{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T06:08:41Z","timestamp":1784873321983,"version":"3.55.0"},"reference-count":76,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2020,8,30]],"date-time":"2020-08-30T00:00:00Z","timestamp":1598745600000},"content-version":"vor","delay-in-days":366,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Army Research Laboratory","award":["W911NF-17-2-0104"],"award-info":[{"award-number":["W911NF-17-2-0104"]}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["DE-NE0008571"],"award-info":[{"award-number":["DE-NE0008571"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NSF IGERT grant through the Center for Interdisciplinary Studies in Security and Privacy (CRISSP) at New York University","award":["CNS-1544782, EFRI-1441140, and SES-1541164"],"award-info":[{"award-number":["CNS-1544782, EFRI-1441140, and SES-1541164"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2020,7,31]]},"abstract":"<jats:p>Cyberattacks on both databases and critical infrastructure have threatened public and private sectors. Ubiquitous tracking and wearable computing have infringed upon privacy. Advocates and engineers have recently proposed using defensive deception as a means to leverage the information asymmetry typically enjoyed by attackers as a tool for defenders. The term deception, however, has been employed broadly and with a variety of meanings. In this article, we survey 24 articles from 2008 to 2018 that use game theory to model defensive deception for cybersecurity and privacy. Then, we propose a taxonomy that defines six types of deception: perturbation, moving target defense, obfuscation, mixing, honey-x, and attacker engagement. These types are delineated by their information structures, agents, actions, and duration: precisely concepts captured by game theory. Our aims are to rigorously define types of defensive deception, to capture a snapshot of the state of the literature, to provide a menu of models that can be used for applied research, and to identify promising areas for future work. Our taxonomy provides a systematic foundation for understanding different types of defensive deception commonly encountered in cybersecurity and privacy.<\/jats:p>","DOI":"10.1145\/3337772","type":"journal-article","created":{"date-parts":[[2019,9,3]],"date-time":"2019-09-03T12:47:00Z","timestamp":1567514820000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":142,"title":["A Game-theoretic Taxonomy and Survey of Defensive Deception for Cybersecurity and Privacy"],"prefix":"10.1145","volume":"52","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3970-4756","authenticated-orcid":false,"given":"Jeffrey","family":"Pawlick","sequence":"first","affiliation":[{"name":"NYU Tandon School of Engineering and U.S. Army Research Laboratory, Adelphi, MD, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Edward","family":"Colbert","sequence":"additional","affiliation":[{"name":"Virginia Tech Intelligent Systems Lab, Hume Center for National Security and Technology, and U.S. Army Research Laboratory, Arlington, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Quanyan","family":"Zhu","sequence":"additional","affiliation":[{"name":"New York University Tandon School of Engineering"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,8,30]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Shiller","author":"Akerlof George A.","year":"2015","unstructured":"George A. Akerlof and Robert J. Shiller. 2015. Phishing for Phools: The Economics of Manipulation and Deception. Princeton University Press."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2003.1273013"},{"key":"e_1_2_1_3_1","volume-title":"Decision and Game Theory for Security","author":"Alvim M\u00e1rio S.","unstructured":"M\u00e1rio S. Alvim, Konstantinos Chatzikokolakis, Yusuke Kawamoto, and Catuscia Palamidessi. 2017. Information leakage games. In Decision and Game Theory for Security. Springer, 437--457."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1257\/aer.100.3.984"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056602"},{"key":"e_1_2_1_6_1","unstructured":"J. Bowyer Bell and Barton Whaley. 2017. Cheating and Deception. Routledge."},{"key":"e_1_2_1_7_1","volume-title":"Counterdeception Principles and Applications for National Security","author":"Bennett Michael","unstructured":"Michael Bennett and Edward Waltz. 2007. Counterdeception Principles and Applications for National Security. Artech House."},{"key":"e_1_2_1_8_1","volume-title":"Reverse Deception: Organized Cyber Threat Counter-exploitation","author":"Bodmer Sean","year":"2012","unstructured":"Sean Bodmer, Max Kilger, Gregory Carpenter, and Jade Jones. 2012. Reverse Deception: Organized Cyber Threat Counter-exploitation. McGraw Hill Professional."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1037\/0033-2909.134.4.477"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.242"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-47413-7_2"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2015.14"},{"key":"e_1_2_1_13_1","volume-title":"Encyclopedia Britannica","author":"Chisholm Hugh","unstructured":"Hugh Chisholm. 1911. Predicables. In Encyclopedia Britannica (11th ed.). Cambridge University Press.","edition":"11"},{"key":"e_1_2_1_14_1","volume-title":"Decision and Game Theory for Security","author":"Clark Andrew","unstructured":"Andrew Clark, Quanyan Zhu, Radha Poovendran, and Tamer Ba\u015far. 2012. Deceptive routing in relay networks. In Decision and Game Theory for Security. Springer, 171--185."},{"key":"e_1_2_1_15_1","unstructured":"Hugh Cott. 1940. Adaptive Coloration in Animals. Methuen."},{"key":"e_1_2_1_16_1","volume-title":"Crawford and Joel Sobel","author":"Vincent","year":"1982","unstructured":"Vincent P. Crawford and Joel Sobel. 1982. Strategic information transmission. Econometrica: J of the Econometric Soc. (1982), 1431--1451."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3057268"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/2832249.2832322"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyw003"},{"key":"e_1_2_1_20_1","volume-title":"Decision and Game Theory for Security","author":"Feng Xiaotao","unstructured":"Xiaotao Feng, Zizhan Zheng, Prasant Mohapatra, and Derya Cansever. 2017. A Stackelberg game and Markov modeling of moving target defense. In Decision and Game Theory for Security. Springer, 315--335."},{"key":"e_1_2_1_21_1","first-page":"28","article-title":"Friend or \u201cFaux\u201d: Deception for cyber defense","volume":"16","author":"Ferguson-Walter K. J.","year":"2017","unstructured":"K. J. Ferguson-Walter, D. S. LaFon, and T. B. Shade. 2017. Friend or \u201cFaux\u201d: Deception for cyber defense. J. Info. Warfare 16, 2 (2017), 28--42. https:\/\/www.jstor.org\/stable\/26502755.","journal-title":"J. Info. Warfare"},{"key":"e_1_2_1_22_1","volume-title":"Competitive Markov Decision Processes","author":"Filar Jerzy","unstructured":"Jerzy Filar and Koos Vrieze. 2012. Competitive Markov Decision Processes. Springer Science 8 Business Media, New York."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1111\/jeea.12014"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653702"},{"key":"e_1_2_1_25_1","unstructured":"D. Fudenberg and J. Tirole. 1991. Game Theory. MIT Press."},{"key":"e_1_2_1_26_1","first-page":"1","article-title":"The cognitive interview for suspects (CIS)","volume":"30","author":"Geiselman R. Edward","year":"2012","unstructured":"R. Edward Geiselman. 2012. The cognitive interview for suspects (CIS). Amer. Coll. Forensic Psychol. 30, 3 (2012), 1--16.","journal-title":"Amer. Coll. Forensic Psychol."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1257\/0002828053828662"},{"key":"e_1_2_1_28_1","volume-title":"Wirtz","author":"Godson Roy","year":"2011","unstructured":"Roy Godson and James J. Wirtz. 2011. Strategic Denial and Deception: The Twenty-first Century Challenge. Transaction Publishers."},{"key":"e_1_2_1_29_1","volume-title":"\u201cscary","author":"Grosser Benjamin","unstructured":"Benjamin Grosser. 2014. Privacy through visibility: Disrupting NSA surveillance with algorithmically generated \u201cscary\u201d stories. University of Wisconsin-Milwaukee. Retrieved from https:\/\/bengrosser.com\/projects\/scaremail\/."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.5555\/2857298"},{"key":"e_1_2_1_31_1","volume-title":"Decision and Game Theory for Security","author":"Hor\u00e1k Karel","unstructured":"Karel Hor\u00e1k, Quanyan Zhu, and Branislav Bo\u0161ansk\u00fd. 2017. Manipulating adversary\u2019s belief: A dynamic game approach to deception by design in network security. In Decision and Game Theory for Security. Springer, 273--294."},{"key":"e_1_2_1_32_1","first-page":"417","article-title":"TrackMeNot: Resisting surveillance in web search. Lessons Ident. Trail: Anon., Priv","volume":"23","author":"Howe Daniel C.","year":"2009","unstructured":"Daniel C. Howe and Helen Nissenbaum. 2009. TrackMeNot: Resisting surveillance in web search. Lessons Ident. Trail: Anon., Priv., Ident. Netw. Soc. 23 (2009), 417--436. Retrieved from http:\/\/www.nyu.edu\/pages\/projects\/nissenbaum\/papers\/ch23(HoweNissenbaum)Web.pdf.","journal-title":"Ident. Netw. Soc."},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10683-008-9208-2"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1287\/inte.1100.0505"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.1467-937X.2009.00559.x"},{"key":"e_1_2_1_36_1","volume-title":"Cyber Warfare","author":"Kiekintveld Christopher","unstructured":"Christopher Kiekintveld, Viliam Lis\u1ef3, and Radek P\u00edbil. 2015. Game-theoretic foundations for the strategic use of honeypots in network security. In Cyber Warfare. Springer, 81--101."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2011.2162864"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1037\/h0046060"},{"key":"e_1_2_1_39_1","volume-title":"The Stanford Encyclopedia of Philosophy (winter 2016 ed.), Edward N","author":"Mahon James Edwin","unstructured":"James Edwin Mahon. 2016. The definition of lying and deception. In The Stanford Encyclopedia of Philosophy (winter 2016 ed.), Edward N. Zalta (Ed.)."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2480741.2480742"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1614320.1614358"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.2307\/3003562"},{"key":"e_1_2_1_43_1","unstructured":"MITRE. 2010. Science of cyber-security. https:\/\/fas.org\/irp\/agency\/dod\/jason\/cyber.pdf."},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-47413-7_22"},{"key":"e_1_2_1_45_1","volume-title":"Game Theory: Analysis of Conflict","author":"Myerson Roger B.","year":"1991","unstructured":"Roger B. Myerson. 1991. Game Theory: Analysis of Conflict. Harvard University Press."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.36.1.48"},{"key":"e_1_2_1_47_1","unstructured":"NISO. 2005. Guidelines for the construction format and management of monolingual controlled vocabularies. https:\/\/groups.niso.org\/apps\/group_public\/download.php\/12591\/z39-19-2005r2010.pdf."},{"key":"e_1_2_1_48_1","first-page":"119","article-title":"Privacy as contextual integrity","volume":"79","author":"Nissenbaum Helen","year":"2004","unstructured":"Helen Nissenbaum. 2004. Privacy as contextual integrity. Wash. Law Rev. 79 (2004), 119.","journal-title":"Wash. Law Rev."},{"key":"e_1_2_1_49_1","volume-title":"Proceedings of the Conference on Semantic Technology for Defense, Intelligence, and Security (STIDS\u201914)","author":"Oltramari Alessandro","unstructured":"Alessandro Oltramari, Lorrie Faith Cranor, Robert J. Walls, and Patrick D. McDaniel. 2014. Building an ontology of cyber security. In Proceedings of the Conference on Semantic Technology for Defense, Intelligence, and Security (STIDS\u201914). 54--61."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2886472"},{"key":"e_1_2_1_51_1","volume-title":"Decision and Game Theory for Security","author":"Pawlick Jeffrey","unstructured":"Jeffrey Pawlick, Sadegh Farhang, and Quanyan Zhu. 2015. Flip the cloud: Cyber-physical signaling games in the presence of advanced persistent threats. In Decision and Game Theory for Security. Springer, 289--308."},{"key":"e_1_2_1_52_1","volume-title":"Proceedings of the Workshop on the Economics of Inform. Security and Privacy","author":"Pawlick Jeffrey","year":"2015","unstructured":"Jeffrey Pawlick and Quanyan Zhu. 2015. Deception by design: Evidence-based signaling games for network defense. In Proceedings of the Workshop on the Economics of Inform. Security and Privacy. Delft, The Netherlands. http:\/\/arxiv.org\/abs\/1503.05458"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/WIFS.2016.7823893"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2017.8308697"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2725224"},{"key":"e_1_2_1_56_1","first-page":"85","article-title":"Regulating the Internet of things: First steps toward managing discrimination, privacy, security and consent","volume":"93","author":"Peppet Scott R.","year":"2014","unstructured":"Scott R. Peppet. 