Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Jayasankar Kumar Santhirani, Deivanai Shankar, Arjun Shetty, Karthik Venkatesh, Jesmilan Jesu · Team Saarlanders
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range featuring a legitimate workload, an unscripted attacker, and a policy engine enforcing deny-only actions, the research compares no defense, a stateful static playbook, and an AI defender across 40 measured episodes and four controls. The empirical results demonstrate that the static playbook prevented secret retrieval in all eight of its episodes, whereas the AI defender allowed retrieval in three of eight episodes with a fixed canary and four of eight with adaptive placement, while also inflicting greater availability losses on legitimate traffic. When the attacker adapted by switching routes post-block, both defenders successfully achieved containment in every instance, with the AI defender responding within a median of one to seven seconds compared to the playbook's twenty-one seconds. Ultimately, the study shows that in this environment, within-incident adaptation did not reduce overall attack success or impact compared to a fixed policy, leading to a proposed Adaptive Containment Requirement (ACR) emphasizing bounded authority and third-party verifiable conformance.
Reviews
- There are some unsubstantiated claims "Each containment action taken was a fixed, one-shot intervention, and the attacker adapted around it faster than a human loop could react"
- the idea of adaptive containment is good and currently being researched, more investigations into different ways to implement this are welcome
- It is hard to say conclusive things about this idea because there are so many ways for the offensive team to try and escape, as well as many ways for the defensive team to try and prevent this escape.
- Significant LLM-written signs, this makes me less likely to read the full project as closely as I would otherwise
- it's unmotivated and unclear why Gemini 3.7 Flash with low reasoning effort was used as the defender but GLM-5.3 (reasoning effort unspecified) was used as the attacker.
- the experiment design and cyber range is quite complicated, making it difficult to figure out which are necessary parts and which are incidental (AI written?) complications.
Read full reviewShow less
What makes this approach compelling is how it pairs static playbooks and canary credentials with an LLM defender without over-privileging the model. Enforcing bounded authority—where the LLM proposes deny-only actions validated by an independent policy gate, backed by a deterministic playbook fallback—delivers fast, auditable containment via telemetry logs while keeping blast radiuses strictly contained. It strikes a pragmatic balance between adaptive reasoning and reliable, production-ready safety guardrails
Cite this project
@misc{santhirani2026adaptive,
title = {{Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study}},
author = {Jayasankar Kumar Santhirani and Deivanai Shankar and Arjun Shetty and Karthik Venkatesh and Jesmilan Jesu},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/adaptive-aibased-containment-of-autonomous-cyber-attacks-a-reproducible-docker-cyber-range-study-9kk3}},
url = {https://apartresearch.com/sprints/projects/adaptive-aibased-containment-of-autonomous-cyber-attacks-a-reproducible-docker-cyber-range-study-9kk3}
}More from AI Incident Response Sprint
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …
- View project: When to Ask: An RL Environment That Teaches AI Agents to Act on What Users Mean and Not Just What They Say
When to Ask: An RL Environment That Teaches AI Agents to Act on What Users Mean and Not Just What They Say
Teachafy
When to Ask is a reinforcement-learning environment that trains AI agents to work out what the user actually means before they use a powerful credential, instead of just carrying out the literal instruction. Agents …