Skip to content
Open access

Strategic allocation and dynamic rescue for multi-defender stackelberg security games with infectious attacks

Aug 2026 · Journal of King Saud University: Computer and Information Sciences · Vol 38 · 0 citations · 51 references

Abstract

Interconnected systems can suffer infectious attacks, where the compromise of one node exposes neighboring nodes and may trigger cascading loss. Existing Stackelberg and network-defense models usually address only part of this setting: a centralized defender, independent targets, or no post-attack resource transfer. This paper studies an observable pure-strategy setting in which multiple heterogeneous defenders independently allocate limited resources before an attacker selects a target. A publicly announced response rule fixed before deployment then reallocates transferable surplus after the target is observed. We formulate the resulting allocation game by backward induction: rescue is target-contingent for every allocation–target pair, the attacker anticipates that response when choosing a target, and defenders anticipate both continuation stages when choosing their allocations. We give a necessary-and-sufficient equilibrium characterization and sufficient conditions for pure-strategy existence, and use a centralized MILP only as an aggregate minimax benchmark. The optimal rescue problem is NP-hard even with fixed initial allocation and target. We therefore propose a two-stage heuristic aimed at the (ϵ,ξ)\documentclass[12pt]{minimal} \usepackage{amsmath} \usepackage{wasysym} \usepackage{amsfonts} \usepackage{amssymb} \usepackage{amsbsy} \usepackage{mathrsfs} \usepackage{upgreek} \setlength{\oddsidemargin}{-69pt} \begin{document}$$(\epsilon ,\xi )$$\end{document}-SNE conditions: equilibrium-guided initial allocation followed by feasible node-level greedy rescue. Experiments on three simulated and three real-world networks show lower aggregate loss than the tested baselines on all six datasets, at the cost of additional runtime. On the tested power-law instances, the method remains close to the centralized MILP lower-bound benchmark.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.