Bytecore1/ai-deception-openenv
๐ก๏ธ AI Cyber Deception OpenEnv
Overview
AI Cyber Deception OpenEnv is a real-world cybersecurity simulation environment where an AI agent learns to detect, deceive, and mitigate cyber attacks.
This environment simulates production-like cybersecurity defense scenarios including brute force attacks, port scanning, SQL injection, directory traversal, and credential stuffing.
The environment follows the OpenEnv specification and supports:
reset()step()state()
๐ฏ Real-World Task
Simulate cybersecurity defense in a production-like environment:
- Detect brute force attacks
- Detect port scanning
- Detect SQL injection
- Detect directory traversal
- Deploy deception mechanisms
- Block malicious attackers
โ๏ธ Action Space
The AI agent can perform the following actions:
detect_attackdeploy_honeypotfake_databaseblock_ip
๐๏ธ Observation Space
Environment returns structured observation:
failed_loginsport_scanssuspicious_ipstotal_requestsattack_types
๐ง Tasks
Easy Task
Detect cyber attack
Goal:
- Detect suspicious activity
- Identify attack patterns
Medium Task
Detect attack and deploy deception
Goal:
- Detect cyber attack
- Deploy honeypot or fake database
Hard Task
Full cyber defense workflow
Goal:
- Detect attack
- Deploy deception
- Block attacker
๐ Reward Function
Reward range normalized between 0.0 โ 1.0
๐ API Endpoints
Available endpoints:
/reset/step/state/logs/status
Example:
POST /reset POST /step GET /state
๐ Run Locally
Install dependencies:
pip install -r requirements.txt
Run inference:
python inference.py
๐ณ Docker
Build:
docker build -t ai-deception .
Run:
docker run -p 7860:7860 ai-deception
๐ค Hugging Face Deployment
Live Space:
https://bytecore1-ai-deception-openenv.hf.space/
Endpoints:
https://bytecore1-ai-deception-openenv.hf.space/reset
https://bytecore1-ai-deception-openenv.hf.space/state
https://bytecore1-ai-deception-openenv.hf.space/status
https://bytecore1-ai-deception-openenv.hf.space/logs
๐ Baseline Results
Example run:
[START] task=easy env=ai-deception-openenv model=Qwen
[STEP] step=1 action=detect_attack reward=0.45 done=false error=null
[STEP] step=2 action=deploy_honeypot reward=0.30 done=false error=null
[STEP] step=3 action=block_ip reward=0.70 done=true error=null
[END] success=true steps=3 score=0.48 rewards=0.45,0.30,0.70
๐๏ธ Architecture
Attacker
โ
Fake Server
โ
AI Agent (Inference)
โ
Defense Actions
โ
Reward
๐ฆ Project Structure
ai-deception-openenv/
โ
โโโ env/
โ โโโ __init__.py
โ โโโ attacker.py
โ โโโ deception.py
โ โโโ env.py
โ โโโ fake_server.py
โ โโโ test_env.py
โ โโโ test_server.py
โ
โโโ tasks/
โ โโโ __init__.py
โ โ
โ โโโ easy/
โ โ โโโ __init__.py
โ โ โโโ task.py
โ โ โโโ grader.py
โ โ
โ โโโ medium/
โ โ โโโ __init__.py
โ โ โโโ task.py
โ โ โโโ grader.py
โ โ
โ โโโ hard/
โ โ โโโ __init__.py
โ โ โโโ task.py
โ โ โโโ grader.py
โ โ
โ โโโ test_tasks.py
โ
โโโ server/
โ โโโ app.py
โ
โโโ inference.py
โโโ app.py
โโโ models.py
โโโ openenv.yaml
โโโ Dockerfile
โโโ requirements.txt
โโโ pyproject.toml
โโโ uv.lock
โโโ README.md
โโโ LICENSE
โโโ .gitignore
โโโ .gitattributes
โ
OpenEnv Compliance
reset() implemented
step() implemented
state() implemented
Docker support
Structured logs
Multiple tasks
Reward normalization
๐จโ๐ป Use Case
This environment can be used for:
Cybersecurity research
Reinforcement learning
AI defense strategy training
Red team vs blue team simulations
๐ก๏ธ AI Cyber Deception
This project demonstrates how AI can:
Detect attackers
Deploy deception
Block malicious actors
Learn defensive strategies
License
MIT License
