arXiv · 2609.26797
Calibrated Bait: Defensive Information Design under Adversarial Fingerprinting
Abstract
A honeytoken, a decoy credential or record whose use reveals an intruder, produces defence intelligence only if an adversary sometimes treats it as genuine. The adversary can instead pay to fingerprint it. I model this problem as information design followed by receiver information acquisition. Without fingerprinting, a defender whose installed trap prevalence exceeds the adversary's participation boundary places the attacked pool exactly at that boundary: calibrated bait. That posterior also maximises the gross value of any fixed informative diagnostic with finitely many signal outcomes. For a perfect covert test, the resulting appearance design has a closed-form, prior-dependent characterisation: expensive testing preserves calibrated bait, intermediate-cost testing produces under-calibrated bait, and cheap testing yields pooling, protected segmentation or abstention. Free and costless adjustment of trap prevalence makes non-degenerate segmentation unnecessary, but a sufficiently large adjustment cost around a sufficiently high inherited composition can sustain it. Finally, along an exogenously declining fingerprinting-cost path, lower cost reduces trap activation without reducing genuine compromise within the under-calibrated regime. Evaluation against fresh attackers can therefore overstate the durability of reusable bait.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Joshua S. Gans. 2026-08-14. Calibrated Bait: Defensive Information Design under Adversarial Fingerprinting. https://arxiv.org/abs/2609.26797
Cite the original work for its findings. Save a collection to share your selection of sources.