kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Publications (10 of 73) Show all publications
Lindström, M., Brynielsson, J., Cohen, M., Kamrani, F., Lavebrink, S., Limér, C. & Vangeli, M. (2026). Outsmarting Willful-Thinking Opponents: Bayesian Belief Revision for Adversarial Reasoning in Large Language Models. In: Social Networks Analysis and Mining - 17th International Conference, ASONAM 2025, Proceedings: . Paper presented at 17th International Conference on Social Networks Analysis and Mining, ASONAM 2025, Niagara Falls, Canada, Aug 25 2025 - Aug 28 2025 (pp. 559-578). Springer Nature, 16324
Open this publication in new window or tab >>Outsmarting Willful-Thinking Opponents: Bayesian Belief Revision for Adversarial Reasoning in Large Language Models
Show others...
2026 (English)In: Social Networks Analysis and Mining - 17th International Conference, ASONAM 2025, Proceedings, Springer Nature , 2026, Vol. 16324, p. 559-578Conference paper, Published paper (Refereed)
Abstract [en]

In adversarial contexts, success often hinges on understanding not just what the opponent knows, but what they believe and how they revise those beliefs. This study investigates how large language models can be made more resilient and strategically capable by modeling the opponent’s reasoning using Bayesian belief revision. By formalizing negotiations as Bayesian games of incomplete information, it is shown that models equipped with belief revision are better able to counter deceptive or willful-thinking adversaries. The findings underscore the role of second-order reasoning in adversarial settings, with implications for social manipulation in the context of, for example, online communication and intelligence gathering.

Place, publisher, year, edition, pages
Springer Nature, 2026
Series
Lecture Notes in Computer Science, ISSN 03029743
Keywords
Adversarial modeling, Bayesian belief revision, Behavioral learning, Game theory, Social manipulation
National Category
Philosophy
Identifiers
urn:nbn:se:kth:diva-377811 (URN)10.1007/978-3-032-14107-1_44 (DOI)2-s2.0-105029897517 (Scopus ID)
Conference
17th International Conference on Social Networks Analysis and Mining, ASONAM 2025, Niagara Falls, Canada, Aug 25 2025 - Aug 28 2025
Note

Part of ISBN 9783032141064

QC 20260312

Available from: 2026-03-12 Created: 2026-03-12 Last updated: 2026-03-12Bibliographically approved
Lavebrink, S., Brynielsson, J., Cohen, M., Kamrani, F., Limér, C., Lindström, M. & Vangeli, M. (2026). Strategic Steering of Large Language Models via Game-Theoretic Action Space Optimization. In: Social Networks Analysis and Mining: 17th International Conference, ASONAM 2025, Niagara Falls, ON, Canada, August 25–28, 2025, Proceedings, Part III. Paper presented at 17th International Conference on Social Networks Analysis and Mining, ASONAM 2025, Niagara Falls, Canada, Aug 25 2025 - Aug 28 2025 (pp. 508-528). Springer Nature, 16324
Open this publication in new window or tab >>Strategic Steering of Large Language Models via Game-Theoretic Action Space Optimization
Show others...
2026 (English)In: Social Networks Analysis and Mining: 17th International Conference, ASONAM 2025, Niagara Falls, ON, Canada, August 25–28, 2025, Proceedings, Part III, Springer Nature , 2026, Vol. 16324, p. 508-528Conference paper, Published paper (Refereed)
Abstract [en]

This paper investigates how large language models can be steered to act more strategically in text-based negotiation settings. Two prompt-based action space designs are compared, namely emotional tone prompts and explicit offer prompts, within a negotiation environment, and outcomes are compared in simulated dialogues. The results show that both approaches improve strategic outcomes compared to a baseline, with tone-based actions yielding higher agreement rates and offer-based actions providing more stable tradeoffs. These findings demonstrate how action space design influences agent behavior, providing insights for deployment of large language models in strategic negotiation scenarios to gain an advantage in, for example, online influence operations.

