Accelerating Autonomous Cyber Operations: A Symbolic Logic Planner Guided Reinforcement Learning Approach

Ryan Kerr, Steven H. H. Ding, Li Li, Adrian Taylor · 2024

Training a reinforcement learning agent to learn network penetration testing is challenging due to the partially-observable, non-deterministic environment. The large action space leads to extended training time, an issue of particular concern in mission-oriented network deployment that requires timely hardening tests. Current solutions for automating penetration testing are divided between reinforcement learning (RL) and AI planning. This work integrates the two paradigms and establishes a neuro-symbolic agent training system through an interactive symbolic logic engine. Two methods are examined for accelerating the pentest agent training in this system, namely: invalid action masking for Deep Q-Networks and using a symbolic logic engine as an environment driver. The results show that invalid action masking is highly effective at reducing the number of steps to convergence, while the logic-based simulator provides a significant per-step performance improvement to speed up training. These results highlight that a hybrid neuro-symbolic approach is a viable, and perhaps even necessary, method for developing and improving cyber RL agents.

Read the paper · More papers on PaperTik