
DEF CON 33 - Decision Making in Adversarial Automation - Bobby Kuzma, Michael Odell
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 26:52
Revised Summary
This presentation by Bobby and Michael Odell (Moch) explores decision-making frameworks in adversarial contexts, beginning with relatable analogies like comparing deterministic blackjack players (who follow rules consistently) versus random players. The speakers introduce the concept of "stochastic parrots" (systems that merely regurgitate training data) versus "deterministic predators" (systems following predictable processes), establishing a foundation for understanding automated decision-making in adversarial environments like cybersecurity [0:00-3:30].
Key Takeaways:
• Adversarial OODA loops create time disadvantages: In cybersecurity, attackers and defenders operate in continuous "Observe, Orient, Decide, Act" cycles. When an attacker acts, they disrupt the defender's decision loop. The presenters illustrate this by noting that Security Operations Centers often have alert latencies of five minutes or more, while attackers can move rapidly through networks, potentially compromising multiple systems before defenders can respond [4:20-7:00].
• Decision frameworks depend on environment knowledge: Markov Decision Processes (MDPs) model environments with complete knowledge (like white box assessments), while Partially Observable MDPs (POMDPs) address scenarios with incomplete information (like black box assessments). The speakers use the analogy of Atari games for MDPs (where the screen state, available actions, and scoring system are completely known) versus real-world networks where unknown factors must be considered [7:00-10:30].
• Multiple decision-making approaches with different trade-offs: The presentation compares various models including:
- Stochastic methods (random action selection)
- Deterministic approaches (always choosing the maximum quality action)
- Policy gradients (continuous decision surfaces)
- Boltzmann exploration (quality-weighted probabilistic selection)
- Decision trees (algorithmic check
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So, um, thank first off, thank you for coming. I know almost everyone wants to be either napping in a coma or in some kind of stuper around here at this point. So, I do appreciate that. Um, we are going to be talking about uh decision-m and adversarial automation. Um, I do have to give you a quick warning. Um, this does contain math. Um, I understand that some people have a very fraught relationship with math. And to quote my mother-in-law, math isn't supposed to have symbols or letters. So, we'll we'll try to keep that to the minimum. Um, I'm Bobby. I'm a dad, husband, nerd. I chase rockets when I'm not breaking things. Uh, Michael Odell or I go by Moch sometimes. I'm just a nerd that happens to work with him that he thought I'd be good for this talk. So, it's pleasure to meet you. He he …