Place, publisher, year, edition, pages
Springer Nature, 2026
Series
Lecture Notes in Computer Science
Keywords
Action space optimization, Adversarial dialogue, Game theory, Influence operations, Large language models
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:kth:diva-377816 (URN)10.1007/978-3-032-14107-1_41 (DOI)2-s2.0-105029907544 (Scopus ID)
Conference
17th International Conference on Social Networks Analysis and Mining, ASONAM 2025, Niagara Falls, Canada, Aug 25 2025 - Aug 28 2025
Note

Part of ISBN 9783032141064

QC 20260309

Available from: 2026-03-09 Created: 2026-03-09 Last updated: 2026-03-09Bibliographically approved
Andreasson, A., Artman, H., Brynielsson, J. & Franke, U. (2025). Cyber situation awareness during an emerging cyberthreat: a case study. International Journal of Information Security, 24(5), Article ID 217.
Open this publication in new window or tab >>Cyber situation awareness during an emerging cyberthreat: a case study
2025 (English)In: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 24, no 5, article id 217Article in journal (Refereed) Published
Abstract [en]

The digitalization of our societies makes them increasingly vulnerable to emerging cyberthreats. These cyberthreats can manifest themselves in the form of organized, sophisticated, and persistent threat actors, as well as nonadversarial mistakes. Staff involved in responding to cyberthreats and handling incidents in organizations need cyber situation awareness. This paper presents a case study on what challenges members of staff involved in cybersecurity in a large, complex organization experience when developing cyber situation awareness while handling a remote code execution vulnerability in the form of Log4Shell. Two types of qualitative empirical material were used for the case study, data collected through semi-structured interviews with ten informants, and internal documentation. The empirical material was analyzed to create a timeline of events in the organization. The results show how information about the threat spread throughout the organization, the types of artifacts that served as common operational pictures, and the role played by information sharing in maintaining staff cyber situation awareness. Three major challenges to the organization were found: (i) information sharing among staff was not effortless, (ii) there was no organization-wide common operational picture established, and (iii) inaccurate information was shared. This study adds a real-world contribution to the literature on organizational handling of cyberthreats.

Place, publisher, year, edition, pages
Springer Nature, 2025
Keywords
Common operational picture, Cyber situation awareness, Cybersecurity, Log4j, Log4Shell, Public sector
National Category
Information Systems, Social aspects Information Systems Business Administration
Identifiers
urn:nbn:se:kth:diva-372052 (URN)10.1007/s10207-025-01106-z (DOI)001581739200001 ()2-s2.0-105017586059 (Scopus ID)
Note

Not duplicate with DiVA 1955293

QC 20251023

Available from: 2025-10-23 Created: 2025-10-23 Last updated: 2025-10-23Bibliographically approved
Brynielsson, J., Carp, A. & Tegen, A. (2025). Detection of Emerging Cyberthreats Through Active Learning. In: Uche Onyekpe, Vasile Palade, M. Arif Wani (Ed.), Recent Advances in Deep Learning Applications: New Techniques and Practical Examples (pp. 123-144). Informa UK Limited
Open this publication in new window or tab >>Detection of Emerging Cyberthreats Through Active Learning
2025 (English)In: Recent Advances in Deep Learning Applications: New Techniques and Practical Examples / [ed] Uche Onyekpe, Vasile Palade, M. Arif Wani, Informa UK Limited , 2025, p. 123-144Chapter in book (Other academic)
Abstract [en]

In the realm of cybersecurity, leveraging machine learning holds promise for advancing threat detection capabilities. Yet, the sheer volume of unlabeled data presents a challenging hurdle to efficient data management. This chapter delves into the efficacy of active learning methodologies in alleviating the burden of manual data labeling. By employing various query strategies, the study identifies the most informative unlabeled data points suitable for labeling. Examining the performance across different query strategies involved testing a transformer model's ability in discerning tweets referencing advanced persistent threats. In scenarios where labeled training data is scarce, the results suggest that the K-means diversity-based query strategy outperforms both the uncertainty-based approach and the random data point selection. Furthermore, the study investigated the cost-effective active learning paradigm, which integrates high-confidence data points into the training dataset. Surprisingly, this approach emerged as the least effective strategy. In summary, the findings not only explain the potential of active learning in cybersecurity, but also underscore the importance of strategic data selection in optimizing model performance. 

