{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T08:03:34Z","timestamp":1784793814872,"version":"3.55.0"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032325181","type":"print"},{"value":"9783032325198","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T00:00:00Z","timestamp":1784851200000},"content-version":"vor","delay-in-days":204,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>We show how to use passive automata learning to infer models of attacker-defender interactions in cybersecurity. By treating system event logs as words in a formal language, we can apply algorithms such as RPNI to infer compact deterministic finite automata from observed traces. We evaluate this approach through a case study on the Cyber Operations Research Gymnasium (CybORG), a widely-used simulation framework for training defensive agents using machine learning. We analyze the structural properties of the inferred automata and assess their empirical fidelity with respect to the semantics of CybORG. Our results show that accurate formal models can be learned from a relatively small number of traces, suggesting a promising path toward more automated and data-driven approaches to cybersecurity.<\/jats:p>","DOI":"10.1007\/978-3-032-32519-8_25","type":"book-chapter","created":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T07:17:54Z","timestamp":1784791074000},"page":"497-510","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["The Simulator\u2019s Blueprint: Automata Learning from Cybersecurity Logs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-0119-2353","authenticated-orcid":false,"given":"Tudor","family":"Braicu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8608-7404","authenticated-orcid":false,"given":"Benjamin","family":"Ylvisaker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7802-6196","authenticated-orcid":false,"given":"Nicolas","family":"Espinosa Dice","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yiding","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9180-8512","authenticated-orcid":false,"given":"Yiyi","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6557-684X","authenticated-orcid":false,"given":"Nate","family":"Foster","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4743-8750","authenticated-orcid":false,"given":"Hossein","family":"Hojjat","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,24]]},"reference":[{"key":"25_CR1","doi-asserted-by":"publisher","unstructured":"Aichernig, B.K., Muskardin, E., Pferscher, A.: Active vs. passive: a comparison of automata learning paradigms for network protocols. In: International Workshop on Formal Methods for Autonomous Systems (FMAS) and International Workshop on Automated and verifiable Software System Development (ASYDE). EPTCS, vol. 371, pp. 1\u201319 (2022). https:\/\/doi.org\/10.4204\/EPTCS.371.1","DOI":"10.4204\/EPTCS.371.1"},{"issue":"2","key":"25_CR2","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1016\/0890-5401(87)90052-6","volume":"75","author":"D Angluin","year":"1987","unstructured":"Angluin, D.: Learning regular sets from queries and counterexamples. Inf. Comput. 75(2), 87\u2013106 (1987). https:\/\/doi.org\/10.1016\/0890-5401(87)90052-6","journal-title":"Inf. Comput."