Network- and Device-Level Cyber Deception for Contested Environments Using RL and LLMs
This work proposes a novel framework that integrates large language models (LLMs) with reinforcement learning (RL) to generate adaptive, intelligent deception strategies at both network and device levels—an approach not previously achieved. Addressing the limitations of traditional deception techniques, which are often costly, static, and reliant on manual intervention, the proposed method leverages containerization and operational technology (OT) security architectures to autonomously optimize and dynamically deploy deception mechanisms within simulated adversarial environments. Experimental results demonstrate that the framework significantly enhances defensive capabilities against stealthy attacks by improving deception efficacy while substantially reducing operational costs. The approach achieves high detection accuracy and superior cost-effectiveness, offering a scalable and intelligent solution for modern cyber defense.