Place, publisher, year, edition, pages
Informa UK Limited, 2025
National Category
Security, Privacy and Cryptography
Identifiers
urn:nbn:se:kth:diva-374103 (URN)10.1201/9781003570882-9 (DOI)2-s2.0-105022862964 (Scopus ID)
Note

Part of ISBN 9781032944623, 9781040323977

QC 20251216

Available from: 2025-12-16 Created: 2025-12-16 Last updated: 2025-12-16Bibliographically approved
Oscarsson, M., Brynielsson, J., Cohen, M., Kamrani, F. & Limér, C. (2025). The Cost of Uncertainty in Self-play Reinforcement Learning and Search. In: 2025 IEEE International Conference on Intelligence and Security Informatics (ISI): . Paper presented at 21st Annual IEEE International Conference on Intelligence and Security Informatics, ISI 2025, Hong Kong, China, July 12-13, 2025 (pp. 113-120). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>The Cost of Uncertainty in Self-play Reinforcement Learning and Search
Show others...
2025 (English)In: 2025 IEEE International Conference on Intelligence and Security Informatics (ISI), Institute of Electrical and Electronics Engineers (IEEE) , 2025, p. 113-120Conference paper, Published paper (Refereed)
Abstract [en]

The combination of reinforcement learning and look-ahead search introduced in AlphaGo, has revolutionized our understanding of tactics and strategy in classical strategy games such as Go and chess. Until recently, this pioneering approach has been limited to perfect information games, where players have full information about the current state of the game. This paper investigates the recent generalization of reinforcement learning with search to imperfect information games, such as poker, where parts of the game state, e.g., the opponent’s hand, is hidden from the player. The paper explores how well this approach scales as the amount of hidden information increases. To this end, the current state of the art in reinforcement learning with search, the student of games general learning algorithm, is reproduced and evaluated across three variants of a custom poker game, each differing by the number of hidden cards dealt to players. It is found that games with less hidden information are learned more effectively, and that computational demands scale sublinearly with increasing hidden information.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2025
Keywords
computer poker, counterfactual regret minimization, imperfect information games, Reinforcement learning, student of games algorithm, tree search
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-377986 (URN)10.1109/ISI65680.2025.11201174 (DOI)2-s2.0-105030660994 (Scopus ID)
Conference
21st Annual IEEE International Conference on Intelligence and Security Informatics, ISI 2025, Hong Kong, China, July 12-13, 2025
Note

Part of ISBN 9798331512767

QC 20260312

Available from: 2026-03-12 Created: 2026-03-12 Last updated: 2026-03-12Bibliographically approved
Andreasson, A., Artman, H., Brynielsson, J. & Franke, U. (2024). Cybersecurity work at Swedish administrative authorities: taking action or waiting for approval. Cognition, Technology & Work, 26(4), 709-731
Open this publication in new window or tab >>Cybersecurity work at Swedish administrative authorities: taking action or waiting for approval
2024 (English)In: Cognition, Technology & Work, ISSN 1435-5558, E-ISSN 1435-5566, Vol. 26, no 4, p. 709-731Article in journal (Refereed) Published
Abstract [en]

In recent years, the Swedish public sector has undergone rapid digitalization, while cybersecurity efforts have not kept even steps. This study investigates conditions for cybersecurity work at Swedish administrative authorities by examining organizational conditions at the authorities, what cybersecurity staff do to acquire the cyber situation awareness required for their role, as well as what experience cybersecurity staff have with incidents. In this study, 17 semi-structured interviews were held with respondents from Swedish administrative authorities. The results showed the diverse conditions for cybersecurity work that exist at the authorities and that a variety of roles are involved in that work. It was found that national-level support for cybersecurity was perceived as somewhat lacking. There were also challenges in getting access to information elements required for sufficient cyber situation awareness.

