INQUIRING LINE

If fake decoys must look real to fool attackers, how long can an attacker keep poking before getting kicked out?

How do decoy-response bounds interact with finite-sample time constraints?

This explores how the price of making decoys convincing (a limit on how far trusted users can be separated from decoy-touchers) meets the race an attacker faces when probing gets them removed before they've seen enough.


This explores how two limits in decoy-based defense meet: how closely a decoy can imitate a genuine object, and how long an attacker can keep probing before being thrown out. The corpus holds three notes on this, and together they tell one story. The other nine retrievals (reward variance, sandbagging, inference budgets and so on) cover unrelated ground, so I've left them out.

Start with the attacker's best case. In an idealized setting, if decoys and genuine objects respond differently to probes, and probes don't set off any alarm, then repeating them separates the two with error that shrinks toward zero Can repeated quiet probes separate decoys from genuine objects?. Any difference in behavior, however small, gets found given enough quiet observations. So the defender's only real protection is to make the difference tiny.

That protection has a cost, and the cost falls on the defender's own side. The closer decoys match genuine objects, the smaller the gap between how often legitimate agents can use them and how often false alarms fire What cost does making decoys convincing impose on legitimate users?. A perfect decoy leaves trusted users no better off than intruders. The bound measures how much legitimate use you give up to make the disguise convincing.

The time constraint is what lets the defender keep some of that disguise cheap. Once probing can trigger containment, the attacker has to collect enough observations before removal, and a finite-sample bound puts a number on how fast a coalition must accumulate them How fast must a coalition gather observations before containment?. The corpus states each bound separately, so the link between them is my inference. The smaller the difference between decoy and genuine responses, the more probes the attacker needs, and the more of that clock they spend. A defender doesn't need decoys that are perfect forever. They need decoys good enough that the required sample size outruns the attacker's expected survival time.

So the trade-off has three parts. Sharper decoys cost legitimate users something. Sloppier decoys hand attackers a faster route to certainty. Faster or stricter containment shortens the window the attacker has. The zero-error result is a limit that assumes unlimited quiet probing, and containment is what takes that assumption away. That is why the finite-sample framing matters: it turns a question of whether attackers can ever tell the difference into a question of whether they can tell before they're removed.


Sources 3 notes

Can repeated quiet probes separate decoys from genuine objects?

In idealized settings with independent responses, enough quiet probes let a classifier separate decoys from genuine objects with vanishing error if their response distributions differ and are known or learnable from feedback.

What cost does making decoys convincing impose on legitimate users?

Making decoys look genuine to evade attackers forces a tradeoff: the closer decoys match genuine objects, the smaller the gap between legitimate use rates and false-alarm rates for trusted agents. This bound captures the cost paid by the protected side.

How fast must a coalition gather observations before containment?

When probing triggers containment, the attacker's challenge shifts to sample accumulation against time. A finite-sample bound establishes how many observations a coalition needs before removal, pricing the separation in temporal constraints.

Papers this line draws on 8

The research behind the notes this line reads — ranked by how closely each paper relates.