},{"key":"25_CR3","doi-asserted-by":"publisher","unstructured":"Carrasco, R.C., Oncina, J.: Learning stochastic regular grammars by means of a state merging method. In: International Colloquium on Grammatical Inference and Applications (ICGI). LNCS, vol. 862, pp. 139\u2013152. Springer (1994). https:\/\/doi.org\/10.1007\/3-540-58473-0_144","DOI":"10.1007\/3-540-58473-0_144"},{"key":"25_CR4","doi-asserted-by":"publisher","unstructured":"Ferreira, T., Brewton, H., D\u2019Antoni, L., Silva, A.: Prognosis: closed-box analysis of network protocol implementations. In: ACM SIGCOMM Conference, pp. 762\u2013774 (2021). https:\/\/doi.org\/10.1145\/3452296.3472938","DOI":"10.1145\/3452296.3472938"},{"key":"25_CR5","doi-asserted-by":"publisher","unstructured":"Frohme, M., Howar, F., Steffen, B.: LearnLib: 10 years later. In: Computer Aided Verification (CAV). LNCS, vol. 15934, pp. 141\u2013160. Springer (2025). https:\/\/doi.org\/10.1007\/978-3-031-98685-7_7","DOI":"10.1007\/978-3-031-98685-7_7"},{"key":"25_CR6","doi-asserted-by":"publisher","unstructured":"Henderson, P., Islam, R., Bachman, P., Pineau, J., Precup, D., Meger, D.: Deep reinforcement learning that matters. In: AAAI Conference on Artificial Intelligence, vol. 32, pp. 3207\u20133214 (2018). https:\/\/doi.org\/10.1609\/AAAI.V32I1.11694","DOI":"10.1609\/AAAI.V32I1.11694"},{"key":"25_CR7","doi-asserted-by":"publisher","unstructured":"de la Higuera, C.: Grammatical Inference: Learning Automata and Grammars. Cambridge University Press (2010). https:\/\/doi.org\/10.1017\/CBO9781139194655","DOI":"10.1017\/CBO9781139194655"},{"key":"25_CR8","doi-asserted-by":"publisher","unstructured":"Hsiung, E., Biswas, J., Chaudhuri, S.: Automata learning from preference and equivalence queries. In: Computer Aided Verification (CAV). LNCS, vol. 15934, pp. 104\u2013126. Springer (2025). https:\/\/doi.org\/10.1007\/978-3-031-98685-7_5","DOI":"10.1007\/978-3-031-98685-7_5"},{"key":"25_CR9","doi-asserted-by":"publisher","unstructured":"Kiely, M., Bowman, D., Standen, M., Moir, C.: On autonomous agents in a cyber defence environment (2023). https:\/\/doi.org\/10.48550\/arXiv.2309.07388","DOI":"10.48550\/arXiv.2309.07388"},{"key":"25_CR10","doi-asserted-by":"publisher","unstructured":"Lang, K.J., Pearlmutter, B.A., Price, R.A.: Results of the Abbadingo one DFA learning competition and a new evidence-driven state merging algorithm. In: International Colloquium on Grammatical Inference (ICGI). LNCS, pp. 1\u201312. Springer (1998). https:\/\/doi.org\/10.1007\/BFB0054059","DOI":"10.1007\/BFB0054059"},{"key":"25_CR11","doi-asserted-by":"publisher","unstructured":"Levine, S., Kumar, A., Tucker, G., Fu, J.: Offline reinforcement learning: tutorial, review, and perspectives on open problems (2020). https:\/\/doi.org\/10.48550\/arXiv.2005.01643","DOI":"10.48550\/arXiv.2005.01643"},{"key":"25_CR12","doi-asserted-by":"publisher","unstructured":"Moeller, M., Ferreira, T., Lu, T., Foster, N., Silva, A.: Active learning of symbolic NetKAT automata. In: Proceedings of the ACM on Programming Languages (PACMPL) 9(PLDI), pp. 1119\u20131142 (2025). https:\/\/doi.org\/10.1145\/3729295","DOI":"10.1145\/3729295"},{"key":"25_CR13","unstructured":"Moon, S., et al.: Alembic: automated model inference for stateful network functions. In: Symposium on Networked Systems Design and Implementation (NSDI), pp. 699\u2013718. USENIX (2019). https:\/\/www.usenix.org\/conference\/nsdi19\/presentation\/moon"},{"issue":"3","key":"25_CR14","doi-asserted-by":"publisher","first-page":"417","DOI":"10.1007\/S11334-022-00449-3","volume":"18","author":"E Muskardin","year":"2022","unstructured":"Muskardin, E., Aichernig, B.K., Pill, I., Pferscher, A., Tappler, M.: AALpy: an active automata learning library. Innov. Syst. Softw. Eng. 18(3), 417\u2013426 (2022). https:\/\/doi.org\/10.1007\/S11334-022-00449-3","journal-title":"Innov. Syst. Softw. Eng."