Place, publisher, year, edition, pages
Springer Nature, 2024
National Category
Computer and Information Sciences
Research subject
Human-computer Interaction
Identifiers
urn:nbn:se:kth:diva-354123 (URN)10.1007/s10111-024-00779-1 (DOI)001321655700001 ()2-s2.0-85205049306 (Scopus ID)
Funder
Swedish Armed Forces
Note

QC 20240930

Available from: 2024-09-29 Created: 2024-09-29 Last updated: 2025-04-29Bibliographically approved
Carp, A., Brynielsson, J. & Tegen, A. (2023). Active Learning for Improvement of Classification of Cyberthreat Actors in Text Fragments. In: Proceedings - 22nd IEEE International Conference on Machine Learning and Applications, ICMLA 2023: . Paper presented at 22nd IEEE International Conference on Machine Learning and Applications, ICMLA 2023, Jacksonville, United States of America, Dec 15 2023 - Dec 17 2023 (pp. 1279-1286). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Active Learning for Improvement of Classification of Cyberthreat Actors in Text Fragments
2023 (English)In: Proceedings - 22nd IEEE International Conference on Machine Learning and Applications, ICMLA 2023, Institute of Electrical and Electronics Engineers (IEEE) , 2023, p. 1279-1286Conference paper, Published paper (Refereed)
Abstract [en]

In the domain of cybersecurity, machine learning can offer advanced threat detection. However, the volume of unlabeled data poses challenges for efficient data management. This study investigates the potential for active learning to reduce the effort required for manual data labeling. Through different query strategies, the most informative unlabeled data points were selected for labeling. The performance of different query strategies was assessed by testing a transformer model's ability to accurately distinguish tweets mentioning names of advanced persistent threats. The findings suggest that the K-means diversity-based query strategy outperformed both the uncertainty-based approach and the random data point selection, when the amount of labeled training data was limited. This study also evaluated the cost-effective active learning approach, which incorporates high-confidence data points into the training dataset. However, this was shown to be the least effective strategy.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2023
Keywords
Active learning, advanced persistent threat, cybersecurity, natural language processing
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-350002 (URN)10.1109/ICMLA58977.2023.00193 (DOI)2-s2.0-85190143463 (Scopus ID)
Conference
22nd IEEE International Conference on Machine Learning and Applications, ICMLA 2023, Jacksonville, United States of America, Dec 15 2023 - Dec 17 2023
Note

Part of ISBN 9798350345346

QC 20240705

Available from: 2024-07-05 Created: 2024-07-05 Last updated: 2024-08-01Bibliographically approved
Brynielsson, J., Cohen, M., Hansen, P., Lavebrink, S., Lindström, M. & Tjörnhammar, E. (2023). Comparison of Strategies for Honeypot Deployment. In: Prakash, BA Wang, D Weninger, T (Ed.), Proceedings Of The 2023 Ieee/Acm International Conference On Advances In Social Networks Analysis And Mining, Asonam 2023: . Paper presented at 15th IEEE/ACM Annual International Conference on Advances in Social Networks Analysis and Mining (ASONAM), NOV 06-09, 2023, Kusadasi, Turkey (pp. 612-619). Association for Computing Machinery (ACM)
Open this publication in new window or tab >>Comparison of Strategies for Honeypot Deployment
Show others...
2023 (English)In: Proceedings Of The 2023 Ieee/Acm International Conference On Advances In Social Networks Analysis And Mining, Asonam 2023 / [ed] Prakash, BA Wang, D Weninger, T, Association for Computing Machinery (ACM) , 2023, p. 612-619Conference paper, Published paper (Refereed)
Abstract [en]

Recent experimental studies have explored how well adaptive honeypot allocation strategies defend against human adversaries. As the experimental subjects were drawn from an unknown, nondescript pool of subjects using Amazon Mechanical Turk, the relevance to defense against real-world adversaries is unclear. The present study reproduces the experiments with more relevant experimental subjects. The results suggest that the strategies considered are less effective against attackers from the current population. In particular, their ability to predict the next attack decreased steadily over time, that is, the human subjects from this population learned to attack less and less predictably.

