Evidence of Cognitive Biases in Capture-the-Flag Cybersecurity Competitions
By: Carolina Carreira , Anu Aggarwal , Alejandro Cuevas and more
Potential Business Impact:
Helps computers learn how hackers think.
Understanding how cognitive biases influence adversarial decision-making is essential for developing effective cyber defenses. Capture-the-Flag (CTF) competitions provide an ecologically valid testbed to study attacker behavior at scale, simulating real-world intrusion scenarios under pressure. We analyze over 500,000 submission logs from picoCTF, a large educational CTF platform, to identify behavioral signatures of cognitive biases with defensive implications. Focusing on availability bias and the sunk cost fallacy, we employ a mixed-methods approach combining qualitative coding, descriptive statistics, and generalized linear modeling. Our findings show that participants often submitted flags with correct content but incorrect formatting (availability bias), and persisted in attempting challenges despite repeated failures and declining success probabilities (sunk cost fallacy). These patterns reveal that biases naturally shape attacker behavior in adversarial contexts. Building on these insights, we outline a framework for bias-informed adaptive defenses that anticipate, rather than simply react to, adversarial actions.
Similar Papers
A Human Study of Cognitive Biases in Web Application Security
Cryptography and Security
Makes learning to hack safer by tricking minds.
A Case Study on the Use of Representativeness Bias as a Defense Against Adversarial Cyber Threats
Cryptography and Security
Tricks hackers' minds to stop cyberattacks.
Guarding Against Malicious Biased Threats (GAMBiT): Experimental Design of Cognitive Sensors and Triggers with Behavioral Impact Analysis
Cryptography and Security
Tricks hackers' minds to stop cyberattacks.