← Latest papers
🤖 AI

Can LLMs effectively provide game-theoretic-based scenarios for cybersecurity?

This paper investigates the effectiveness of using Large Language Models (LLMs) as agents in game-theoretic cybersecurity scenarios, revealing that their strategic behaviors and payoffs are significantly influenced by personality traits, knowledge of repeated interactions, and linguistic context, thereby highlighting critical stability and bias concerns for their deployment in global security applications.

Original authors: Daniele Proverbio, Alessio Buscemi, Alessandro Di Stefano, The Anh Han, German Castignani, Pietro Liò

Published 2026-02-19
📖 5 min read🧠 Deep dive

Original authors: Daniele Proverbio, Alessio Buscemi, Alessandro Di Stefano, The Anh Han, German Castignani, Pietro Liò

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you are trying to predict how two people will behave in a high-stakes game of chess, but instead of human players, you have two super-smart robots (Large Language Models, or LLMs) playing against each other.

This paper asks a very important question: Can we trust these AI robots to act like the "perfect" strategic players that math predicts they should?

Here is the breakdown of the study using simple analogies:

1. The Setting: The Cybersecurity Playground

Think of the internet as a giant, chaotic playground. On one side, you have Attackers (trying to break the swings), and on the other, Defenders (trying to keep the swings safe).

For years, experts have used Game Theory (a branch of math) to predict how these two sides will act. It's like a rulebook that says, "If the attacker does X, the defender should do Y to win."

Now, we have LLMs (the brains behind chatbots like the one you're talking to). We want to use these AIs to simulate these attacks and defenses. But before we let them loose, we need to know: Do they actually follow the math, or do they have their own weird quirks?

2. The Experiments: Two Classic Games

The researchers put four different top-tier AI models (GPT-4, Gemini, Mistral, and Llama) into two specific game scenarios to see how they behaved.

  • Game 1: The Zero-Sum Game (The "Pie" Game)

    • The Analogy: Imagine two people fighting over a single pie. If you get a bigger slice, I get a smaller one. There is no way for both of us to win; one person's gain is the other's loss.
    • The Math Prediction: The best strategy is usually to be unpredictable (randomly choosing slices) so the opponent can't guess your move.
    • What the AI Did: The AIs were not consistent. Sometimes they played randomly, sometimes they played the same way every time. Worse, if you asked the same AI to play the game in English, it played one way. If you asked it to play in French or Arabic, it changed its strategy completely! It was like the AI had a different personality depending on the language it was speaking.
  • Game 2: The Prisoner's Dilemma (The "Trust" Game)

    • The Analogy: Two suspects are in separate cells. They can either Cooperate (stay silent) or Defect (snitch on the other).
      • If both stay silent, they both get a light sentence (Good!).
      • If one snitches and the other stays silent, the snitch goes free and the other gets a heavy sentence (Bad!).
      • If both snitch, they both get a medium sentence (Okay, but not great).
    • The Math Prediction: In a single round, the smart move is to snitch (Defect) because you never know what the other person will do. But if you play this game many times (Repeated Prisoner's Dilemma), the smart move is to learn to trust and cooperate to get better results over time.
    • What the AI Did: The AIs generally learned to cooperate over time (which is good!). However, their behavior was heavily influenced by Personality and Language.
      • If the AI was told to be "Selfish," it snitched more.
      • If it was told to be "Cooperative," it stayed silent more.
      • The Shock: The same AI model would cooperate in English but betray its partner in Vietnamese. The language itself changed the AI's moral compass!

3. The Big Discovery: The "Accent" Problem

The most surprising finding is that language matters more than we thought.

Imagine you hire a security guard. You expect them to act the same way whether they are speaking English, French, or Chinese. But in this study, the AI "guards" changed their tactics based on the language they were speaking.

  • An AI might be a "hero" in English but a "villain" in Arabic.
  • This means if you build a cybersecurity system using an AI, and you deploy it in a country where the AI speaks a different language, your security system might suddenly become weak or unpredictable.

4. The Takeaway: Don't Just Press "Play"

The paper concludes that while AI is a powerful tool for cybersecurity, we cannot just plug it in and assume it will work perfectly.

  • The Good News: We have a new way to test these AIs (using a tool called FAIRGAME) to see if they are stable.
  • The Bad News: Different AI models behave very differently. Some are stable (like Llama and GPT-4 in some tests), while others are chaotic (like Claude and Mistral in this study).
  • The Warning: If you are building a defense system, you must test your AI in the exact language and cultural context where it will be used. You can't assume an AI trained in English will act the same way in Vietnam or the Middle East.

Summary Metaphor

Think of these AI models as chameleons.
In Game Theory, we want a robot that is a rock—solid, predictable, and unchanging.
But these LLMs are chameleons. They change their color (strategy) based on the background (language) and the mood (personality traits) they are given.

The lesson: Before you let a chameleon guard your castle, you need to know exactly what color it will be in the specific room where it's standing. Otherwise, it might turn invisible right when you need it most.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →