Skip to content
Open access

TIGER: An Open-Source Cyber-Threat Intelligence Game Environment for Reinforcement Learning

2026 · IEEE Transactions on Network and Service Management · Vol 23, pp. 7553-7575 · 1 citation · 84 references

TL;DR

T tiger, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyber-defence life-cycles is presented.

Abstract

Open-source testbeds for intrusion detection and mitigation enable benchmarking the efficacy of machine-learning-based cyber-defensive systems under increasingly realistic, heterogeneous network scenarios. In this context, the open-world nature of network intrusion detection requires defences to use continual learning strategies to adapt pattern-matching to new attack classes. The cost of periodically fine-tuning pre-trained detectors is not only computational but also encompasses the broader Cyber Threat Intelligence (CTI) life-cycle, which involves collecting, analyzing, and processing raw data into actionable insights. For ML-driven defensive systems, such actionable CTI ultimately takes the form of curated, labelled traffic traces of novel attacks. However, the concurrent optimisation of these intelligence-gathering costs and defence effectiveness has received little attention from the research community. In this respect, this work presents tiger, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyber-defence life-cycles. tiger uses realistic network simulation software to model an active-learning game in which an agent learns to timely purchase CTI—abstracted in our environment as labelled samples of Zero-day attacks— to retrain its intrusion detection machinery on new attack patterns, while considering a constrained resource availability scenario.

Read PDF

Similar papers

Open access 2026

Autonomous Cyber Defense Learning Using Reinforcement and Threat Intelligence

The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.

Abimbola B. Owolabi, F. Osang · 0 citations
Open access Sep 2026

ACID: beta-testing active inference for active cyber-defence

Active cyber-defence employs anticipatory techniques to proactively mitigate cyber threats. Among such techniques, the most relevant one consists in the continuous updating of cyber-threat intelligence. In this respect, there is a trade-off between the cost of intelligence assets and the benefits derived from their exp...

Jesús F. Cevallos-Moreno, A. Rizzardi, S. Sicari et al. · 0 citations
Open access 2026

Hierarchical Adversarially-Driven Escalation System (HADES) for Network Intrusion Detection

The Hierarchical Adversarially-Driven Escalation System (hades) is introduced, a framework that addresses this vulnerability to adversarial examples through three coordinated mechanisms and maintains near-perfect detection accuracy under both normal and adversarial conditions.

A. Derhab, Adlen Kerboua, N. Seddari et al. · 0 citations
#federated learning Open access Aug 2026

An Explainable AI-Driven Cyber Threat Intelligence Framework for Proactive and Adaptive Cyberattack Detection

XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.

R. Yadav · 0 citations

STOCHASTIC ATTACK–DEFENSE CONFRONTATION MODEL FOR WEB

The model uses an aggregated representation of system components as an aggregation of an attack graph built with the Meta Attack Language together with a stochastic initialization of initial conditions, which reduces the dimensionality of the state space and ensures the computational tractability of the analysis.

Prytula Andrii, Kupershtein Leonid · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.