ACDZero: Graph-Embedding-Based Tree Search for Mastering Automated Cyber Defense
Jan 1, 2026·,
,,,,,
Yu Li
Sizhe Tang
Rongqian Chen
Fei Xu Yu
Guangyu Jiang
Mahdi Imani
Nathaniel D Bastian
Tian Lan

TL;DR
ACDZero masters automated cyber defense by pairing Monte Carlo Tree Search with graph-neural-network embeddings of the network state — a planning-centric alternative to deep RL that achieves better defense reward, robustness, and sample efficiency.
Key contributions:
- Frames automated cyber defense as a POMDP and solves it with MCTS guided by learned graph embeddings, balancing exploration and exploitation.
- GNN-based, permutation-invariant reasoning over hosts and their relationships as attributed graphs.
- Policy distillation with look-ahead planning, yielding improved defense reward and robustness over state-of-the-art RL baselines across CAGE Challenge 4 scenarios.
BibTeX
@article{li2026acdzero,
title={ACDZero: Graph-Embedding-Based Tree Search for Mastering Automated Cyber Defense},
author={Li, Yu and Tang, Sizhe and Chen, Rongqian and Yu, Fei Xu and Jiang, Guangyu and Imani, Mahdi and Bastian, Nathaniel D and Lan, Tian},
journal={arXiv preprint arXiv:2601.02196},
year={2026}
}