Joel Brynielsson

dblp:26/2403 · DBLP profile ↗
← Back
8ranked-venue papers in the field
3as first author
3since 2021 · last 2025
0000-0002-2677-9759ORCID · verified

Domains — venue-derived; a paper can count in several

Data Mining & Knowledge Discovery · 8 (3 first)
YearPublicationVenuePosition
2025 Strategic Steering of Large Language Models via Game-Theoretic Action Space Optimization
abstract
Abstract This paper investigates how large language models can be steered to act more strategically in text-based negotiation settings. Two prompt-based action space designs are compared, namely emotional tone prompts and explicit offer prompts, within a negotiation environment, and outcomes are compared in simulated dialogues. The results show that both approaches improve strategic outcomes compared to a baseline, with tone-based actions yielding higher agreement rates and offer-based actions providing more stable tradeoffs. These findings demonstrate how action space design influences agent behavior, providing insights for deployment of large language models in strategic negotiation scenarios to gain an advantage in, for example, online influence operations.
Samuel Lavebrink, Joel Brynielsson, Mika Cohen, Farzad Kamrani, Christoffer Limér, Madeleine Lindström, Marius Vangeli
ASONAM (3)2
2025 Outsmarting Willful-Thinking Opponents: Bayesian Belief Revision for Adversarial Reasoning in Large Language Models
abstract
Abstract In adversarial contexts, success often hinges on understanding not just what the opponent knows, but what they believe and how they revise those beliefs. This study investigates how large language models can be made more resilient and strategically capable by modeling the opponent’s reasoning using Bayesian belief revision. By formalizing negotiations as Bayesian games of incomplete information, it is shown that models equipped with belief revision are better able to counter deceptive or willful-thinking adversaries. The findings underscore the role of second-order reasoning in adversarial settings, with implications for social manipulation in the context of, for example, online communication and intelligence gathering.
Madeleine Lindström, Joel Brynielsson, Mika Cohen, Farzad Kamrani, Samuel Lavebrink, Christoffer Limér, Marius Vangeli
ASONAM (3)2
2023 Comparison of Strategies for Honeypot Deployment
abstract
Recent experimental studies have explored how well adaptive honeypot allocation strategies defend against human adversaries. As the experimental subjects were drawn from an unknown, nondescript pool of subjects using Amazon Mechanical Turk, the relevance to defense against real-world adversaries is unclear. The present study reproduces the experiments with more relevant experimental subjects. The results suggest that the strategies considered are less effective against attackers from the current population. In particular, their ability to predict the next attack decreased steadily over time, that is, the human subjects from this population learned to attack less and less predictably.
Joel Brynielsson, Mika Cohen, Patrik Hansen, Samuel Lavebrink, Madeleine Lindström, Edward Tjörnhammar
ASONAM1
2020 A Census of Swedish Government Administrative Authority Employee Communications on Cybersecurity during the COVID-19 Pandemic
abstract
Cybersecurity is the backbone of a successful digitalization of society, and cyber situation awareness is an essential aspect of managing it. The COVID-19 pandemic has sped up an already ongoing digitalization of Swedish government agencies, but the cybersecurity maturity level varies across agencies. In this study, we conduct a census of Swedish government administrative authority communications on cybersecurity to employees at the beginning of the COVID-19 pandemic. The census shows that the employee communications in the beginning of the pandemic to a greater extent have focused on first-order risks, such as video meetings and telecommuting, rather than on second-order risks, such as invoice fraud or social engineering. We also find that almost two thirds of the administrative authorities have not yet implemented, but only initiated or documented, their cybersecurity policies.
Annika Andreasson, Henrik Artman, Joel Brynielsson, Ulrik Franke
ASONAM3
2018 Information Requirements for National Level Cyber Situational Awareness
abstract
As modern societies become more dependent on IT services, the potential impact both of adversarial cyberattacks and non-adversarial service management mistakes grows. This calls for better cyber situational awareness-decision-makers need to know what is going on. The main focus of this paper is to examine the information elements that need to be collected and included in a common operational picture in order for stakeholders to acquire cyber situational awareness. This problem is addressed through a survey conducted among the participants of a national information assurance exercise conducted in Sweden. Most participants were government officials and employees of commercial companies that operate critical infrastructure. The results give insight into information elements that are perceived as useful, that can be contributed to and required from other organizations, which roles and stakeholders would benefit from certain information, and how the organizations work with creating cyber common operational pictures today. Among findings, it is noteworthy that adversarial behavior is not perceived as interesting, and that the respondents in general focus solely on their own organization.
Stefan Varga, Joel Brynielsson, Ulrik Franke
ASONAM2
2015 Detectability of Low-Rate HTTP Server DoS Attacks using Spectral Analysis
abstract
Denial-of-Service (DoS) attacks pose a threat to any service provider on the internet. While traditional DoS flooding attacks require the attacker to control at least as much resources as the service provider in order to be effective, so-called low-rate DoS attacks can exploit weaknesses in careless design to effectively deny a service using minimal amounts of network traffic.
Joel Brynielsson, Rishie Sharma
ASONAM1
2014 The security awareness paradox: A case study
abstract
Knowledge-intensive organizations are characterized by their dependency on highly skilled personnel who perform their daily work in a decentralized manner. In these organizations it is the users who make the important decisions, and therefore the organization's information security awareness is upheld by and depends on its users' combined security awareness. To assess the overall organizational security awareness it therefore becomes interesting to assess both the users' individual level of security awareness, as well as their level of consistency and conformity with regard to other users' awareness. In the present case study, 15 semi-structured interviews have been undertaken within a large telecommunication company in order to understand how significant IT security aspects are understood within the organization. The study highlights a number of perception differences where the technical IT staff and the ordinary users do not share the same understanding. It is suggested that these perception differences result from a paradoxical situation where the users' possibility to uphold security awareness is hindered because of security concerns.
Muhammad Adnan Tariq, Joel Brynielsson, Henrik Artman
ASONAM2
2010 Detecting Social Positions Using Simulation
abstract
Describing social positions and roles is an important topic within social network analysis. One approach is to compute a suitable equivalence relation on the nodes of the target network. One relation that is often used for this purpose is regular equivalence, or bisimulation, as it is known within the field of computer science. In this paper we consider a relation from computer science called simulation relation. Simulation creates a partial order on the set of actors in a network and we can use this order to identify actors that have characteristic properties. The simulation relation can also be used to compute simulation equivalence which is a less restrictive equivalence relation than regular equivalence but is still computable in polynomial time. This paper primarily considers weighted directed networks and we present definitions of both weighted simulation equivalence and weighted regular equivalence. Weighted networks can be used to model a number of network domains, including information flow, trust propagation, and communication channels. Many of these domains have applications within homeland security and in the military, where one wants to survey and elicit key roles within an organization. Identifying social positions can be difficult when the target organization lacks a formal structure or is partially hidden.
Joel Brynielsson, Johanna Björklund, Lisa Kaati, Christian Mårtenson, Pontus Svenson
ASONAM1