},{"key":"25_CR15","doi-asserted-by":"publisher","unstructured":"Neider, D., Smetsers, R., Vaandrager, F., Kuppens, H.: Benchmarks for automata learning and conformance testing. In: Models, Mindsets, Meta: The What, the How, and the Why Not? Essays Dedicated to Bernhard Steffen on the Occasion of His 60th Birthday, LNCS, vol. 11200, pp. 390\u2013416. Springer (2019). https:\/\/doi.org\/10.1007\/978-3-030-22348-9_23","DOI":"10.1007\/978-3-030-22348-9_23"},{"issue":"49\u201361","key":"25_CR16","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1142\/9789812797902_0004","volume":"1","author":"J Oncina","year":"1992","unstructured":"Oncina, J., Garcia, P., et al.: Inferring regular languages in polynomial update time. Patt. Recogn. Image Anal. 1(49\u201361), 10\u20131142 (1992). https:\/\/doi.org\/10.1142\/9789812797902_0004","journal-title":"Patt. Recogn. Image Anal."},{"key":"25_CR17","doi-asserted-by":"publisher","unstructured":"Shehab, M.L., Aspeel, A., Ozay, N.: Learning reward machines from partially observed policies. Trans. Mach. Learn. Res. (TMLR) (2025). https:\/\/doi.org\/10.48550\/arXiv.2502.03762","DOI":"10.48550\/arXiv.2502.03762"},{"key":"25_CR18","doi-asserted-by":"publisher","unstructured":"Standen, M., Lucas, M., Bowman, D., Richer, T.J., Kim, J., Marriott, D.: Cyborg: a gym for the development of autonomous cyber agents (2021). https:\/\/doi.org\/10.48550\/arXiv.2108.09118","DOI":"10.48550\/arXiv.2108.09118"},{"key":"25_CR19","unstructured":"Sutton, R.S., Barto, A.G.: Reinforcement Learning: An Introduction, 2nd edn. MIT Press (2018). http:\/\/www.incompleteideas.net\/book\/the-book-2nd.html"},{"issue":"2","key":"25_CR20","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1145\/2967606","volume":"60","author":"F Vaandrager","year":"2017","unstructured":"Vaandrager, F.: Model learning. Commun. ACM (CACM) 60(2), 86\u201395 (2017). https:\/\/doi.org\/10.1145\/2967606","journal-title":"Commun. ACM (CACM)"},{"key":"25_CR21","doi-asserted-by":"publisher","unstructured":"Verwer, S., Hammerschmidt, C.A.: Flexfringe: a passive automaton learning package. In: International Conference on Software Maintenance and Evolution (ICSME), pp. 638\u2013642. IEEE (2017). https:\/\/doi.org\/10.1109\/ICSME.2017.58","DOI":"10.1109\/ICSME.2017.58"},{"key":"25_CR22","doi-asserted-by":"publisher","unstructured":"Waga, M.: Active learning of deterministic timed automata with Myhill-Nerode style characterization. In: Enea, C., Lal, A. (eds.) Computer Aided Verification (CAV). LNCS, vol. 13964, pp. 3\u201326. Springer (2023). https:\/\/doi.org\/10.1007\/978-3-031-37706-8_1","DOI":"10.1007\/978-3-031-37706-8_1"},{"key":"25_CR23","doi-asserted-by":"publisher","unstructured":"Xu, Z., et al.: Joint inference of reward machines and policies for reinforcement learning. In: International Conference on Automated Planning and Scheduling (ICAPS), pp. 590\u2013598. AAAI Press (2020). https:\/\/doi.org\/10.1609\/icaps.v30i1.6756","DOI":"10.1609\/icaps.v30i1.6756"}],"container-title":["Lecture Notes in Computer Science","Computer Aided Verification"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-32519-8_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T07:17:56Z","timestamp":1784791076000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-32519-8_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032325181","9783032325198"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-32519-8_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"24 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Foster is a visiting researcher at Jane Street. The authors have no other competing interests to declare that are relevant to this article.","order":1,"name":"Ethics","label":"Disclosure of Interests","group":{"name":"EthicsHeading","label":"Ethics"}},{"value":"CAV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Computer Aided Verification","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lisbon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"38","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cav2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.floc26.org\/program","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}