21 papers
SoK: The Pitfalls of Deep Reinforcement Learning for Cybersecurity
Shae McFadden, Myles Foley, Elizabeth Bates +5
Deep Reinforcement Learning (DRL) has achieved remarkable success in domains requiring sequential decision-making, motivating its application to cybersecurity problems. However, tr…
Beyond Rewards in Reinforcement Learning for Cyber Defence
Elizabeth Bates, Chris Hicks, Vasilios Mavroudis
Recent years have seen an explosion of interest in autonomous cyber defence agents trained to defend computer networks using deep reinforcement learning. These agents are typically…
On The Effectiveness of the UK NIS Regulations as a Mandatory Cybersecurity Reporting Regime
Junade Ali, Chris Hicks
Existing cybersecurity literature lacks a source of empirical, representative data as to the true nature of cyberattacks on Critical National Infrastructure. We have obtained UK-wi…
Measuring Security Without Fooling Ourselves: Why Benchmarking Agents Is Hard
Sahar Abdelnabi, Chris Hicks, Konrad Rieck +1
The benchmarks used to evaluate AI agents in security-critical roles suffer from crucial weaknesses. Building on recent empirical evidence, we characterize three core challenges th…
Direction for Detection: A Survey of Automated Vulnerability Detection and all of its Pain Points
Dan Ristea, Shae McFadden, Ezzeldin Shereen +4
Security vulnerabilities in software can have severe consequences; however, manual vulnerability detection is costly and does not scale, especially as agentic coding frameworks inc…
Building Better Environments for Autonomous Cyber Defence
Chris Hicks, Elizabeth Bates, Shae McFadden +12
In November 2025, the authors ran a workshop on the topic of what makes a good reinforcement learning (RL) environment for autonomous cyber defence (ACD). This paper details the kn…