{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T14:25:50Z","timestamp":1774967150417,"version":"3.50.1"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T00:00:00Z","timestamp":1769558400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T00:00:00Z","timestamp":1769558400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Sci. China Inf. Sci."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1007\/s11432-025-4530-7","type":"journal-article","created":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T06:02:47Z","timestamp":1770357767000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Stackelberg game based deception defense strategy against APT under resource constraints"],"prefix":"10.1007","volume":"69","author":[{"given":"Xin","family":"Deng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pengdeng","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chenguang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weihong","family":"Han","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhihong","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,1,28]]},"reference":[{"key":"4530_CR1","doi-asserted-by":"publisher","first-page":"1163","DOI":"10.1109\/TDSC.2018.2858786","volume":"17","author":"L X Yang","year":"2018","unstructured":"Yang L X, Li P, Yang X, et al. A risk management approach to defending against the advanced persistent threat. IEEE Trans Dependable Secure Comput, 2018, 17: 1163\u20131172","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"4530_CR2","first-page":"1","volume-title":"Proceedings of IEEE Global Communications Conference (GLOBECOM)","author":"M Nakip","year":"2021","unstructured":"Nakip M, Gelenbe E. Mirai botnet attack detection with auto-associative dense random neural network. In: Proceedings of IEEE Global Communications Conference (GLOBECOM), 2021. 1\u20136"},{"key":"4530_CR3","doi-asserted-by":"publisher","first-page":"763","DOI":"10.1007\/978-981-15-8289-9_73","volume-title":"Proceedings of ICT Systems and Sustainability","author":"S Algarni","year":"2021","unstructured":"Algarni S. Cybersecurity attacks: analysis of \u201cWannacry\u201d attack and proposing methods for reducing or preventing such attacks in future. In: Proceedings of ICT Systems and Sustainability, 2021. 763\u2013770"},{"key":"4530_CR4","doi-asserted-by":"publisher","first-page":"5695","DOI":"10.1109\/TKDE.2022.3175719","volume":"35","author":"Y Ren","year":"2023","unstructured":"Ren Y, Xiao Y, Zhou Y, et al. CSKG4APT: a cybersecurity knowledge graph for advanced persistent threat organization attribution. IEEE Trans Knowl Data Eng, 2023, 35: 5695\u20135709","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"4530_CR5","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MSP.2018.1870866","volume":"16","author":"C Wang","year":"2018","unstructured":"Wang C, Lu Z. Cyber deception: overview and the road ahead. IEEE Secur Privacy, 2018, 16: 80\u201385","journal-title":"IEEE Secur Privacy"},{"key":"4530_CR6","first-page":"1230","volume":"61","author":"R Wang","year":"2024","unstructured":"Wang R, Yang C, Deng X, et al. Development of deception defense technology and exploration of its large language model applications. J Comput Res Dev, 2024, 61: 1230\u20131249","journal-title":"J Comput Res Dev"},{"key":"4530_CR7","doi-asserted-by":"publisher","first-page":"130139","DOI":"10.1016\/j.neucom.2025.130139","volume":"638","author":"R Wang","year":"2025","unstructured":"Wang R, Yang C, Deng X, et al. Turn the tables: proactive deception defense decision-making based on Bayesian attack graphs and Stackelberg games. Neurocomputing, 2025, 638: 130139","journal-title":"Neurocomputing"},{"key":"4530_CR8","doi-asserted-by":"publisher","first-page":"96","DOI":"10.15302\/J-SSCAE-2023.06.007","volume":"25","author":"Z Tian","year":"2023","unstructured":"Tian Z, Fang B, Liao Q, et al. Cybersecurity assurance system in the new era and development suggestions thereof: from self-defense to guard. Strategic Study CAE, 2023, 25: 96","journal-title":"Strategic Study CAE"},{"key":"4530_CR9","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1109\/TMC.2024.3455564","volume":"24","author":"H Liu","year":"2025","unstructured":"Liu H, Zhou Y, Fang B, et al. PHCG: PLC honeypoint communication generator for industrial IoT. IEEE Trans Mobile Comput, 2025, 24: 198\u2013209","journal-title":"IEEE