PaperScope
LIVE · 2026-09-10 05:40 UTC

Learning Intrusion Response Strategies for OT Systems

Duc Huy Le, Rolf Stadler

Latestcs.CLcs.LGcs.AIcs.CV
arXiv ID
2609.10298 v1
Category
Submitted
2026-09-09

Abstract

Cyberattacks against Operational Technology (OT) systems, which monitor and control industrial processes, pose an increasing threat to essential societal services. For this reason, developing automated intrusion response strategies is highly important. In this paper, we present a formal model of an OT intrusion response use case using the POMDP framework. It includes a realistic model of partial observability that is based on traffic measurements. This approach allows us to develop tractable, learning-based solution methods for automated intrusion response, which are based on PPO. We evaluate the obtained response strategies on an emulated OT system and find that they are effective against several types of MITRE attacks for the studied use case.

Comment: A version of this paper has been published at the 22nd International Conference on Network and Service Management (CNSM2026)

arXiv abs page · PDF · same-day batch