizes a payment; a flood of alerts exhausts an analyst's attention; a false post spreads faster than a correction; an injected instruction redirects an AI agent. This book treats cognition as an engineered layer of a socio-technical system, with vulnerabilities that can be modeled, measured, and defended.

7parts
5levels, from individual to society
22chapters
156pages in the free sample
Cover of Cognitive Security by Ya-Ting Yang, Linan Huang and Quanyan Zhu
Beyond the weakest link

From data security to decision security

“The human is the weakest link” has too often served as a conclusion rather than the beginning of an analysis. These incidents share a structure: no firewall rule failed, and the decisive failure was a decision.

Deepfake payment fraud

A meeting of synthetic colleagues

A finance employee joins a video conference, sees and hears the chief financial officer, and executes a series of transfers. The colleagues were synthetic, and the firm stated its internal systems were not compromised.

Attention as a target

Alerts that exhaust the analyst

An informational denial-of-service attack floods a security operations center, so that real incidents cannot be triaged inside the deadline. Nothing is breached; the defender simply runs out of attention.

Injected instruction

An agent told what to believe

An AI assistant reads untrusted content that carries instructions for it. The manipulation enters through the model's input, not through its permissions.

A vulnerability that is attributed to people, and left there, cannot be engineered.

The running example

MERIDIAN, one winter night

A notional regional utility carries the models through the book, so that chapters can be compared in one setting. It is a teaching construct, not a real organization.

MERIDIAN · electricity and water for 2.0 million residents

A storm, a payment request, and a rumor

A storm cuts power to 310,000 customers. Within the hour the security operations center queue triples and the call center is saturated. A message that appears to come from the chief financial officer asks the finance office to expedite an emergency payment to a restoration contractor. At the same time, a post claiming the tap water is unsafe begins to circulate among the utility's 240,000 social media followers.

No firewall rule fails and no server is compromised. Whether MERIDIAN serves its customers well that night depends on what its analysts notice, what its finance staff believe, what its AI copilot recommends, and what the public trusts.

The frameworks

Where a cognitive attack lands

Every problem in the book has an address: a level of the Cognitive Security Stack, a stage of the cognitive loop, and a phase of resilience. Together they form the Cognitive Security Cube, which shows at a glance which cells your controls cover and which are empty.

Level × stage, with three incidents placed
LevelSenseModelDecideActLearn
L5 SocietyB
L4 OrganizationA
L3 Human–AI team
L2 AI agentC
L1 Individual

A: deepfake payment fraud, at the organization's Act stage. B: a false official post, at society's Model stage. C: an injected instruction, at the agent's Model stage. Each cell also carries a resilience phase.

The four phases of resilience

Anticipate · before onset Withstand · until detected Recover · until restored Adapt · a new level

What the frameworks buy you

  • A unit of analysis above the individual: manipulation propagates across people, teams, agents, organizations, and society.
  • A coverage map: placing controls in the Cube exposes cells with no control at all.
  • A measurable objective: decision quality Q(t) over time, rather than awareness or click rates alone.
  • A strategic adversary: attacker and defender act on predictions about each other, so defenses are designed against adaptation, not a fixed attack.
Interactive · Chapter 4, Definition 4.10

The resilience curve

A single measurement of decision quality describes a moment; security concerns trajectories. Drag the sliders to shape an incident at MERIDIAN's operations center and watch the resilience functional respond. Time to detect splits into time to alert, how fast the defender senses, and time to act, how fast it decides, so an alert raised quickly and acted on slowly shows up as a cognitive problem, not a sensor problem.

when the manipulation begins
the defender's Sense stage
the defender's Decide stage
worst loss of decision quality
until quality is restored
above 1 means the incident left the system better
–resilience R over 12 h
–depth δmax
–time to detect
–loss area Λ (hours)
Normalized decision quality through an incident
R(𝒜, π; w) = (1/T) ∫₀ᵀ Q(t)/Q₀ dt  ·  Λ = ∫₀ᵀ (1 − q(t)) dt  ·  TTD = td − ta

Piecewise-linear illustration of the book's definition over a 12-hour horizon, with a single manipulation. In the book, R is the worst case over a whole set of manipulations, which is what makes it a design criterion rather than a description of one incident.

The book

Seven parts

Twenty-two chapters and two appendices, about 810 pages. Each chapter can be read on its own and closes with worked examples, case studies, an ethics and limits section, exercises, and a computational lab with companion code. Part I is in the free sample, together with the preface, the notation, and the contents of the whole book.

