Using Hypergames and Spiking Neural Networks to Defend IoT Systems Against Malware
Published:
Malware propagation presents a continuing threat to Internet of Things (IoT) systems. Defence is particularly challenging when attackers and defenders have different or incomplete perceptions of the system and cannot accurately observe each other’s intentions.
This blog post discusses our paper, Integrating Deep Spiking Q-Network Into Hypergame-Theoretic Deceptive Defense for Mitigating Malware Propagation in Edge Intelligence-Enabled IoT Systems https://doi.org/10.1109/TSC.2025.3562355, published in IEEE Transactions on Services Computing.
Why is asymmetric information important?
Many security models assume that attackers and defenders have a common understanding of the environment. In practice, their perceptions may differ. A defender may not know which devices an attacker intends to compromise, while an attacker may have an incomplete understanding of the defender’s detection and response capabilities.
These differences influence the strategies selected by both sides. Modelling malware defence as a conventional game may therefore overlook uncertainty, misperception, and deception.
What did we propose?
We developed a Deception-Oriented Hypergame-Theoretic Malware Propagation-Mitigation model, called DHMPM. It represents the strategic interaction between IoT nodes and edge devices under asymmetric information.
In this model, IoT nodes and edge devices continually adjust their strategies according to their perceived beliefs, available utilities, and changes in the environment.
We then integrated spiking neural networks with a Deep Q-Network to produce a Hypergame-Theoretic Deep Spiking Q-Network, or HGDSQN. The resulting method learns practical deceptive defence strategies for mitigating malware propagation.
What did we find?
Our simulation experiments examined how factors such as attack arrival probability and learning rate affected strategy selection. The results demonstrated the ability of HGDSQN to learn effective defensive decisions under the proposed hypergame model.
Using spiking neural networks also provides a mechanism for processing temporal information through event-driven communication, which may support responsive malware defence in dynamic IoT systems.
Perspective
The key idea is that cyber defence is not always a game in which both participants see the same board. Attackers and defenders may act on different beliefs and may intentionally influence one another’s perceptions.
Hypergame theory helps represent this imperfect understanding, while the learning component enables the defender to adapt its strategy over time.
The paper was co-authored with Yizhou Shen, Carlton Shepherd, Shigen Shen, and Shui Yu.
Reference
https://doi.org/10.1109/TSC.2025.3562355. IEEE Transactions on Services Computing 18, 3 (2025), 1487–1499. https://doi.org/10.1109/TSC.2025.3562355
