SearcharxivSearch

arXiv subjects

Caroline Hillairet

Publications and source records attributed to Caroline Hillairet.

At least 19 recordsLinked to original sources

Optimal Impulse Control for Cyber Risk Management

We explore an optimal impulse control problem wherein an electronic device owner strategically calibrates protection levels against cyber attacks. Utilizing epidemiological compartment models, we qualitatively characterize the dynamics of cyber attacks within the network. We determine the optimal protective measures against effective hacking by formulating and solving a stochastic control problem with optimal switching. We demonstrate that the value function for the cluster owner constitutes a viscosity solution to a system of coupled variational inequalities associated with a fully coupled reflected backward stochastic differential equation (BSDE). Furthermore, we devise a comprehensive algorithm alongside a verification procedure to ascertain the optimal timing for network protection across various cyber attack scenarios. Our findings are illustrated through numerical approximations employing deep Galerkin methods for partial differential equations (PDEs). We visualize the optimal protection strategies in the context of two distinct attack scenarios: (1) a constant cyber attack, (2) an exogenous cyber attack strategy modeled with a Poisson process.

math.OC

Optimal investment and Pension policy in Pay-As-You-Go systems under forward utility and ageing population

This paper investigates optimal investment and pension policies in a Pay-As-You-Go (PAYG) system supplemented by a buffer fund used as an intergenerational risk-sharing mechanism. The social planner's preference criterion is represented by non-zero volatility forward Constant Relative Risk Aversion (CRRA) utilities, and explicitly accounts for both sustainability and adequacy constraints. The optimal policies are characterized in closed form, and an in-depth analysis of the impact of preference sensitivities on the pension scheme is conducted. A detailed numerical analysis is performed to evaluate the sustainability and benefit adequacy of this hybrid PAYG buffer fund arrangement under a range of demographic, financial, and macroeconomic scenarios.

q-fin.MF

A stochastic SIR model for cyber contagion: application to granular growth of firms and to insurance portfolio

This work evaluates the impact of contagious cyber-events, over a finite horizon, on firms' financial health and on a cyber insurance portfolio. Our approach builds on key empirical findings from economics and cybersecurity. In economics, firm size and growth-rate distributions are non-Gaussian and exhibit heavy tails. In cybersecurity, contagion dynamics strongly depend on firm size and environmental conditions. To capture these features, we propose a stochastic multi-group SIR model coupled with a granular model of firm growth. This framework allows us to quantify the financial impact of cyber-attacks on firms' revenues and on the insurer's portfolio. In the model, the arrival time and duration of cyber-attacks are driven by a combination of a Cox process and a Bernoulli random variable. The Cox process represents external contagion, with an intensity given by the force of infection derived from the stochastic SIR dynamics. The Bernoulli component captures contagion originating from an infected sister or subsidiary firm. Environmental variability enables stochastic scenario generation and the computation of aggregate exceedance probabilities, a standard metric in catastrophe modeling that provides insurers with immediate insight into the financial severity of an event. We apply the framework to the LockBit ransomware attacks observed between May and July 2024. For a portfolio of 2,929 firms located in Ile-de-France, the model predicts that, with 50% probability, the insurer will need to compensate losses equivalent to up to two days of revenue over a 100-day cyber incident.

q-fin.RM

A stochastic Gordon-Loeb model for optimal cybersecurity investment under clustered attacks

We develop a continuous-time stochastic model for optimal cybersecurity investment under the threat of cyberattacks. The arrival of attacks is modeled using a Hawkes process, capturing the empirically relevant feature of clustering in cyberattacks. Extending the Gordon-Loeb model, each attack may result in a breach, with breach probability depending on the system's vulnerability. We aim at determining the optimal cybersecurity investment to reduce vulnerability. The problem is cast as a two-dimensional Markovian stochastic optimal control problem and solved using dynamic programming methods. Numerical results illustrate how accounting for attack clustering leads to more responsive and effective investment policies, offering significant improvements over static and Poisson-based benchmark strategies. Our findings underscore the value of incorporating realistic threat dynamics into cybersecurity risk management.

