Aug 2026· Computer Networks· Vol 288, pp. 112668· 0 citations· 49 references
TL;DR
A multi-agent reinforcement learning (MARL) framework that utilises software-defined networking (SDN) to achieve near real-time mitigation of DoS attacks targeting ICS networks, and exploits the scalability benefits of hierarchical learning to provide more granular agent decision making through a composite action space.
Abstract
The increasing frequency of cyber-attacks targeting industrial control systems (ICS) demonstrates the importance of digital resilience for Critical National Infrastructures. Denial of service (DoS) attacks have been shown to be highly effective against ICS environments due to the resource-constrained nature of industrial components and networks, such as programmable logic controllers (PLCs). Reinforcement learning (RL) can be used to address this challenge by dynamically managing and mitigating attack effects through statistical monitoring of underlying system behaviours, rather than using pre-trained data models commonly used in supervised and unsupervised machine learning approaches. In this paper, we propose a multi-agent reinforcement learning (MARL) framework that utilises software-defined networking (SDN) to achieve near real-time mitigation of DoS attacks targeting ICS networks. Specifically, we formulate network states using measurements extracted from industrial network communication protocols such as EtherNet/IP. Moreover, we exploit the scalability benefits of hierarchical learning to provide more granular agent decision making through a composite action space. We integrate an SDN controller with a virtualised OpenFlow switch to monitor network performance measurements such as average packet inter-arrival time to establish state behaviours. Through an emulated ICS network representing a live system, we mitigate the effects of different variants of DoS attacks with differing intensities, and highlight the performance improvements of using MARL compared to a single-agent framework. Our results show that MARL provides DoS recovery rates up to 83% faster than standard single-agent implementations, and improves network recovery rates compared with existing research.
T tiger, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyber-defence life-cycles is presented.
Jesús F. Cevallos-Moreno, A. Rizzardi, S. Sicari et al.· IEEE Transactions on Network...· 1 citation
Connected and automated vehicles (CAVs) are introduced to enhance the safety, efficiency, and mobility of transportation systems by leveraging advanced onboard sensors and wireless communication technologies. Cooperative adaptive cruise control (CACC), a fundamental application of CAVs, enhances adaptive cruise control...
This study provides among the first empirical evaluations of adversarial fragility in cooperative MARL-based intrusion detection within distributed 5G-oriented security abstractions, demonstrating that cooperative intelligence alone does not guarantee adversarial robustness.
B. Ndlovu, Kudzaishe Lawal Chizengwe· Scientific Journal of Inform...· 0 citations
The unique ability to combine distributed renewable energy sources and enhance system reliability, resilience, and system flexibility has made microgrids a key component of modern power system. But the existing time-triggered control approaches involve periodic communication between the distributed controllers irrespec...
Ravindra Prathap Singh, N. Nagabhooshanam, Yogendra Thakur et al.· Journal of Circuits, Systems...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.