Trans Mobile Comput"},{"key":"4530_CR10","doi-asserted-by":"publisher","first-page":"16186","DOI":"10.1109\/TNNLS.2025.3554217","volume":"36","author":"Y Xu","year":"2025","unstructured":"Xu Y, Li M, Fang B, et al. Neural honeypoint: an active defense framework against model inversion attacks. IEEE Trans Neural Netw Learn Syst, 2025, 36: 16186\u201316197","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"4530_CR11","doi-asserted-by":"publisher","first-page":"9388","DOI":"10.1109\/TKDE.2024.3474792","volume":"36","author":"Z Wang","year":"2024","unstructured":"Wang Z, Zhou Y, Liu H, et al. ThreatInsight: innovating early threat detection through threat-intelligence-driven analysis and attribution. IEEE Trans Knowl Data Eng, 2024, 36: 9388\u20139402","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"4530_CR12","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1016\/j.cose.2019.04.013","volume":"85","author":"J Tan","year":"2019","unstructured":"Tan J, Lei C, Zhang H, et al. Optimal strategy selection approach to moving target defense based on Markov robust game. Comput Secur, 2019, 85: 63\u201376","journal-title":"Comput Secur"},{"key":"4530_CR13","doi-asserted-by":"publisher","first-page":"141201","DOI":"10.1007\/s11432-022-3777-y","volume":"67","author":"X X Li","year":"2024","unstructured":"Li X X, Meng M, Hong Y G, et al. A survey of decision making in adversarial games. Sci China Inf Sci, 2024, 67: 141201","journal-title":"Sci China Inf Sci"},{"key":"4530_CR14","doi-asserted-by":"publisher","first-page":"932","DOI":"10.1109\/TITS.2022.3157394","volume":"24","author":"Y Yang","year":"2023","unstructured":"Yang Y, Wang W, Liu L, et al. AoI optimization in the UAV-aided traffic monitoring network under attack: a Stackelberg game viewpoint. IEEE Trans Intell Transp Syst, 2023, 24: 932\u2013941","journal-title":"IEEE Trans Intell Transp Syst"},{"key":"4530_CR15","doi-asserted-by":"publisher","first-page":"12912","DOI":"10.1109\/TITS.2022.3167485","volume":"24","author":"W Wang","year":"2023","unstructured":"Wang W, Srivastava G, Lin J C W, et al. Data freshness optimization under CAA in the UAV-aided MECN: a potential game perspective. IEEE Trans Intell Transp Syst, 2023, 24: 12912\u201312921","journal-title":"IEEE Trans Intell Transp Syst"},{"key":"4530_CR16","first-page":"1","volume-title":"Proceedings of IEEE Conference on Computer Communications","author":"X Feng","year":"2017","unstructured":"Feng X, Zheng Z, Cansever D, et al. A signaling game model for moving target defense. In: Proceedings of IEEE Conference on Computer Communications, 2017. 1\u20139"},{"key":"4530_CR17","first-page":"1","volume-title":"Proceedings of IEEE International Conference on Communications","author":"J Liu","year":"2021","unstructured":"Liu J, Wang Z, Yang J, et al. Deception maze: a Stackelberg game-theoretic defense mechanism for intranet threats. In: Proceedings of IEEE International Conference on Communications, 2021. 1\u20136"},{"key":"4530_CR18","doi-asserted-by":"publisher","first-page":"3816","DOI":"10.1109\/TNSM.2023.3240366","volume":"20","author":"Z Wan","year":"2023","unstructured":"Wan Z, Cho J H, Zhu M, et al. Resisting multiple advanced persistent threats via hypergame-theoretic defensive deception. IEEE Trans Netw Serv Manage, 2023, 20: 3816\u20133830","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"4530_CR19","doi-asserted-by":"publisher","first-page":"1349","DOI":"10.1109\/TIFS.2022.3229595","volume":"18","author":"L Zhang","year":"2022","unstructured":"Zhang L, Zhu T, Hussain F K, et al. A game-theoretic method for defending against advanced persistent threats in cyber systems. IEEE Trans Inform Forensic Secur, 2022, 18: 1349\u20131364","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4530_CR20","doi-asserted-by":"publisher","first-page":"1713","DOI":"10.1109\/TIFS.2018.2885251","volume":"14","author":"L X Yang","year":"2018","unstructured":"Yang L X, Li P, Zhang Y, et al. Effective repair strategy against advanced persistent threat: a differential game approach. IEEE Trans Inform Forensic Secur, 2018, 14: 1713\u20131728","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4530_CR21","first-page":"1","volume":"2021","author":"Y Mi","year":"2021","unstructured":"Mi Y, Zhang H, Hu H, et al. Optimal network defense strategy selection method: a stochastic differential game model. Secur Commun Netws, 2021, 2021: 1\u201316","journal-title":"Secur Commun Netws"},{"key":"4530_CR22","doi-asserted-by":"publisher","first-page":"9619","DOI":"10.1109\/TII.2022.3231406","volume":"19","author":"J Bi","year":"2023","unstructured":"Bi J, He S, Luo F, et al. Defense of advanced persistent threat on Industrial Internet of Things with lateral movement modeling. IEEE Trans Ind Inf, 2023, 19: 9619\u20139630","journal-title":"IEEE Trans Ind Inf"},{"key":"4530_CR23","doi-asserted-by":"publisher","first-page":"121255","DOI":"10.1016\/j.eswa.2023.121255","volume":"236","author":"C Gan","year":"2024","unstructured":"Gan C, Lin J, Huang D W, et al. Equipment classification based differential game method for advanced persistent threats in Industrial Internet of Things. Expert Syst Appl, 2024, 236: 121255","journal-title":"Expert Syst Appl"},{"key":"4530_CR24","doi-asserted-by":"publisher","first-page":"8353","DOI":"10.1109\/TIFS.2024.3451189","volume":"19","author":"W He","year":"2024","unstructured":"He W, Tan J, Guo Y, et al. A deep reinforcement learning-based deception asset selection algorithm in differential games. IEEE Trans Inform Forensic Secur, 2024, 19: 8353\u20138368","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4530_CR25","doi-asserted-by":"publisher","first-page":"4719","DOI":"10.1109\/TDSC.2022.3232537","volume":"20","author":"J Tan","year":"2022","unstructured":"Tan J, Jin H, Hu H, et al. WF-MTD: evolutionary decision method for moving target defense based on Wright-Fisher process. IEEE Trans Dependable Secure Comput, 2022, 20: 4719\u20134732","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"4530_CR26","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1016\/j.jksuci.2023.01.018","volume":"35","author":"H Jin","year":"2023","unstructured":"Jin H, Zhang S, Zhang B, et al. Evolutionary game decision-making method for network attack and defense based on regret minimization algorithm. J King Saud Univ-Comput Inf Sci, 2023, 35: 292\u2013302","journal-title":"J King Saud Univ-Comput Inf Sci"},{"key":"4530_CR27","doi-asserted-by":"publisher","first-page":"120875","DOI":"10.1016\/j.ins.2024.120875","volume":"677","author":"L Liu","year":"2024","unstructured":"Liu L, Tang C, Zhang L, et al. A generic approach for network defense strategies generation based on evolutionary game theory. Inf Sci, 2024, 677: 120875","journal-title":"Inf Sci"},{"key":"4530_CR28","doi-asserted-by":"publisher","first-page":"534","DOI":"10.1109\/JSAC.2017.2659418","volume":"35","author":"L Xiao","year":"2017","unstructured":"Xiao L, Xu D, Xie C, et al. Cloud storage defense against advanced persistent threats: a prospect theoretic study. IEEE J Sel Areas Commun, 2017, 35: 534\u2013544","journal-title":"IEEE J Sel Areas Commun"},{"key":"4530_CR29","doi-asserted-by":"publisher","first-page":"119759","DOI":"10.1016\/j.ins.2023.119759","volume":"652","author":"H Ge","year":"2024","unstructured":"Ge H, Zhao L, Yue D, et al. A game theory based optimal allocation strategy for defense resources of smart grid under cyber-attack. Inf Sci, 2024, 652: 119759","journal-title":"Inf Sci"},{"key":"4530_CR30","first-page":"17372","volume":"8","author":"W Tian","year":"2021","unstructured":"Tian W, Du M, Ji X, et al. Honeypot detection strategy against advanced persistent threats in Industrial Internet of Things: a prospect theoretic game. IEEE Int Things J, 2021, 8: 17372\u201317381","journal-title":"IEEE Int Things J"},{"key":"4530_CR31","doi-asserted-by":"publisher","first-page":"569","DOI":"10.1109\/TIFS.2020.3016842","volume":"16","author":"D Ye","year":"2021","unstructured":"Ye D, Zhu T, Shen S, et al. A differentially private game theoretic approach for deceiving cyber adversaries. IEEE Trans Inform Forensic Secur, 2021, 16: 569\u2013584","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4530_CR32","doi-asserted-by":"publisher","first-page":"384","DOI":"10.26599\/TST.2024.9010063","volume":"30","author":"Y Dong","year":"2024","unstructured":"Dong Y, Liu J, Ren J, et al. Attack and defense game with intuitionistic fuzzy payoffs in infrastructure networks. Tsinghua Sci Technol, 2024, 30: 384\u2013401","journal-title":"Tsinghua Sci Technol"},{"key":"4530_CR33","doi-asserted-by":"publisher","first-page":"5560416","DOI":"10.1155\/2023\/5560416","volume":"2023","author":"W He","year":"2023","unstructured":"He W, Tan J, Guo Y, et al. Flipit game deception strategy selection method based on deep reinforcement learning. Int J Intell Syst, 2023, 2023: 5560416","journal-title":"Int J Intell Syst"},{"key":"4530_CR34","first-page":"451","volume-title":"Proceedings of IEEE Conference on Computer Communications","author":"H Q Ngo","year":"2024","unstructured":"Ngo H Q, Guo M, Nguyen H. Catch me if you can: effective honeypot placement in dynamic ad attack graphs. In: Proceedings of IEEE Conference on Computer Communications, 2024. 451\u2013460"},{"key":"4530_CR35","doi-asserted-by":"publisher","first-page":"1653","DOI":"10.1109\/TNSM.2020.2987085","volume":"17","author":"S Yoon","year":"2020","unstructured":"Yoon S, Cho J H, Kim D S, et al. Attack graph-based moving target defense in software-defined networks. IEEE Trans Netw Serv Manage, 2020, 17: 1653\u20131668","journal-title":"IEEE Trans Netw Serv Manage"},{"key":"4530_CR36","doi-asserted-by":"publisher","first-page":"170305","DOI":"10.1007\/s11432-021-3462-4","volume":"65","author":"H R Li","year":"2022","unstructured":"Li H R, Guo Y F, Huo S M, et al. Defensive deception framework against reconnaissance attacks in the cloud with deep reinforcement learning. Sci China Inf Sci, 2022, 65: 170305","journal-title":"Sci China Inf Sci"},{"key":"4530_CR37","doi-asserted-by":"publisher","first-page":"5735","DOI":"10.1109\/TIFS.2023.3314219","volume":"18","author":"T Zhang","year":"2023","unstructured":"Zhang T, Xu C, Shen J, et al. How to disturb network reconnaissance: a moving target defense approach based on deep reinforcement learning. IEEE Trans Inform Forensic Secur, 2023, 18: 5735\u20135748","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4530_CR38","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1007\/978-3-030-64793-3_4","volume-title":"Proceedings of the 11th International Conference on Decision and Game Theory for Security","author":"T Eghtesad","year":"2020","unstructured":"Eghtesad T, Vorobeychik Y, Laszka A. Adversarial deep reinforcement learning based adaptive moving target defense. In: Proceedings of the 11th International Conference on Decision and Game Theory for Security, 2020. 58\u201379"},{"key":"4530_CR39","first-page":"19459","volume":"12","author":"J Chen","year":"2025","unstructured":"Chen J, Lan X, Zhang Q, et al. Defending against APT attacks in cloud computing environments using grouped multiagent deep reinforcement learning. IEEE Int Things J, 2025, 12: 19459\u201319470","journal-title":"IEEE Int Things J"},{"key":"4530_CR40","unstructured":"Sengupta S, Kambhampati S. Multi-agent reinforcement learning in Bayesian Stackelberg Markov games for adaptive moving target defense. 2020. ArXiv:2007.10457"},{"key":"4530_CR41","doi-asserted-by":"publisher","first-page":"2410","DOI":"10.1109\/TSMC.2022.3211866","volume":"53","author":"T Zhu","year":"2023","unstructured":"Zhu T, Ye D, Cheng Z, et al. Learning games for defending advanced persistent threats in cyber systems. IEEE Trans Syst Man Cybern Syst, 2023, 53: 2410\u20132422","journal-title":"IEEE Trans Syst Man Cybern Syst"},{"key":"4530_CR42","volume-title":"Common vulnerability scoring system (CVSS)","author":"M Schiffman","year":"2011","unstructured":"Schiffman M. Common vulnerability scoring system (CVSS). 2011. https:\/\/www.first.org\/cvss\/v3-0\/"}],"container-title":["Science China Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-025-4530-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11432-025-4530-7","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-025-4530-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T07:03:24Z","timestamp":1770361404000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11432-025-4530-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,28]]},"references-count":42,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["4530"],"URL":"https:\/\/doi.org\/10.1007\/s11432-025-4530-7","relation":{},"ISSN":["1674-733X","1869-1919"],"issn-type":[{"value":"1674-733X","type":"print"},{"value":"1869-1919","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,28]]},"assertion":[{"value":"12 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 May 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 July 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 January 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"132109"}}