Resource-Aware Intrusion Detection in Infrastructure Networks: A Game-Theoretic Approach

Aug 7, 2026· Xuanli Lin , Zhaofeng Zhang , Zunzheng Zhang , Kevin S. Chan , Guoliang Xue · 1 min read
Summary
A graph security game models how a defender should allocate limited sensing and processing resources against an attacker choosing routes to valuable targets. The report analyzes Nash and Stackelberg equilibria under different attacker observations and develops algorithms for defense configurations and mixed strategies when exhaustive strategy enumeration is impractical.
Type
Publication
arXiv preprint arXiv:2608.06655
publication

Abstract

Infrastructure networks increasingly rely on distributed sensing to detect intrusions before attackers reach valuable assets. Yet sensing devices, communication resources, and edge server capacity are limited, while intelligent attackers can adapt their routes to the deployed defense. Motivated by integrated sensing and communication (ISAC), we study how sensing and processing resources should be allocated under strategic interaction between a defender and an attacker. We formulate their interaction as a graph security game in which the defender deploys sensing actions under resource and false alarm constraints, while the attacker selects routes to valuable targets. We consider simultaneous play and settings in which the attacker observes either a pure defender configuration or a mixed defender strategy. Our analysis characterizes the existence, structure, and computational complexity of the Nash and Stackelberg equilibria, showing how the attacker’s observation of the defense affects equilibrium behavior and when optimal strategies become difficult to compute. We develop algorithms that construct effective pure configurations and refine restricted games for mixed Nash and mixed Stackelberg play. On enumerable instances, their solutions have small mean normalized differences from fully enumerated references; the methods also apply when exhaustive strategy enumeration is impractical. We also identify conditions under which Nash and mixed Stackelberg payoffs are ordered or coincide.

Preprint, first submitted 2026-08-07.

Xuanli Lin
Authors
PhD Student in Computer Science

Xuanli Lin is a fifth-year PhD student in the Computer Science department at Arizona State University, supervised by Dr. Guoliang Xue.

His research interests include network optimization, network security, artificial intelligence, and the Internet of Things.

Zunzheng Zhang
Authors
PhD Student in Computer Science
Zunzheng Zhang is a PhD student in computer science at Arizona State University. He studies network optimization and quantum networks. Before joining ASU, he earned his bachelor’s and master’s degrees in electronic engineering from Nanjing University in 2021 and 2024, respectively.
Kevin S. Chan
Authors
Lead Research Electronics Engineer
Kevin S. Chan is a lead research electronics engineer and Network Science Team Lead at the U.S. Army DEVCOM Army Research Laboratory. His research spans network science, edge computing, and cybersecurity. He holds a bachelor’s degree from Carnegie Mellon University and master’s and doctoral degrees in electrical and computer engineering from Georgia Tech. He received the IEEE Communications Society’s Leonard G. Abraham Prize in 2021.
Guoliang Xue
Authors
Professor of Computer Science and Engineering
Guoliang Xue is a professor in Arizona State University’s School of Computing and Augmented Intelligence and an IEEE Fellow. He investigates wireless and quantum networks, network security and privacy, and optimization. He earned his PhD in computer science from the University of Minnesota in 1991. His honors include the IEEE Communications Society’s 2019 William R. Bennett Prize, and he chaired the IEEE INFOCOM Steering Committee from 2020 through 2025.