Research & Papers

Multi-agent AI framework recommends security controls with 99% accuracy

New DSS uses game theory to cut security over-provisioning by 35%

Deep Dive

Hardening on-premises IT environments is a challenge for organizations lacking specialized cybersecurity expertise. To address this, Carolina Fernández-Martínez, Shuaib Siddiqui, and Vanesa Daza from Universitat Pompeu Fabra propose a novel Decision Support System (DSS) that recommends security control sub-families based on minimal user input. The framework models the recommendation process as a non-zero-sum simultaneous game grounded in a Multi-Agent Influence Diagram (MAID), where seven security dimensions act as agents. Using no-regret online learning, the system explores the decision space to find the optimal set of controls that best matches user requirements while minimizing both under- and over-provisioning of security resources.

The system leverages a curated, unified dataset from information security standards and academic sources. In validation tests, it achieved 99% satisfaction coverage using approximately 65% of the software-implementable controls, with runtime between 1.2 and 35.7 seconds. More conservative scenarios using only 29% of controls yielded 73–77% coverage in 0.8–13.8 seconds. Published in Elsevier's Knowledge-Based Systems, this research offers a practical tool for teams lacking deep security expertise, enabling them to make informed, cost-effective decisions quickly.

Key Points
  • 99% security coverage achieved using only 65% of available controls, reducing over-provisioning costs
  • System runs in 1.2–35.7 seconds, enabling real-time decision support for IT teams
  • Multi-agent game-theoretic model with 7 security dimensions and no-regret online learning

Why It Matters

Democratizes expert-level security recommendations for teams without dedicated cybersecurity staff, cutting waste and improving protection.

📬 Get the top 10 AI stories daily