Distilling Knowledge from Large Language Models into Lightweight Reinforcement Learning Agents for Autonomous Cyber Operations
This study addresses the challenges faced by reinforcement learning (RL) agents in early-stage autonomous cyber defense, including high exploration costs, weak decision-making capabilities, and behavioral instability. To overcome these limitations, the work proposes an online policy distillation framework that leverages a prompt-engineered large language model (LLM) specialized in cybersecurity as a teacher policy. The framework efficiently transfers knowledge from the LLM to a lightweight RL agent containing only 64,910 parameters. Evaluated in multi-scale CybORG network environments with 4 to 12 hosts, the distilled agent closely replicates the teacher’s performance and significantly outperforms baseline RL methods. Despite a five-order-of-magnitude reduction in parameter count, the agent maintains robust defensive capabilities, demonstrating the feasibility of deploying state-of-the-art security models in resource-constrained settings.