Related Experiment Videos
Alert-Driven Active Defense for IoT-Enabled CBTC Systems Using Bayesian Hypergame Modeling and Hierarchical
Junyi Zhao1, Qichang Li1, Zhiwei Cao2
1Signal and Communication Research Institute, China Academy of Railway Sciences Corporation Limited, Beijing 100081, China.
Sensors (Basel, Switzerland)
|July 28, 2026
Summary
This study introduces an active defense framework for Communication-Based Train Control (CBTC) systems, enhancing cybersecurity against advanced persistent threats (APTs) with improved defense success and resource efficiency.
Area of Science:
- Cybersecurity
- Railway Engineering
- Artificial Intelligence
Background:
- Advanced Persistent Threats (APTs) increasingly target Internet of Things (IoT) systems.
- Communication-Based Train Control (CBTC) systems, vital for railway infrastructure, are now interconnected cyber-physical networks vulnerable to cyber-attacks.
- Existing defenses struggle against the stealth and adaptability of APTs in critical infrastructure.
Purpose of the Study:
- To propose an alert-driven active defense framework for CBTC systems against APTs.
- To integrate Bayesian belief updating, hypergame-based cognitive-bias modeling, and Hierarchical Reinforcement Learning (HRL) for enhanced defense.
- To improve the cost-effectiveness and success rate of cyber defenses in railway signaling.
Main Methods:
- Developed a framework converting intrusion detection system (IDS) alerts and network/cyber-physical observations into actionable defense inputs.
- Employed Bayesian belief updating for attacker profiling and hypergame modeling for cognitive bias simulation.
- Utilized Hierarchical Reinforcement Learning (HRL) to decouple strategic defense posture from tactical execution.
Main Results:
- The proposed framework achieved an 87.1% defense success rate against APT attacks in simulated CBTC environments.
- The defense strategy consumed only 62.7% of normalized defense resources, outperforming standard algorithms like DQN, PG, and PPO.
- Demonstrated superior performance compared to existing methods under identical test conditions.
Conclusions:
- Explicitly coupling cyber observations, CBTC operational constraints, and deception-aware policies significantly enhances cost-aware active defense.
- The integrated framework offers a robust solution for protecting critical railway signaling infrastructures from sophisticated cyber threats.
- The findings highlight the potential of AI-driven cognitive modeling for advanced cybersecurity in industrial control systems.
Related Concept Videos
Observational Learning
Albert Bandura's observational learning, also known as imitation or modeling, occurs when a person observes and imitates another's behavior. It is a quicker process than operant conditioning. A well-known example is the Bobo doll study, where children who saw an adult acting aggressively towards the doll were more likely to act aggressively when left alone, compared to those who observed a nonaggressive adult. Many psychologists view observational learning as a form of latent learning because...
Avoidance Learning and Learned Helplessness
Avoidance learning and learned helplessness are critical concepts in understanding behavioral responses to negative stimuli.
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
Avoidance learning occurs when an organism learns that a specific behavior can prevent an unpleasant outcome. For example, a student who receives a bad grade may start studying harder to avoid future poor grades. This behavior persists even when the negative outcome is no longer present. Avoidance learning is powerful because it maintains behavior in the absence of the...
Cognitive Learning
Cognitive learning is based on purposive behavior, incidental learning, and insight learning.
E. C. Tolman's theory of purposive behavior emphasizes that much behavior is goal-directed. He argued that to understand behavior, we must look at the entire sequence of actions leading to a goal. For instance, high school students study hard, not just due to past reinforcement but also to achieve the goal of getting into a good college.
Tolman introduced the idea that behavior is influenced by...
E. C. Tolman's theory of purposive behavior emphasizes that much behavior is goal-directed. He argued that to understand behavior, we must look at the entire sequence of actions leading to a goal. For instance, high school students study hard, not just due to past reinforcement but also to achieve the goal of getting into a good college.
Tolman introduced the idea that behavior is influenced by...
Automatic Processing and Automatic Social Behavior
Automatic processing refers to the cognitive operations that occur without conscious intent or awareness, playing a fundamental role in shaping social cognition and behavior. These processes enable individuals to navigate complex social environments efficiently by relying on mental shortcuts and pre-existing knowledge structures known as schemas. One of the most influential mechanisms underlying automatic processing is priming, which subtly activates mental representations through exposure to...