Place, publisher, year, edition, pages
Association for Computing Machinery (ACM), 2023
Series
Proceedings of the IEEE-ACM International Conference on Advances in Social Networks Analysis and Mining, ISSN 2473-9928
Keywords
Cybersecurity, honeypot, game theory, defense strategy, behavioral learning
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:kth:diva-345925 (URN)10.1145/3625007.3631602 (DOI)001191293500097 ()2-s2.0-85190627573 (Scopus ID)
Conference
15th IEEE/ACM Annual International Conference on Advances in Social Networks Analysis and Mining (ASONAM), NOV 06-09, 2023, Kusadasi, Turkey
Note

Part of proceedings ISBN: 979-840070409-3

QC 20240426

Available from: 2024-04-26 Created: 2024-04-26 Last updated: 2024-04-26Bibliographically approved
Hansen, P., García Lozano, M., Kamrani, F. & Brynielsson, J. (2023). Real-time estimation of heart rate in situations characterized by dynamic illumination using remote photoplethysmography. In: Proceedings: 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops, CVPRW 2023. Paper presented at 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops, CVPRW 2023, Vancouver, Canada, Jun 18 2023 - Jun 22 2023 (pp. 6094-6103). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Real-time estimation of heart rate in situations characterized by dynamic illumination using remote photoplethysmography
2023 (English)In: Proceedings: 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops, CVPRW 2023, Institute of Electrical and Electronics Engineers (IEEE) , 2023, p. 6094-6103Conference paper, Published paper (Refereed)
Abstract [en]

Remote photoplethysmography (rPPG) is a technique that aims to remotely estimate the heart rate of an individual using an RGB camera. Although several studies use the rPPG methodology, it is usually applied in a laboratory in a controlled environment, where both the camera and the subject are static, and the illumination is ideal for the task. However, applying rPPG in a real-life scenario is much more demanding, since dynamic illumination issues arise. The work presented in this paper introduces a framework to estimate the heart rate of an individual in real-time using an RGB camera in a situation characterized by dynamic illumination. Such situations occur, for example, when either the camera or the subject is moving, and/or the face visibility is limited. The framework uses a face detection program to extract regions of interest on an individual's face. These regions are combined and constitute the input to a convolutional neural network, which is trained to estimate the heart rate in real-time. The method is evaluated on three publicly available datasets, and an in-house dataset specifically collected for the purpose of this study, that includes motions and dynamic illumination. The method shows good performance on all four datasets, outperforming other methods.

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2023
National Category
Computer Systems
Identifiers
urn:nbn:se:kth:diva-337848 (URN)10.1109/CVPRW59228.2023.00649 (DOI)2-s2.0-85170820700 (Scopus ID)
Conference
2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops, CVPRW 2023, Vancouver, Canada, Jun 18 2023 - Jun 22 2023
Note

Part of ISBN 9798350302493

QC 20231010

Available from: 2023-10-10 Created: 2023-10-10 Last updated: 2023-10-10Bibliographically approved
Varga, S., Sommestad, T. & Brynielsson, J. (2022). Automation of Cybersecurity Work. In: Artificial Intelligence and Cybersecurity: Theory and Applications (pp. 67-101). Springer Nature
Open this publication in new window or tab >>Automation of Cybersecurity Work
2022 (English)In: Artificial Intelligence and Cybersecurity: Theory and Applications, Springer Nature , 2022, p. 67-101Chapter in book (Other academic)
Abstract [en]

This chapter examines the conditions for automation of cybersecurity work roles, and the probabilities of them being automated. Further, variables that limit the automation potential for current cybersecurity roles are reviewed. Based on a well-established and widely adopted reference resource that lists typical skill requirements and duties of cybersecurity workers, an assessment of the susceptibility for automation of cybersecurity work was performed by an expert panel. All cybersecurity work descriptions were ranked in terms of proneness for automation according to four criteria: requirements for creativity, social interaction, physical work, and the existence of relevant statistical training data. It was found that technical roles, for example database administrators and data analysts, are easiest to automate. Roles associated with management and accountability, for example, legal advisors and cyber operations planners, are more difficult to automate. Finally, requirements for physical work is a negligible factor when it comes to cybersecurity work automation.

Place, publisher, year, edition, pages
Springer Nature, 2022
National Category
Communication Systems
Identifiers
urn:nbn:se:kth:diva-333031 (URN)10.1007/978-3-031-15030-2_4 (DOI)2-s2.0-85160502522 (Scopus ID)
Note

Part of ISBN 9783031150302 9783031150296

QC 20230725

Available from: 2023-07-25 Created: 2023-07-25 Last updated: 2023-07-25Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-2677-9759

Search in DiVA

Show all publications