2014. Regulating the Internet of things: First steps toward managing discrimination, privacy, security and consent. Tex. L. Rev. 93 (2014), 85. Retrieved from http:\/\/heinonlinebackup.com\/hol-cgi-bin\/getpdf.cgi?handle&equals;hein.J.s\/tlr938section&equals;5.","journal-title":"Tex. L. Rev."},{"key":"e_1_2_1_57_1","volume-title":"Decision and Game Theory for Security","author":"P\u00edbil Radek","unstructured":"Radek P\u00edbil, Viliam Lis\u1ef3, Christopher Kiekintveld, Branislav Bo\u0161ansk\u1ef3, and Michal Pechoucek. 2012. Game theoretic model of strategic honeypot selection in computer networks. In Decision and Game Theory for Security. Springer, 201--220."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.5555\/1402795.1402819"},{"key":"e_1_2_1_59_1","volume-title":"Decision and Game Theory for Security","author":"Rass Stefan","unstructured":"Stefan Rass, Sandra K\u00f6nig, and Stefan Schauer. 2017. On the cost of game playing: How to control the expenses in mixed strategies. In Decision and Game Theory for Security. Springer, 495--505."},{"key":"e_1_2_1_60_1","volume-title":"The Art and Science of Military Deception","author":"Rothstein Hy","unstructured":"Hy Rothstein and Barton Whaley. 2013. The Art and Science of Military Deception. Artech House."},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the International Conference on Information Warfare and Security","author":"Rowe Neil C.","year":"2006","unstructured":"Neil C. Rowe. 2006. A taxonomy of deception in cyberspace. In Proceedings of the International Conference on Information Warfare and Security (2006)."},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.5555\/3017661"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.5555\/1748111.1748149"},{"key":"e_1_2_1_64_1","volume-title":"Decision and Game Theory for Security","author":"Sengupta Sailik","unstructured":"Sailik Sengupta, Ankur Chowdhary, Dijiang Huang, and Subbarao Kambhampati. 2018. Moving target defense for the placement of intrusion detection systems in the cloud. In Decision and Game Theory for Security. Springer, 326--345."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.5555\/2343576.2343578"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2015-0024"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2665943.2665946"},{"key":"e_1_2_1_68_1","volume-title":"Marktform und Gleichgewicht","author":"Stackelberg Heinrich Von","unstructured":"Heinrich Von Stackelberg. 1934. Marktform und Gleichgewicht. Springer."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10979-007-9103-y"},{"key":"e_1_2_1_70_1","volume-title":"Practise to Deceive: Learning Curves of Military Deception Planners","author":"Whaley Barton","unstructured":"Barton Whaley. 2016. Practise to Deceive: Learning Curves of Military Deception Planners. Naval Institute Press."},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.5555\/1947915.1947921"},{"key":"e_1_2_1_72_1","volume-title":"Proceedings of the 18th International Conference on Information Fusion (Fusion\u201915)","author":"Zhang Rui","year":"2015","unstructured":"Rui Zhang and Quanyan Zhu. 2015. Secure and resilient distributed machine learning under adversarial environments. In Proceedings of the 18th International Conference on Information Fusion (Fusion\u201915). IEEE, 644--651."},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2017.7926118"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-02786-9_15"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2012.6426515"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejor.2009.07.028"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3337772","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3337772","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3337772","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T13:24:40Z","timestamp":1750857880000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3337772"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,8,30]]},"references-count":76,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,7,31]]}},"alternative-id":["10.1145\/3337772"],"URL":"https:\/\/doi.org\/10.1145\/3337772","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,8,30]]},"assertion":[{"value":"2017-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-05-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-08-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}