q-fin.RM

Disaster Risk Financing through Taxation: A Framework for Regional Participation in Collective Risk-Sharing

We consider an economy composed of different risk profile regions wishing to be hedged against a disaster risk using multi-region catastrophe insurance. Such catastrophic events inherently have a systemic component; we consider situations where the insurer faces a non-zero probability of insolvency. To protect the regions against the risk of the insurer's default, we introduce a public-private partnership between the government and the insurer. When a disaster generates losses exceeding the total capital of the insurer, the central government intervenes by implementing a taxation system to share the residual claims. In this study, we propose a theoretical framework for regional participation in collective risk-sharing through tax revenues by accounting for their disaster risk profiles and their economic status.

econ.TH

Multivariate Self-Exciting Processes with Dependencies

This paper introduces the class of multidimensional self-exciting processes with dependencies (MSPD), which is a unifying writing for a large class of processes: counting, loss, intensity, and also shifted processes. The framework takes into account dynamic dependencies between the frequency and the severity components of the risk, and therefore induces theoretical challenges in the computations of risk valuations. We present a general method for calculating different quantities related to these MSPDs, which combines the Poisson imbedding, the pseudo-chaotic expansion and Malliavin calculus. The methodology is illustrated for the computation of explicit general correlation formula.

math.PR

Fair Active Learning: Solving the Labeling Problem in Insurance

This paper addresses significant obstacles that arise from the widespread use of machine learning models in the insurance industry, with a specific focus on promoting fairness. The initial challenge lies in effectively leveraging unlabeled data in insurance while reducing the labeling effort and emphasizing data relevance through active learning techniques. The paper explores various active learning sampling methodologies and evaluates their impact on both synthetic and real insurance datasets. This analysis highlights the difficulty of achieving fair model inferences, as machine learning models may replicate biases and discrimination found in the underlying data. To tackle these interconnected challenges, the paper introduces an innovative fair active learning method. The proposed approach samples informative and fair instances, achieving a good balance between model predictive performance and fairness, as confirmed by numerical experiments on insurance datasets.

stat.ML

Poisson imbedding meets the Clark-Ocone formula

In this paper we develop a representation formula of Clark-Ocone type for any integrable Poisson functionals, which extends the Poisson imbedding for point processes. This representation formula differs from the classical Clark-Ocone formula on three accounts. First the representation holds with respect to the Poisson measure instead of the compensated one; second the representation holds true in L1 and not in L2; and finally contrary to the classical Clark-Ocone formula the integrand is defined as a pathwise operator and not as a L2-limiting object. We make use of Malliavin's calculus and of the pseudo-chaotic decomposition with uncompensated iteraded integrals to establish this Pseudo-Clark-Ocone representation formula and to characterize the integrand, which turns out to be a predictable integrable process.

math.PR

Time-consistent pension policy with minimum guarantee and sustainability constraint

This paper proposes and investigates an optimal pair investment/pension policy for a pay-as-you-go (PAYG) pension scheme. The social planner can invest in a buffer fund in order to guarantee a minimal pension amount. The model aims at taking into account complex dynamic phenomena such as the demographic risk and its evolution over time, the time and age dependence of agents preferences, and financial risks. The preference criterion of the social planner is modeled by a consistent dynamic utility defined on a stochastic domain, which incorporates the heterogeneity of overlapping generations and its evolution over time. The preference criterion and the optimization problem also incorporate sustainability, adequacy and fairness constraints. The paper designs and solves the social planner's dynamic decision criterion, and computes the optimal investment/pension policy in a general framework. A detailed analysis for the case of dynamic power utilities is provided.

