Contagion Effects of Heterogeneous Cyber Risk on Network Security and Systemic Stability
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "Contagion Effects of Heterogeneous Cyber Risk on Network Security and Systemic Stability".
Elias: Cyber risk has become a critical financial threat in today’s interconnected digital economy, necessitating a new management framework that combines strategic player behavior with contagion dynamics within a security game.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: Let's talk about the title and authors of this paper, "Contagion Effects of Heterogeneous Cyber Risk on Network Security and Systemic Stability." The title itself makes it clear that we aren't just looking at one type of risk, but how different kinds of cyber risks interact with each other across a whole network.
Elias: I think the authors, Botteghi, Centonze, Pastorello, and Tantari, are bringing together different areas—mathematics and applied security—which suggests a rigorous approach to modeling these complex interactions.
Priya: It sounds like they are setting up a scenario where financial crises can follow cyber incidents because of how the network is structured and who values those nodes most. I wonder what kind of data they use to represent those different risk profiles.
Nadia: They are focusing on this competition between attackers and defenders, where one side tries to maximize their gain while the other tries to minimize loss, which sets up a very dynamic security game.
Elias: That competitive structure is key; it means we have to look at how the attacker's choice of targets directly influences the defender's optimal resource allocation, which is where things get mathematically interesting.
The paper's summary: Nadia: The paper summarizes that they are introducing a cyber-risk management framework designed specifically to figure out the best way to allocate cybersecurity resources across a network when those risk profiles are not uniform.
Elias: They build on the idea of contagion mechanisms, but they make it more complex by allowing nodes to be valued differently by both parties, which reflects their asymmetric information about the system's structure and strategic importance.
Priya: What I find interesting is that they define specific risk measures based on contagion paths, which suggests we aren't just looking at immediate threats but also the potential for slow, long-term propagation within the network.
Nadia: Right, Priya; they introduce these path-based measures to quantify how a node's vulnerability is connected to its neighbors over time through susceptibility variables.
Elias: And they extend this concept by defining a risk measure based on the expected number of paths connecting a node to an infection seed, which can be computed efficiently through matrix multiplication.
The paper's improvements: Nadia: The authors outline several key contributions, including extending the method to determine optimal resource allocation using simple network metrics derived from the one-point and two-point protection tensors, p one and p two <ref:2601.16805#pg0,method to determine optimal resource allocation>.
Elias: Those metrics are pretty interesting because they quantify vulnerability based on connectivity, specifically how a node can disrupt paths or how many pairs of nodes it can block simultaneously to stop contagion.
Priya: And they provide an explicit approximation for the optimal security investment vector q* in a low-budget regime, showing that this strategy depends solely on those network metrics combined with the value profiles z and eta.
Nadia: That approximation is important because it gives us a concrete way to calculate what the defender should invest in without having to solve the whole complex game every time.
Elias: Beyond that, they introduce risk measures like R(f,L) i(q, phi; A), where L can be interpreted as infection propagation time, allowing for an explicit dynamical dimension to study how fast things spread.
Conclusion: Nadia: So to wrap up the main points of "Contagion Effects of Heterogeneous Cyber Risk on Network Security and Systemic Stability," they show that optimal allocation can be characterized by these network-based metrics, and they've given us specific tools for measuring risk based on contagion paths.
Elias: The implication here is that for complex digital ecosystems, we need to move past uniform security investments and instead use game-theoretic models to decide where to spend resources based on who is trying to attack you.
Priya: I think the most tangible result is the ability to quantify risk not just as a single probability of infection, but by looking at the expected number of paths, which gives us a better picture of systemic fragility.
Nadia: Exactly; this work suggests that understanding how different players value different parts of the network is crucial for building truly robust systems against sophisticated cyber threats.
Elias: It really frames cybersecurity as an ongoing strategic competition rather than just a defensive measure, and that's a significant shift in how we should think about system stability.
Priya: I just hope future work digs deeper into applying these path measures to real-world, high-throughput systems where the dynamics are much more chaotic than the static contagion mechanism they first defined.
Department of Mathematics, University of Bologna · TIFPA-INFN
cs.CR, cs.GT, cs.SI, q-fin.RM
Submitted: 2026-01-23
Updated: 2026-10-05
Comments: Title changed, new sections added
Journal ref: Economic Modelling, Volume 165, 2026, 107854, ISSN 0264-9993
DOI: 10.1016/j.econmod.2026.107854.
