Adaptive adversaries that respond to defensive actions

Develop autonomous cyber-defense strategies that can defend enterprise IT/OT networks against adversaries that observe defensive responses and adapt their attack strategy accordingly.

Background

BlueSTAR models the adversary as persistent and multi-technique, with ordered fallback behaviors when credentials, sessions, hosts, or network paths become unavailable. However, the modeled red agent cannot observe the defender’s decisions, action set, or detection policy, and therefore cannot strategically alter its techniques in response to defensive behavior. The paper explicitly identifies extending the threat model to adversaries that adapt to blue-team responses as unresolved.

References

This scoping captures the machine-speed, persistent, multi-technique character of recent autonomous intrusions; it excludes adversaries that strategically adapt their technique in response to observed defender behavior, which remains an open problem (Section~\ref{sec:discussion}).

BlueSTAR: Tiered Agentic Architecture for Autonomous Cyber Defense  (2609.11852 - Boboila et al., 10 Sep 2026) in Section 2, Subsection “Adversary Model”