IDEAS home Printed from https://ideas.repec.org/a/gam/jmathe/v14y2026i4p683-d1865577.html

Graph Neural Network-Guided TrapManager for Critical Path Identification and Decoy Deployment

Author

Listed:
  • Rui Liu

    (Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China)

  • Guangxia Xu

    (Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China
    Department of New Networks, Peng Cheng Laboratory, Shenzhen 518000, China
    Guangdong Key Laboratory of Industrial Control System Security, Guangzhou 510006, China)

  • Zhenwei Hu

    (Cyberspace Institute of Advanced Technology, Guangzhou University, Guangzhou 510006, China)

Abstract

Static honeypot deployment and one-shot attack-path analysis often become ineffective against adaptive adversaries because fixed decoy layouts are easy to fingerprint and risk estimates quickly go stale. This paper presents a unified, mathematically grounded TrapManager framework that couples graph representation learning with budget-constrained combinatorial optimization for dynamic cyber deception. We model attacker progression on vulnerability-based attack graphs and learn context-aware node embeddings using a Graph Attention Network (GAT) that fuses vulnerability-driven risk signals (e.g., CVSS-derived node scores) with structural features. The learned representations are used to estimate edge plausibility and rank candidate source–target routes at the path level. Given limited resources, we formulate pointTrap placement as a Mixed-Integer Programming (MIP) problem that maximizes the expected interception of high-risk paths while penalizing deployment cost under explicit budget constraints, including mandatory coverage of the top-ranked critical paths. To enable online adaptiveness, a pointTrap-triggered, event-driven feedback mechanism locally amplifies risk around alerted regions, updates path weights without retraining the GAT, and re-solves the MIP for rapid redeployment. Experiments on MulVAL-generated benchmark attack graphs and cross-domain transfer settings demonstrate fast convergence, strong discrimination between attack and non-attack edges, and early interception within a small number of hops even with minimal decoy budgets. Overall, the proposed framework provides a scalable and resource-efficient approach to closed-loop attack-path defense by integrating attention-based learning and integer optimization.

Suggested Citation

  • Rui Liu & Guangxia Xu & Zhenwei Hu, 2026. "Graph Neural Network-Guided TrapManager for Critical Path Identification and Decoy Deployment," Mathematics, MDPI, vol. 14(4), pages 1-20, February.
  • Handle: RePEc:gam:jmathe:v:14:y:2026:i:4:p:683-:d:1865577
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/2227-7390/14/4/683/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/2227-7390/14/4/683/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jmathe:v:14:y:2026:i:4:p:683-:d:1865577. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.