q-fin.MF

Cyber risk modeling using a two-phase Hawkes process with external excitation

With the growing digital transformation of the worldwide economy, cyber risk has become a major issue. As 1 % of the world's GDP (around $1,000 billion) is allegedly lost to cybercrime every year, IT systems continue to get increasingly interconnected, making them vulnerable to accumulation phenomena that undermine the pooling mechanism of insurance. As highlighted in the literature, Hawkes processes appear to be suitable models to capture contagion phenomena and clustering features of cyber events. This paper extends the standard Hawkes modeling of cyber risk frequency by adding external shocks, modelled by the publication of cyber vulnerabilities that are deemed to increase the likelihood of attacks in the short term. The aim of the proposed model is to provide a better quantification of contagion effects since, while the standard Hawkes model allocates all the clustering phenomena to self-excitation, our model allows to capture the external common factors that may explain part of the systemic pattern. We propose a Hawkes model with two kernels, one for the endogenous factor (the contagion from other cyber events) and one for the exogenous component (cyber vulnerability publications). We use parametric exponential specifications for both the internal and exogenous intensity kernels, and we compare different methods to tackle the inference problem based on public datasets containing features of cyber attacks found in the Hackmageddon database and cyber vulnerabilities from the Known Exploited Vulnerability database and the National Vulnerability Dataset. By refining the external excitation database selection, the degree of endogeneity of the model is nearly halved. We illustrate our model with simulations and discuss the impact of taking into account the external factor driven by vulnerabilities. Once an attack has occurred, response measures are implemented to limit the effects of an attack. These measures include patching vulnerabilities and reducing the attack's contagion. We use an augmented version of the model by adding a second phase modeling a reduction in the contagion pattern from the remediation measures. Based on this model, we explore various scenarios and quantify the effect of mitigation measures of an insurance company that aims to mitigate the effects of a cyber pandemic in its insured portfolio.

math.ST

The value of the information in the Moral Hazard setting

This article studies the problem of evaluating the information that a Principal lacks when establishing an incentive contract with an Agent whose effort is not observable. The Principal ("she") pays a continuous rent to the Agent ("he"), while the latter gives a best response characterized by his effort, until a terminal date decided by the Principal when she stops the contract and gives compensation to the Agent. The output process of the project is a diffusion process driven by a Brownian motion whose drift is impacted by the Agent's effort. The first part of the paper investigates the optimal stochastic control problem when the Principal and the Agent share the same information. This situation, known as the first-best case, is solved by tackling the Lagrangian problem. In the second part, the Principal observes the output process but she may not observe the drift and the Brownian motion separately. This situation is known as the second-best case. We derive the best response of the Agent, then we solve the mixed optimal stopping/stochastic control problem of the Principal under a fixed probability and on the filtration generated by the Brownian motion, which is larger than the one generated by the output process (that corresponds to the information available for the Principal). Under some regularity conditions, the Principal value function is characterized by solving the associated Hamilton Jacobi Bellman Variational Inequality. At the optimum, we prove that the two filtrations coincide. Finally, we compute the value of the information for the Principal provided by the observation of the Agent's effort. It is defined as the difference between the principal value function in the first-best and second-best cases.

math.OC

Explicit correlations for the Hawkes processes

In this paper we fill a gap in the literature by providing exact and explicit expressions for the correlation of general Hawkes processes together with its intensity process. Our methodology relies on the Poisson imbedding representation and on recent findings on Malliavin calculus and pseudo-chaotic representation for counting processes.

math.PR

Optimal stopping contract for Public Private Partnerships under moral hazard

This paper studies optimal Public Private Partnerships contract between a public entity and a consortium, in continuous-time and with a continuous payment, with the possibility for the public to stop the contract. The public ("she") pays a continuous rent to the consortium ("he"), while the latter gives a best response characterized by his effort. This effect impacts the drift of the social welfare, until a terminal date decided by the public when she stops the contract and gives compensation to the consortium. Usually, the public can not observe the effort done by the consortium, leading to a principal agent's problem with moral hazard. We solve this optimal stochastic control with optimal stopping problem in this context of moral hazard. The public value function is characterized by the solution of an associated Hamilton Jacobi Bellman Variational Inequality. The public value function and the optimal effort and rent processes are computed numerically by using the Howard algorithm. In particular, the impact of the social welfare's volatility on the optimal contract is studied.

