1) The document describes a model for scalable learning of intrusion response through recursive decomposition. It involves a defender protecting an infrastructure of connected components from an attacker seeking to intrude.
2) The system is modeled as a directed tree where each component has states related to defense, attack, and risk. The defender takes actions to maintain workflows and stop intrusions, while the attacker aims to disrupt workflows and compromise components.
3) Components are organized into workflows and the defender and attacker choose actions based on partial observations from intrusion detection systems. The problem is formulated as a Stackelberg game to find strategies that maximize the defender's objectives while minimizing the attacker's objectives.
Related topics: