VulnGym: Evaluating Vulnerability Management Strategies against Advanced Persistent Threats
Sofia Della Penna, Lorenzo Parracino, Luciano Pianese, Vittorio Orbinato, Roberto Natella
cs.CR
Submitted: 2026-07-27
Code: https://github.com/dessertlab/vulnGym
License: http://creativecommons.org/licenses/by/4.0/
The gist: Enterprise networks are continuously targeted by Advanced Persistent Threats (APTs), attack campaigns exploiting software vulnerabilities to compromise critical assets over time.
Terminology
Abstract
Enterprise networks are continuously targeted by Advanced Persistent Threats (APTs), attack campaigns exploiting software vulnerabilities to compromise critical assets over time. As disclosed vulnerabilities grow, resource-constrained organizations must prioritize which ones to patch. Existing prioritization standards score vulnerabilities individually and cannot capture how a patching policy performs against an adversary that progresses through the network over time. Previous tools have simulated attack campaigns through Reinforcement Learning (RL), but either omit vulnerability management, leaving the attacker unopposed, or rely on synthetic networks disconnected from real threat data, and so cannot assess how a policy would fare against a realistic adversary. To fill this gap, we propose VulnGym, a simulation tool to evaluate vulnerability management policies. VulnGym simulates an RL-trained attacker, calibrated on real APT profiles, against a defender executing a configurable patching policy over a network with real Common Vulnerabilities and Exposures (CVEs). Both agents act on a shared, evolving network representation, so the attacker's progress is directly shaped by the defender's patching activity, allowing a given policy to be stress-tested against a realistic attack campaign. Experiments based on real-world vulnerabilities and two APTs show that vulnerability management must be tailored to organizational context, adversarial behavior, network topology, and asset criticality.
Sources
- Evaluation of Reinforcement Learning for Autonomous Penetration Testing using A3C, Q-learning and DQN
- Playing Atari with Deep Reinforcement Learning
- To Patch or Not to Patch: Motivations, Challenges, and Implications for Cybersecurity
- Autonomous Penetration Testing using Reinforcement Learning
- Learning Cyber Defence Tactics from Scratch with Multi-Agent Reinforcement Learning
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs