{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T07:49:50Z","timestamp":1782287390516,"version":"3.54.5"},"reference-count":48,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T00:00:00Z","timestamp":1782259200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.eswa.2026.132741","type":"journal-article","created":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T16:06:39Z","timestamp":1778169999000},"page":"132741","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Explainable autonomous cyber defense using adversarial multi-agent reinforcement learning"],"prefix":"10.1016","volume":"326","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-6018-2612","authenticated-orcid":false,"given":"Yiyao","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8212-8793","authenticated-orcid":false,"given":"Diksha","family":"Goel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9940-2733","authenticated-orcid":false,"given":"Hussain","family":"Ahmad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132741_bib0001","series-title":"Advances in information security","article-title":"Autonomous intelligent cyber defense agent (AICA)","author":"AIC","year":"2023"},{"issue":"17","key":"10.1016\/j.eswa.2026.132741_bib0002","doi-asserted-by":"crossref","first-page":"8482","DOI":"10.3390\/app12178482","article-title":"Malware detection issues, challenges, and future directions: A survey","volume":"12","author":"Aboaoja","year":"2022","journal-title":"Applied Sciences"},{"key":"10.1016\/j.eswa.2026.132741_bib0003","doi-asserted-by":"crossref","first-page":"52138","DOI":"10.1109\/ACCESS.2018.2870052","article-title":"Peeking inside the black-box: A survey on explainable artificial intelligence (XAI)","volume":"6","author":"Adadi","year":"2018","journal-title":"IEEE Access"},{"issue":"9","key":"10.1016\/j.eswa.2026.132741_bib0004","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3558001","article-title":"A review on c3i systems\u2019 security: Vulnerabilities, attacks, and countermeasures","volume":"55","author":"Ahmad","year":"2023","journal-title":"ACM Computing Surveys"},{"issue":"2","key":"10.1016\/j.eswa.2026.132741_bib0005","doi-asserted-by":"crossref","first-page":"33","DOI":"10.3390\/jcp5020033","article-title":"A survey on immersive cyber situational awareness systems","volume":"5","author":"Ahmad","year":"2025","journal-title":"Journal of Cybersecurity and Privacy"},{"key":"10.1016\/j.eswa.2026.132741_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.118439","article-title":"A new intrusion detection system based on Moth-Flame optimizer algorithm","volume":"210","author":"Alazab","year":"2022","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0007","series-title":"Network security: A decision and game-theoretic approach","author":"Alpcan","year":"2010"},{"issue":"2","key":"10.1016\/j.eswa.2026.132741_bib0008","doi-asserted-by":"crossref","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","article-title":"A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities","volume":"21","author":"Alshamrani","year":"2019","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"10.1016\/j.eswa.2026.132741_bib0009","series-title":"2017 IEEE symposium on security and privacy (SP)","first-page":"483","article-title":"Verified models and reference implementations for the tls 1.3 standard candidate","author":"Bhargavan","year":"2017"},{"key":"10.1016\/j.eswa.2026.132741_bib0010","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.120715","article-title":"An empirical study of pattern leakage impact during data preprocessing on machine learning-based intrusion detection models reliability","volume":"230","author":"Bouke","year":"2023","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0011","series-title":"Model checking","author":"Clarke","year":"1999"},{"key":"10.1016\/j.eswa.2026.132741_bib0012","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.123027","article-title":"Dugat-LSTM: Deep learning based network intrusion detection system using chaotic optimization strategy","volume":"245","author":"Devendiran","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0013","article-title":"Review of artificial intelligence for enhancing intrusion detection in the internet of things","volume":"238","author":"Essa","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0014","doi-asserted-by":"crossref","first-page":"32031","DOI":"10.1109\/ACCESS.2020.2973178","article-title":"Security and privacy for green iot-based agriculture: Review, blockchain solutions, and challenges","volume":"8","author":"Ferrag","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.eswa.2026.132741_bib0015","article-title":"Hybrid deep learning model using spcagan augmentation for insider threat analysis","volume":"249","author":"Gayathri","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0016","unstructured":"Goel, D. (2023). Enhancing network resilience through machine learning-powered graph combinatorial optimization: Applications in cyber defense and information diffusion, arXiv preprint arXiv: 2310.10667."},{"key":"10.1016\/j.eswa.2026.132741_bib0017","unstructured":"Goel, D., Ahmad, H., Moore, K., & Guo, M. (2025a). Co-evolutionary defence of active directory attack graphs via GNN-approximated dynamic programming, arXiv preprint arXiv: 2505.11710, 2025."},{"key":"10.1016\/j.eswa.2026.132741_bib0018","series-title":"Computer and cyber security","first-page":"249","article-title":"Overview of smartphone security: Attack and defense techniques","author":"Goel","year":"2018"},{"key":"10.1016\/j.eswa.2026.132741_bib0019","series-title":"Proc. European symposium on research in computer security (ESORICS)","first-page":"332","article-title":"Optimizing cyber defense in dynamic active directories through reinforcement learning","author":"Goel","year":"2024"},{"key":"10.1016\/j.eswa.2026.132741_bib0020","doi-asserted-by":"crossref","unstructured":"Goel, D., Moore, K., Wang, J., Kim, M., & Nguyen, T. T. (2025b). Unveiling the black box: A multi-layer framework for explaining reinforcement learning-based cyber agents, arXiv preprint arXiv: 2505.11708.","DOI":"10.1016\/j.jisa.2026.104507"},{"key":"10.1016\/j.eswa.2026.132741_bib0021","series-title":"Deep learning","author":"Goodfellow","year":"2016"},{"issue":"6","key":"10.1016\/j.eswa.2026.132741_bib0022","doi-asserted-by":"crossref","first-page":"750","DOI":"10.1007\/s10458-019-09421-1","article-title":"A survey and critique of multiagent deep reinforcement learning","volume":"33","author":"Hernandez-Leal","year":"2019","journal-title":"Autonomous Agents and Multi-Agent Systems"},{"issue":"2","key":"10.1016\/j.eswa.2026.132741_bib0023","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3703155","article-title":"A survey on hallucination in large language models: principles, taxonomy, challenges, and open questions","volume":"43","author":"Huang","year":"2025","journal-title":"ACM Transactions on Information Systems"},{"key":"10.1016\/j.eswa.2026.132741_bib0024","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2021.115524","article-title":"A bidirectional LSTM deep learning approach for intrusion detection","volume":"185","author":"Imrana","year":"2021","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0025","doi-asserted-by":"crossref","first-page":"1074","DOI":"10.1016\/j.procs.2024.06.137","article-title":"Enhancing security and energy efficiency of cyber-physical systems using deep reinforcement learning","volume":"238","author":"Jamshidi","year":"2024","journal-title":"Procedia Computer Science"},{"issue":"3","key":"10.1016\/j.eswa.2026.132741_bib0026","doi-asserted-by":"crossref","first-page":"262","DOI":"10.1002\/sec.559","article-title":"A survey on security issues in smart grids","volume":"9","author":"Jokar","year":"2016","journal-title":"Security and Communication Networks"},{"key":"10.1016\/j.eswa.2026.132741_bib0027","first-page":"1","article-title":"Anomaly detection in vehicular networks using causality-aware graph convolutional networks (CA-GCN)","author":"Luo","year":"2025","journal-title":"International Journal of Automotive Technology"},{"key":"10.1016\/j.eswa.2026.132741_bib0028","article-title":"Adversarial examples: A survey of attacks and defenses in deep learning-enabled cybersecurity systems","volume":"238","author":"Macas","year":"2023","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0029","article-title":"Network intrusion detection: An optimized deep learning approach using big data analytics","volume":"251","author":"Mary","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0030","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.artint.2018.07.007","article-title":"Explanation in artificial intelligence: Insights from the social sciences","volume":"267","author":"Miller","year":"2019","journal-title":"Artificial Intelligence"},{"key":"10.1016\/j.eswa.2026.132741_bib0031","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.120596","article-title":"Intrusion detection using hybridized meta-heuristic techniques with weighted xgboost classifier","volume":"232","author":"Mohiuddin","year":"2023","journal-title":"Expert Systems with Applications"},{"issue":"4","key":"10.1016\/j.eswa.2026.132741_bib0032","doi-asserted-by":"crossref","first-page":"3005","DOI":"10.1007\/s10462-022-10246-w","article-title":"Human-in-the-loop machine learning: A state of the art","volume":"56","author":"Mosqueira-Rey","year":"2023","journal-title":"Artificial Intelligence Review"},{"issue":"13","key":"10.1016\/j.eswa.2026.132741_bib0033","doi-asserted-by":"crossref","first-page":"5941","DOI":"10.3390\/s23135941","article-title":"CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environment","volume":"23","author":"Neto","year":"2023","journal-title":"Sensors"},{"issue":"10","key":"10.1016\/j.eswa.2026.132741_bib0034","first-page":"4535","article-title":"Deep reinforcement learning for cyber security","volume":"32","author":"Nguyen","year":"2021","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"10.1016\/j.eswa.2026.132741_bib0035","series-title":"Proceedings of the 2017 ACM on Asia conference on computer and communications security","first-page":"506","article-title":"Practical black-box attacks against machine learning","author":"Papernot","year":"2017"},{"key":"10.1016\/j.eswa.2026.132741_bib0036","series-title":"Causality: Models, reasoning, and inference","author":"Pearl","year":"2009"},{"key":"10.1016\/j.eswa.2026.132741_bib0037","series-title":"Markov decision processes: Discrete stochastic dynamic programming","author":"Puterman","year":"2014"},{"key":"10.1016\/j.eswa.2026.132741_bib0038","series-title":"2018 IEEE international congress on internet of things (ICIOT)","first-page":"65","article-title":"Intelligent multi-agent collaboration model for smart home IoT security","author":"Rafferty","year":"2018"},{"issue":"6","key":"10.1016\/j.eswa.2026.132741_bib0039","doi-asserted-by":"crossref","first-page":"1200","DOI":"10.1016\/j.icte.2025.10.004","article-title":"A comprehensive review of explainable AI in cybersecurity: Decoding the black box","volume":"11","author":"Sharma","year":"2025","journal-title":"ICT Express"},{"key":"10.1016\/j.eswa.2026.132741_bib0040","series-title":"Multiagent systems: Algorithmic, game-theoretic, and logical foundations","author":"Shoham","year":"2008"},{"key":"10.1016\/j.eswa.2026.132741_bib0041","series-title":"Causation, prediction, and search","author":"Spirtes","year":"2000"},{"key":"10.1016\/j.eswa.2026.132741_bib0042","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121549","article-title":"An improved random forest based on the classification accuracy and correlation measurement of decision trees","volume":"237","author":"Sun","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132741_bib0043","series-title":"Reinforcement learning: An introduction","author":"Sutton","year":"2018"},{"issue":"12","key":"10.1016\/j.eswa.2026.132741_bib0044","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3677119","article-title":"Counterfactual explanations and algorithmic recourses for machine learning: A review","volume":"56","author":"Verma","year":"2024","journal-title":"ACM Computing Surveys"},{"issue":"4","key":"10.1016\/j.eswa.2026.132741_bib0045","doi-asserted-by":"crossref","first-page":"97","DOI":"10.3390\/computers13040097","article-title":"A survey of security challenges in cloud-based SCADA systems","volume":"13","author":"Wali","year":"2024","journal-title":"Computers"},{"key":"10.1016\/j.eswa.2026.132741_bib0046","series-title":"Proceedings of the first conference on language modeling","article-title":"AutoGen: Enabling next-gen LLM applications via multi-agent conversation","author":"Wu","year":"2024"},{"key":"10.1016\/j.eswa.2026.132741_bib0047","series-title":"Technical Report","article-title":"Living off the Land and Fileless Attack Techniques","author":"Wueest","year":"2017"},{"key":"10.1016\/j.eswa.2026.132741_bib0048","unstructured":"Xu, M., Fan, J., Huang, X., Zhou, C., Kang, J., Niyato, D., Mao, S., Han, Z., & Lam, K.-Y. (2025). Forewarned is forearmed: A survey on large language model-based agents in autonomous cyberattacks, arXiv preprint arXiv: 2505.12786, 2025."}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426016544?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426016544?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T07:31:51Z","timestamp":1782286311000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426016544"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":48,"alternative-id":["S0957417426016544"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132741","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Explainable autonomous cyber defense using adversarial multi-agent reinforcement learning","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132741","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"132741"}}