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
Importance score: 77/100
The gist: Cyber risk has become a critical financial threat in today’s interconnected digital economy, necessitating a new management framework that combines strategic player behavior with contagion dynamics
Key concepts
- Stackelberg Equilibrium
- This is a sequential game where one player (the defender) moves first by setting their security level, and the second player (the attacker) responds optimally. The equilibrium finds the best possible security investment for the defender given how the attacker will react.
- Contagion Dynamics
- This models how a cyber-threat spreads through a network. A node gets infected if it is connected to an already infected node via a path of susceptible nodes. This helps quantify how quickly and widely an attack can propagate.
- Protection Tensors (p1, p2)
- These are simple mathematical metrics derived from the network structure that measure vulnerability. They quantify how well the network can resist attacks by looking at things like node connectivity and the ability to disrupt paths between nodes.
- Cyber-Deception Effects
- This phenomenon occurs when an attacker intentionally misleads a defender. The paper shows that attackers often avoid directly attacking high-value nodes, instead choosing a seed location that causes the defender to invest defenses in less critical areas.
Terminology
Summary
Cyber risk has become a critical financial threat in today’s interconnected digital economy, necessitating a new management framework that combines strategic player behavior with contagion dynamics within a security game. The core problem addressed is optimally allocating cybersecurity resources across networked digital systems when both attackers and defenders have heterogeneous valuations and risk profiles.
The gist: Optimal security investment strategy in networked systems under heterogeneous cyber-risk profiles is characterized by simple network metrics derived from Stackelberg equilibrium analysis, which reveal patterns of resource allocation and cyber deception effects.
Model Setup for Contagion
The framework models a general class of security games involving an attacker and a defender on an undirected network G. The system state is defined by the adjacency matrix A, where Aij = 1 indicates a link between nodes i and j. Each node s can be the target of a cyber-threat with probability ϕs, representing the attack distribution vector ϕ. Nodes are characterized by their susceptibility vector X, modeled as independent Bernoulli variables where P(Xi = 0) = qi and P(Xi = 1) = 1 - qi; the vector q represents the security level of the system. The infection condition is defined such that a node i becomes infected if it belongs to the same connected component as the seed s in the transmission network T (X), where T(X) is a sub-network consisting only of susceptible nodes.
Security Game Framework and Objectives
The game involves an attacker optimizing their cyber-attack distribution vector ϕ and a defender allocating defenses by adjusting the system’s security vector q. The attacker's utility function is defined as Ua(ϕ; q) = Xn i η i Ri(q, ϕ; A) − θ Ca(ϕ), where Ri is the infection risk at each node, and Ca(ϕ) represents the attacker's information cost. The defender seeks to minimize their loss function Ld(q; ϕ) = Xn i z i Ri(q, ϕ; A) + α Cd(q), where Zi is the defender's value profile and Cd represents the defender's investment cost. The risk profile R measures infection risk as a function of network structure A and strategies (q, ϕ).
Stackelberg Equilibrium and Network Metrics
The analysis focuses on a Stackelberg extensive game where the defender moves first, choosing an action q, and the attacker responds with a best-response function ϕ(q). A Strong Stackelberg Equilibrium (SSE) is defined by conditions ensuring both players play their best responses sequentially. The optimal security investment q∗ corresponding to an SSE can be characterized using simple network metrics derived from the 1-point protection tensor p1 and the 2-point protection tensor p2. These metrics quantify node vulnerability based on connectivity, such as a node's ability to disrupt paths or simultaneous removal of pairs of nodes to block contagion. Theorem 1 provides an explicit approximation for the optimal strategy q∗ in a low-budget regime, showing its dependence solely on these network-based metric tensors p1 and p2 combined with the value profiles z and η.
Risk Measures and Contagion Dynamics
The paper introduces two distinct risk measures: the actual probability of a node being infected, Ri(q, ϕ; A), and a measure based on the expected number of paths connecting the node to the infection seed. The latter is defined using N L i(s, X; A), representing the number of different paths of maximum length L connecting node i to seed s in T(X). This allows for an explicit dynamical dimension where L can be interpreted as infection propagation time. The risk measure can be generalized as R(f,L) i(q, ϕ; A) = EX s [f(N L i(s, X; A))]. For linear activation functions f, the risk simplifies to the expected number of paths (Eq. 16), which can be computed efficiently via matrix multiplication.
