Team Ai
Apppublic

Bytecore1/ai-deception-openenv

sourceHugging Faceupdated 6mo agoView on Hugging Face
0likes
App README

๐Ÿ›ก๏ธ AI Cyber Deception OpenEnv

Overview

AI Cyber Deception OpenEnv is a real-world cybersecurity simulation environment where an AI agent learns to detect, deceive, and mitigate cyber attacks.

This environment simulates production-like cybersecurity defense scenarios including brute force attacks, port scanning, SQL injection, directory traversal, and credential stuffing.

The environment follows the OpenEnv specification and supports:

  • โ€”reset()
  • โ€”step()
  • โ€”state()

๐ŸŽฏ Real-World Task

Simulate cybersecurity defense in a production-like environment:

  • โ€”Detect brute force attacks
  • โ€”Detect port scanning
  • โ€”Detect SQL injection
  • โ€”Detect directory traversal
  • โ€”Deploy deception mechanisms
  • โ€”Block malicious attackers

โš™๏ธ Action Space

The AI agent can perform the following actions:

  • โ€”detect_attack
  • โ€”deploy_honeypot
  • โ€”fake_database
  • โ€”block_ip

๐Ÿ‘๏ธ Observation Space

Environment returns structured observation:

  • โ€”failed_logins
  • โ€”port_scans
  • โ€”suspicious_ips
  • โ€”total_requests
  • โ€”attack_types

๐Ÿง  Tasks

Easy Task

Detect cyber attack

Goal:

  • โ€”Detect suspicious activity
  • โ€”Identify attack patterns

Medium Task

Detect attack and deploy deception

Goal:

  • โ€”Detect cyber attack
  • โ€”Deploy honeypot or fake database

Hard Task

Full cyber defense workflow

Goal:

  • โ€”Detect attack
  • โ€”Deploy deception
  • โ€”Block attacker

๐Ÿ† Reward Function

ActionReward
detect_attack0.15โ€“0.45
deploy_honeypot0.30
fake_database0.20
block_ip (correct)0.70
early block0.05

Reward range normalized between 0.0 โ€“ 1.0


๐ŸŒ API Endpoints

Available endpoints:

  • โ€”/reset
  • โ€”/step
  • โ€”/state
  • โ€”/logs
  • โ€”/status

Example:

POST /reset POST /step GET /state


๐Ÿš€ Run Locally

Install dependencies:

bash
pip install -r requirements.txt

Run inference:

python inference.py
๐Ÿณ Docker

Build:

docker build -t ai-deception .

Run:

docker run -p 7860:7860 ai-deception
๐Ÿค— Hugging Face Deployment

Live Space:

https://bytecore1-ai-deception-openenv.hf.space/

Endpoints:

https://bytecore1-ai-deception-openenv.hf.space/reset

https://bytecore1-ai-deception-openenv.hf.space/state

https://bytecore1-ai-deception-openenv.hf.space/status

https://bytecore1-ai-deception-openenv.hf.space/logs

๐Ÿ“Š Baseline Results

Example run:

[START] task=easy env=ai-deception-openenv model=Qwen
[STEP] step=1 action=detect_attack reward=0.45 done=false error=null
[STEP] step=2 action=deploy_honeypot reward=0.30 done=false error=null
[STEP] step=3 action=block_ip reward=0.70 done=true error=null
[END] success=true steps=3 score=0.48 rewards=0.45,0.30,0.70
๐Ÿ—๏ธ Architecture
Attacker
   โ†“
Fake Server
   โ†“
AI Agent (Inference)
   โ†“
Defense Actions
   โ†“
Reward
๐Ÿ“ฆ Project Structure

ai-deception-openenv/
โ”‚
โ”œโ”€โ”€ env/
โ”‚   โ”œโ”€โ”€ __init__.py
โ”‚   โ”œโ”€โ”€ attacker.py
โ”‚   โ”œโ”€โ”€ deception.py
โ”‚   โ”œโ”€โ”€ env.py
โ”‚   โ”œโ”€โ”€ fake_server.py
โ”‚   โ”œโ”€โ”€ test_env.py
โ”‚   โ””โ”€โ”€ test_server.py
โ”‚
โ”œโ”€โ”€ tasks/
โ”‚   โ”œโ”€โ”€ __init__.py
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ easy/
โ”‚   โ”‚   โ”œโ”€โ”€ __init__.py
โ”‚   โ”‚   โ”œโ”€โ”€ task.py
โ”‚   โ”‚   โ””โ”€โ”€ grader.py
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ medium/
โ”‚   โ”‚   โ”œโ”€โ”€ __init__.py
โ”‚   โ”‚   โ”œโ”€โ”€ task.py
โ”‚   โ”‚   โ””โ”€โ”€ grader.py
โ”‚   โ”‚
โ”‚   โ”œโ”€โ”€ hard/
โ”‚   โ”‚   โ”œโ”€โ”€ __init__.py
โ”‚   โ”‚   โ”œโ”€โ”€ task.py
โ”‚   โ”‚   โ””โ”€โ”€ grader.py
โ”‚   โ”‚
โ”‚   โ””โ”€โ”€ test_tasks.py
โ”‚
โ”œโ”€โ”€ server/
โ”‚   โ””โ”€โ”€ app.py
โ”‚
โ”œโ”€โ”€ inference.py
โ”œโ”€โ”€ app.py
โ”œโ”€โ”€ models.py
โ”œโ”€โ”€ openenv.yaml
โ”œโ”€โ”€ Dockerfile
โ”œโ”€โ”€ requirements.txt
โ”œโ”€โ”€ pyproject.toml
โ”œโ”€โ”€ uv.lock
โ”œโ”€โ”€ README.md
โ”œโ”€โ”€ LICENSE
โ”œโ”€โ”€ .gitignore
โ””โ”€โ”€ .gitattributes

โœ… OpenEnv Compliance
reset() implemented
step() implemented
state() implemented
Docker support
Structured logs
Multiple tasks
Reward normalization
๐Ÿ‘จโ€๐Ÿ’ป Use Case

This environment can be used for:

Cybersecurity research
Reinforcement learning
AI defense strategy training
Red team vs blue team simulations
๐Ÿ›ก๏ธ AI Cyber Deception

This project demonstrates how AI can:

Detect attackers
Deploy deception
Block malicious actors
Learn defensive strategies
License

MIT License