Species Perturbation
Perturbation
Add noise to data or outputs so an observer cannot learn the true values.
e.g.Differential privacy on released statistics
NYU Tandon · Game Theory for Deception
Attackers lie to get in; defenders lie to catch them. We use game theory to understand who knows what, what each side believes, and how to design deception that works, from honeypots to AI agents.
Primer · What is cyber deception?
Every cyber attack is a contest over information. Attackers hide malware, spoof identities and send phishing emails. Defenders can turn the same idea around: decoy servers, fake credentials and shifting network addresses make an attacker waste time, reveal their tools, or give up.
Deception works only if the other side believes it, and they are strategic too.
That is why we use game theory. A game lets us write down what each player knows, what they want, and how they update their beliefs when they see evidence. We can then ask the design questions that matter: How many decoys are enough? What if the attacker can partly detect them? When should a defender reveal, conceal, or commit?
A field guide
Our taxonomy groups defensive deception by the kind of information it manipulates and the game that models it. It gives researchers and practitioners a shared vocabulary.
Species Perturbation
Add noise to data or outputs so an observer cannot learn the true values.
e.g.Differential privacy on released statistics
Species MTD
Keep changing the system’s configuration so the attacker’s reconnaissance quickly goes stale.
e.g.Randomized IP addresses and ports
Species Obfuscation
Hide real signals among useless or misleading ones.
e.g.Dummy queries that mask a user’s location
Species Mixing
Exchange identities among many parties so no single one can be traced.
e.g.Mix networks for anonymous communication
Species Honey-X
Make fake systems or data look real to lure and study attackers.
e.g.Honeypots, honeytokens, honey-files
Species Engagement
Use feedback over time to keep an attacker busy and learn their goals.
e.g.Adaptive honeynets that observe advanced persistent threats
From J. Pawlick, E. Colbert & Q. Zhu, “A Game-theoretic Taxonomy and Survey of Defensive Deception for Cybersecurity and Privacy,” ACM Computing Surveys 52(4), 2019.
Interactive · Try it yourself
You defend a network of 100 hosts. Some are honeypots. An attacker scans one host and sees whether it looks real. Adjust your defense and watch the attacker’s belief and decision change.
A simplified version of the signaling games with evidence in Pawlick, Colbert & Zhu, IEEE TIFS 2019. The full model also lets the defender choose when to deceive and at what cost.
New to the field?
For students and practitioners: start short and free, then go deep.
A short, free introduction to game theory for cyber deception. Read it in an afternoon.
Read the tutorial →The six-species taxonomy and a map of the game models behind each species.
Read the survey →Nash and Stackelberg games, incomplete information, honeypots, and strategic trust in the IoT.
Open the book →Deception by and against AI: LLM agents, agentic workflows, and spear-phishing.
Read the overview →Books
Monographs and edited volumes that define the game-theoretic study of deception.
Featured monograph
Draws on a decade of deception research to build a game-theoretic taxonomy, then applies it to privacy in the Internet of Things, dynamic honeynets against advanced persistent threats, and active defense against physical denial-of-service attacks.
Foundations of Cyber DeceptionModeling, analysis, design, human factors, and how they fit together.
Cognitive SecurityA system-scientific approach to human attention, bias, and deception.
Game Theory and Machine Learning for Cyber SecurityIncludes chapters on manipulating reinforcement learning.
Autonomous Cyber ResilienceIncludes resilience against deceptive information attacks on transportation systems.
Research
Six research threads, each with a few papers to start from. The full list is on the Publications page.
How beliefs are formed and manipulated when one side holds private information and evidence can leak.
When to lure, how long to engage, and how to learn from an attacker without being found out.
Game-theoretic models of deception by and against language models and agentic AI workflows.
Human attention and bias are part of the attack surface. We design defenses that account for them.
Multi-stage attackers who stay hidden for months, and defenses that keep moving.
Deception that moves through the physical world: drones, vehicles, robots, and navigation systems.
Talks & events
Human-Aware AI Agents for the Cyber Battlefield
AAAI Summer Symposium, Seoul, organizing committee · Symposium site
Dynamic Games for Cyber Deception
Seminar, Oden Institute, UT Austin · Event page
Bayesian Persuasion and Cognitive Security
Midwest Workshop on Control and Game Theory, University of Minnesota · Talk page
AAAI-20 Workshop on AI for Cyber Security (AICS)
New York City
Tutorial: Game Theory for Cyber Deception
HoTSoS, Nashville · Tutorial paper
Open resources
Dataset · 2026GAMBiT red-team datasetsHuman-subjects cyber-range data for studying attacker cognitive bias. VideoConversations at the Forefront of CybersecurityNYU CCS interview with Quanyan Zhu. Essay · 2023The Doctrine of Cyber EffectAn ethics framework for defensive cyber deception.This site gathers research, tutorials and workshops on deception games. Send us your paper, course or event and we’ll add it.