IFoundationsin sample
  1. 1The Cognitive Domain as a Security Frontier
  2. 2Cognitive Systems and Assets: Humans, Machines, Teams, and Institutions
  3. 3Cognitive Vulnerabilities, Threats, and the Cognitive Attack Chain
  4. 4Cognitive Security Objectives, Risk, and Resilience Metrics
IIModels and Defense Engineering
  1. 5System-Theoretic Models of Cognition
  2. 6Games, Bounded Rationality, and Information Design
  3. 7Cognitive Defense Engineering: Mechanisms, Controls, and Risk Management
IIIDefending Individual Cognition
  1. 8Social Engineering, Phishing, and Cognitive Fraud
  2. 9Defending Against Inattention and Vigilance Attacks
  3. 10Defending Against Attentional Denial-of-Service Attacks
  4. 11Cognitive Resilience: Inoculation, Metacognition, and Recovery
IVDefending Organizational and Societal Cognition
  1. 12Insider Threats and Organizational Decision Integrity Through Mechanism Design
  2. 13Misinformation, Disinformation, and Platform Manipulation
  3. 14Information Operations and Cognitive Warfare
VCognitive Mechanisms for Defensive Advantage
  1. 15Cognitive Triggers, Indicators, and Sensors
  2. 16Cognitive-Aware Cyber Deception
VIArtificial and Hybrid Cognition
  1. 17AI-Enabled Cognitive Attacks and Deception
  2. 18Cognitive Vulnerabilities of AI and Agentic Systems
  3. 19Bilateral Human-AI Cognitive Security
  4. 20Cognitive-Cyber-Physical Security: Humans and AI in the Control Loop
VIIIntegration, Governance, and Frontiers
  1. 21Evaluation, Red Teaming, Cognitive Digital Twins, and Case Studies
  2. 22Ethics, Law, Governance, and Research Frontiers
A·BAppendices
  1. AFrameworks, Standards, and Glossary
  2. BTest Case Scenarios and Agentic AI Benchmarks

The quantitative toolkit

  • Bayesian inference and detection under low base rates
  • Choice models and bounded rationality
  • Markov and partially observable models
  • Game theory and information design
  • Mechanism design
  • Queueing for attention
  • Network diffusion
  • Control
  • Experimental and causal methods

Reading paths

Courses on cognitive security, human factors and security operations, AI security and human–AI teaming, game theory and deception, security studies, and professional training.

Ethics and limits

Every chapter states them. Questions of autonomy, privacy, and legitimate influence are treated as seriously as the technical ones.

Computational labs

Companion code per chapter, with test scenarios and benchmarks in Appendix B.

For whom

Researchers from psychology, computer science, engineering, and the social sciences, and practitioners in industry and government entering the field.

Related research

The work behind the book

The book grew out of a decade of research on modeling human vulnerabilities as system components, beginning with Linan Huang's doctoral work at NYU on attention and alert management.

  • Cognitive Security: A System Science Approach
    L. Huang and Q. Zhu · SpringerBriefs, 2023 · DOI — the seed from which this book grew
  • ADVERT: An Adaptive and Data-Driven Attention Enhancement Mechanism for Phishing Prevention
    L. Huang, S. Jia, E. Balcetis, and Q. Zhu · IEEE Transactions on Information Forensics and Security, 2022 · DOI
  • RADAMS: Resilient and Adaptive Alert and Attention Management Strategy against Informational Denial-of-Service Attacks
    L. Huang and Q. Zhu · Computers & Security, 2022 · DOI
  • Combating Informational Denial-of-Service (IDoS) Attacks: Modeling and Mitigation of Attentional Human Vulnerability
    L. Huang and Q. Zhu · GameSec 2021, Best Student Paper · DOI
  • Guarding Against Malicious Biased Threats (GAMBiT): Experimental Design of Cognitive Sensors and Triggers with Behavioral Impact Analysis
    B. Beltz, P.-Y. Chen, …, Y.-T. Yang, and Q. Zhu · Computational Brain & Behavior, 2026
  • GAMBiT datasets: Revealing Cognitive Bias in Human-Subjects Red-Team Cyber Range Operations
    B. Beltz et al. · Data in Brief, 2026 · DOI
  • Transparent Tagging for Strategic Social Nudges on User-Generated Misinformation
    Y.-T. Yang, T. Li, and Q. Zhu · IEEE Transactions on Network Science and Engineering, 2025 · DOI
  • Stuck on a Phishing Lure: Differential Use of Base Rates in Self and Social Judgments of Susceptibility to Cyber Risk
    E. Cox, Q. Zhu, and E. Balcetis · Comprehensive Results in Social Psychology, 2020
  • Bi-Level Game-Theoretic Planning of Cyber Deception for Cognitive Arbitrage
    Y.-T. Yang and Q. Zhu · arXiv:2509.05498, 2025
  • LLM-Stackelberg Games: Conjectural Reasoning Equilibria and Their Applications to Spearphishing
    Q. Zhu · arXiv:2507.09407, 2025