math.PR

On the chaotic expansion for counting processes

We introduce and study an alternative form of the chaotic expansion for counting processes using the Poisson imbedding representation; we name this alternative form \textit{pseudo-chaotic expansion}. As an application, we prove that the coefficients of this pseudo-chaotic expansion for any linear Hawkes process are obtained in closed form, whereas those of the usual chaotic expansion cannot be derived explicitly. Finally, we study further the structure of linear Hawkes processes by constructing an example of a process in a pseudo-chaotic form that satisfies the stochastic self-exciting intensity equation which determines a Hawkes process (in particular its expectation equals the one of a Hawkes process) but which fails to be a counting process.

math.PR

An expansion formula for Hawkes processes and application to cyber-insurance derivatives

In this paper we provide an expansion formula for Hawkes processes which involves the addition of jumps at deterministic times to the Hawkes process in the spirit of the well-known integration by parts formula (or more precisely the Mecke formula) for Poisson functional. Our approach allows us to provide an expansion of the premium of a class of cyber insurance derivatives (such as reinsurance contracts including generalized Stop-Loss contracts) or risk management instruments (like Expected Shortfall) in terms of so-called shifted Hawkes processes. From the actuarial point of view, these processes can be seen as "stressed" scenarios. Our expansion formula for Hawkes processes enables us to provide lower and upper bounds on the premium (or the risk evaluation) of such cyber contracts and to quantify the surplus of premium compared to the standard modeling with a homogenous Poisson process.

math.PR

The Malliavin-Stein method for Hawkes functionals

In this paper, following Nourdin-Peccati's methodology, we combine the Malliavin calculus and Stein's method to provide general bounds on the Wasserstein distance between functionals of a compound Hawkes process and a given Gaussian density. To achieve this, we rely on the Poisson embedding representation of an Hawkes process to provide a Malliavin calculus for the Hawkes processes, and more generally for compound Hawkes processes. As an application, we close a gap in the literature by providing the first Berry-Esséen bounds associated to Central Limit Theorems for the compound Hawkes process.

math.PR

Pricing formulae for derivatives in insurance using the Malliavin calculus

In this paper we provide a valuation formula for different classes of actuarial and financial contracts which depend on a general loss process, by using the Malliavin calculus. In analogy with the celebrated Black-Scholes formula, we aim at expressing the expected cash flow in terms of a building block. The former is related to the loss process which is a cumulated sum indexed by a doubly stochastic Poisson process of claims allowed to be dependent on the intensity and the jump times of the counting process. For example, in the context of Stop-Loss contracts the building block is given by the distribution function of the terminal cumulated loss, taken at the Value at Risk when computing the Expected Shortfall risk measure.

q-fin.CP

Shapes of implied volatility with positive mass at zero

We study the shapes of the implied volatility when the underlying distribution has an atom at zero and analyse the impact of a mass at zero on at-the-money implied volatility and the overall level of the smile. We further show that the behaviour at small strikes is uniquely determined by the mass of the atom up to high asymptotic order, under mild assumptions on the remaining distribution on the positive real line. We investigate the structural difference with the no-mass-at-zero case, showing how one can--theoretically--distinguish between mass at the origin and a heavy-left-tailed distribution. We numerically test our model-free results in stochastic models with absorption at the boundary, such as the CEV process, and in jump-to-default models. Note that while Lee's moment formula tells that implied variance is at most asymptotically linear in log-strike, other celebrated results for exact smile asymptotics such as Benaim and Friz (09) or Gulisashvili (10) do not apply in this setting--essentially due to the breakdown of Put-Call duality.

q-fin.PR