Numerical Results and Deception Effects
Numerical experiments explore the efficient frontier by plotting global risk R∗(α; A) against the defender’s cost C∗d(α; A) for varying network topologies and risk profiles. These results illustrate how different topologies, such as tree-structured networks versus Erdős–Rényi random networks, affect robustness. Furthermore, analysis of optimal investment patterns q∗ reveals unexpected effects of cyber-deception: the attacker’s most valuable nodes consistently appear under-protected compared to others when their value profile is targeted. This is interpreted as a strategy where the attacker avoids a direct assault on high-value nodes by selecting a seed relatively distant from them, which misleads the defender into dispersing investments away from actual targets.
Robustness to Contagion Misspecification
To assess robustness, the optimal strategies derived from the security game equilibrium are evaluated under dynamic contagion models, specifically Markovian dynamics defined by Eq. (19).
Improvements for AI systems
As a fastidious researcher, I have analyzed this paper, Network Security under Heterogeneous Cyber-Risk Profiles and Contagion,
and identified several high-impact areas where integrating these findings into AI systems would yield significant improvements.
Here are the specific improvements and the capabilities of the resulting AI system:
) 1. Optimization of Dynamic Cybersecurity Resource Allocation (The Core Mechanism)
Instead of static or rule-based security spending, an AI system can implement a real-time, game-theoretic optimization engine based on the derived Stackelberg Equilibrium (SSE). The AI would use the network structure and current risk profiles to calculate the optimal investment vector, ensuring that limited budgets are allocated where they maximize systemic resilience against anticipated strategic attacks.
) 2. Heterogeneous Risk Modeling and Value Profiling
The AI system can move beyond uniform node valuation by explicitly modeling heterogeneous attacker and defender risk profiles (the vectors of values, e.g., if an attacker prioritizes high-value financial nodes versus infrastructure nodes). This allows the AI to understand that its defense strategy must be tailored not just to network structure, but to the specific vulnerabilities valued by the adversary.
) 3. Contagion-Aware Threat Assessment (Risk Measure Enhancement)
The AI will utilize risk measures based on contagion paths (Definition 15/16), which quantify not just a node's direct vulnerability, but its potential to be infected via susceptible neighbors over time. This allows the system to prioritize defenses based on their bottleneck
or bridge
status within the network—defending nodes that are critical for preventing widespread systemic failure.
) 4. Proactive Cyber Deception Strategy (Adversarial Response)
The AI can learn and implement cyber-deception strategies derived from Section 4.2. By understanding how the attacker exploits the defender’s lack of knowledge, the AI can be programmed to adopt misleading
defense patterns—such as strategically under-protecting high-value targets or seeding threats in distant areas—to disrupt the attacker's optimal path selection, thereby steering them away from critical assets.
) 5. Robustness Testing Against Dynamic Contagion Misspecification
The AI system can be trained on a class of dynamic contagion models (like Markovian dynamics in Section 4.3). This allows the AI to test its optimal defense strategies against various propagation speeds and recovery rates, ensuring the allocated resources remain effective even when the actual threat evolves faster or slower than initially modeled.
) Improved AI System Capabilities:
The resulting system would be a next-generation Cyber Resilience Orchestrator capable of:
-
Calculating the mathematically optimal security budget allocation for a complex network under adversarial conditions in real-time (SSE Solver).
-
Identifying
critical nodes
whose immunization prevents the most potential contagion paths, rather than just protecting high-degree nodes. -
Deploying adaptive defense tactics that intentionally mislead sophisticated attackers by manipulating their perceived value landscape (Deception Engine).
-
Maintaining a
budget-aware
optimization, ensuring that investments yield the highest reduction in overall systemic risk as defined by the attacker's utility function, rather than just minimizing local cost.
Abstract
Understanding how heterogeneous cyber risk shapes security investments and contagion is a key challenge for the resilience of interconnected digital systems. Existing studies on cybersecurity investments and network contagion typically rely on homogeneous assets, uniform attack incentives, or non-strategic threat propagation. We develop a Stackelberg security game that combines contagion dynamics with heterogeneous cyber risk, allowing attackers and defenders to assign different values to network nodes, reflecting differences in asset criticality, information, and objectives. We characterize the equilibrium allocation of cybersecurity investments and derive an analytical approximation for the optimal defense strategy based on endogenous network protection metrics. We show that cyber-risk heterogeneity significantly affects attack incentives and resource allocation, while neglecting it leads to systematic defense misallocation. Our results suggest that cybersecurity policies should leverage both actual and perceived differences in node criticality, as cyber-deception mechanisms can create strategic misperceptions that redirect attacks and enhance systemic resilience.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs