NYU Tandon · Game Theory for Deception

Deception isa strategy.We model it as a game.

Attackers lie to get in; defenders lie to catch them. We use game theory to understand who knows what, what each side believes, and how to design deception that works, from honeypots to AI agents.

5 books & edited volumes 6 species of defensive deception 2017 – 2026 of published research

Primer · What is cyber deception?

Winning with information the other side doesn’t have

Every cyber attack is a contest over information. Attackers hide malware, spoof identities and send phishing emails. Defenders can turn the same idea around: decoy servers, fake credentials and shifting network addresses make an attacker waste time, reveal their tools, or give up.

Deception works only if the other side believes it, and they are strategic too.

That is why we use game theory. A game lets us write down what each player knows, what they want, and how they update their beliefs when they see evidence. We can then ask the design questions that matter: How many decoys are enough? What if the attacker can partly detect them? When should a defender reveal, conceal, or commit?

A field guide

Six species of defensive deception

Our taxonomy groups defensive deception by the kind of information it manipulates and the game that models it. It gives researchers and practitioners a shared vocabulary.

Species Perturbation

Perturbation

Add noise to data or outputs so an observer cannot learn the true values.

e.g.Differential privacy on released statistics

Species MTD

Moving target defense

Keep changing the system’s configuration so the attacker’s reconnaissance quickly goes stale.

e.g.Randomized IP addresses and ports

Species Obfuscation

Obfuscation

Hide real signals among useless or misleading ones.

e.g.Dummy queries that mask a user’s location

Species Mixing

Mixing

Exchange identities among many parties so no single one can be traced.

e.g.Mix networks for anonymous communication

Species Honey-X

Honey-X

Make fake systems or data look real to lure and study attackers.

e.g.Honeypots, honeytokens, honey-files

Species Engagement

Attacker engagement

Use feedback over time to keep an attacker busy and learn their goals.

e.g.Adaptive honeynets that observe advanced persistent threats

From J. Pawlick, E. Colbert & Q. Zhu, “A Game-theoretic Taxonomy and Survey of Defensive Deception for Cybersecurity and Privacy,” ACM Computing Surveys 52(4), 2019.

Interactive · Try it yourself

The leaky honeypot game

You defend a network of 100 hosts. Some are honeypots. An attacker scans one host and sees whether it looks real. Adjust your defense and watch the attacker’s belief and decision change.

The fraction of hosts that are decoys. Decoys cost money to run.
How often the attacker’s scan correctly spots a honeypot as fake. Better decoys leak less.
Gain from hitting a real host versus the loss from being caught in a honeypot.
Real host Honeypot that looks real Honeypot the scan exposes
Attacker’s belief · μ—P(honeypot | looks real)
Expected attack value—(1−μ)·gain − μ·loss

A simplified version of the signaling games with evidence in Pawlick, Colbert & Zhu, IEEE TIFS 2019. The full model also lets the defender choose when to deceive and at what cost.

New to the field?

A four-step reading path

For students and practitioners: start short and free, then go deep.

The tutorial

A short, free introduction to game theory for cyber deception. Read it in an afternoon.

HoTSoS 2019 · arXivRead the tutorial →

The survey

The six-species taxonomy and a map of the game models behind each species.

ACM Computing Surveys 2019Read the survey →

The textbook

Nash and Stackelberg games, incomplete information, honeypots, and strategic trust in the IoT.

Birkhäuser 2021Open the book →

The frontier

Deception by and against AI: LLM agents, agentic workflows, and spear-phishing.

GameSec 2025 · arXiv 2025Read the overview →

Books

The bookshelf

Monographs and edited volumes that define the game-theoretic study of deception.

Birkhäuser · 2021 Game Theory for Cyber Deception Jeffrey Pawlick
Quanyan Zhu

Featured monograph

Game Theory for Cyber Deception: From Theory to Applications

Draws on a decade of deception research to build a game-theoretic taxonomy, then applies it to privacy in the Internet of Things, dynamic honeynets against advanced persistent threats, and active defense against physical denial-of-service attacks.

  • For security practitioners who want to learn game theory
  • For game theorists moving into cybersecurity
  • Covers signaling, Stackelberg, and large-population games

Research

What we work on

Six research threads, each with a few papers to start from. The full list is on the Publications page.

Talks & events

Where we’ve presented

  1. Human-Aware AI Agents for the Cyber Battlefield

    AAAI Summer Symposium, Seoul, organizing committee · Symposium site

  2. Dynamic Games for Cyber Deception

    Seminar, Oden Institute, UT Austin · Event page

  3. Bayesian Persuasion and Cognitive Security

    Midwest Workshop on Control and Game Theory, University of Minnesota · Talk page

  4. AAAI-20 Workshop on AI for Cyber Security (AICS)

    New York City

  5. Tutorial: Game Theory for Cyber Deception

    HoTSoS, Nashville · Tutorial paper

All talks, workshops and tutorials →

Is your work missing?

This site gathers research, tutorials and workshops on deception games. Send us your paper, course or event and we’ll add it.

Submit your work