SearcharxivSearch

arXiv subjects

Yiran Gao

Publications and source records attributed to Yiran Gao.

5 recordsLinked to original sources

Hierarchical Agentic Incident Response with Digital-Twin-Validated Attack Inference

Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands. Decision-theoretic planners provide principled optimization but typically rely on abstract states and predefined actions, while large language model (LLM) agents can reason over operational context but may hallucinate attacks and responses. Toward automating response planning, we present a hierarchical agentic response framework that integrates LLM-based attack inference, rollout planning, and digital-twin validation. A fine-tuned LLM infers the attack progression and affected hosts from security alerts and system measurements. An emulated network digital twin replays the inferred attack and returns discrepancies between predicted and observed effects to calibrate the inference. A separately fine-tuned planning agent uses the rollout planning method to prioritize affected components at the tactical layer. At the operational layer, the planning agent proposes high-level recovery actions, and an execution agent translates selected actions into recovery and verification commands that are validated in the digital twin. We evaluate the framework on a 33-component enterprise-network testbed under three multi-stage attack scenarios. The results show that our framework outperforms frontier-LLM baselines in recovery success rate by 18--31%.

cs.CR

Agentic Incident Response through Digital Twin-Enhanced Multiscale Planning

Incident response is currently managed by security operators using predefined playbooks, resulting in slow, labor-intensive security decision-making processes. Consequently, there is a growing need for automated incident response planning. Decision-theoretic approaches based on control, optimization, and reinforcement learning have been proposed to automate such planning tasks with well-grounded approaches, yet most of which, while guaranteeing strong performance, are limited to abstract models and cannot be directly applied to operational systems. A promising approach to mitigate this limitation is to use the security knowledge embedded in large language models (LLMs) to develop agentic response systems. However, current agentic approaches rely on repeated invocations of the LLM to generate a response plan, which is unreliable and limits the planning horizon due to hallucination. In this paper, we develop a principled LLM-based planning method by combining decision-theoretic planning with LLM-generated response commands. The proposed agentic incident response approach uses a rollout planner to compute a high-level response strategy that allocates security resources (the tactical scale), which is then translated into executable commands by a lightweight LLM agent (the operational scale). Within this architecture, we use a digital twin that supports tactical planning through simulation and operational execution through emulation. Across three attack scenarios, our agentic approach reduces recovery execution time by 15.1\% on average and increases the recovery rate by 33.6\% over frontier LLM baselines.

cs.CR

In-Context Autonomous Network Incident Response: An End-to-End Large Language Model Agent Approach

Rapidly evolving cyberattacks demand incident response systems that can autonomously learn and adapt to changing threats. Prior work has extensively explored the reinforcement learning approach, which involves learning response strategies through extensive simulation of the incident. While this approach can be effective, it requires handcrafted modeling of the simulator and suppresses useful semantics from raw system logs and alerts. To address these limitations, we propose to leverage large language models' (LLM) pre-trained security knowledge and in-context learning to create an end-to-end agentic solution for incident response planning. Specifically, our agent integrates four functionalities, perception, reasoning, planning, and action, into one lightweight LLM (14b model). Through fine-tuning and chain-of-thought reasoning, our LLM agent is capable of processing system logs and inferring the underlying network state (perception), updating its conjecture of attack models (reasoning), simulating consequences under different response strategies (planning), and generating an effective response (action). By comparing LLM-simulated outcomes with actual observations, the LLM agent repeatedly refines its attack conjecture and corresponding response, thereby demonstrating in-context adaptation. Our agentic approach is free of modeling and can run on commodity hardware. When evaluated on incident logs reported in the literature, our agent achieves recovery up to 23% faster than those of frontier LLMs.

cs.CR

Artificial Cnoidal Wave Breathers in Optical Microresonators

Breathers are localized structures that undergo a periodic oscillation in their duration and amplitude. Optical microresonators, benefiting from their high quality factor, provide an ideal test bench for studying the breathing phenomena. In the monochromatically pumped microresonator system, intrinsic breathing instabilities are widely observed in the form of temporal dissipative Kerr solitons which only exist in the effectively red detuned regime. Here, we proposed a novel bichromatic pumping scheme to create compulsive breathing microcombs via respectively distributing two pump lasers at the effectively blue and red detuned side of a single resonance. We experimentally discover the artificial cnoidal wave breathers and molecular crystal-like breathers in a chip-based silicon nitride microresonator, and theoretically describe their intriguing temporal dynamics based on the bichromatic pumping Lugiato-Lefever equation. In particular, the corresponding breathing microcombs exhibit diverse comb line spacing ranging from 2 to 17 times of the free spectral range of the resonator. Our discovery not only provides a simple and robust method to produce microcombs with reconfigurable comb line spacing, but also reveals a new type of breathing waves in driven dissipative nonlinear systems.

physics.optics

Switching dynamics of reconfigurable perfect soliton crystals in dual-coupled microresonators

Dual-coupled structure is typically used to actively change the local dispersion of microresonator through controllable avoided mode crossings (AMXs). In this paper, we investigate the reconfigurability of perfect soliton crystals (PSCs) based on dual-coupled microresonators. The switching dynamics of PSCs are numerically simulated using perturbed Lugiato-Lefever equation (LLE). Nonlinear phenomena such as solitons rearranging, merging and bursting are observed in the switching process. Specially, for the first time, we have discovered an unexplored $PSC$ $region$ in the microcomb power-detuning phase plane. In $PSC$ $region$, the soliton number ($N$) of PSC state can be switched successively and bidirectionally in a defect-free fashion, verifying the feasibility and advantages of our scheme. The reconfigurability of PSCs would further liberate the application potential of microcombs in a wide range of fields, including frequency metrology, optical communications, and signal-processing systems.

physics.optics