Cyber deception in Industrial Internet of Things (IIoT) environments faces a fundamental challenge, insufficient deception investment fails to trap attackers, while excessive deployment causes rational adversaries to accumulate skepticism, progressively neutralizing deceptive mechanisms. To the best of our knowledge, no existing reinforcement learning (RL) framework has jointly characterized the optimal deception investment level under these dynamics and trained against a co-evolutionary adversary that explicitly models skepticism accumulation. This paper introduces Co-ADAM, a Co-evolutionary Adaptive Deception-Aware Multi-mechanism defense framework that formalizes IIoT cyber deception as a constrained Markov decision process (CMDP) with an embedded signaling game. We establish that the co-evolutionary training will reach some equilibrium of skepticism (Lemma 1, Propositions 1, 2) and characterize the resulting joint policy as an ε -Nash deception equilibrium with exploitability ε = 2.4523 (4.43% normalized). A deep Q-network (DQN) defender is trained against an adaptive attacker pool of size K = 10 across 5000 episodes, with skepticism dynamics, attacker momentum, and budget constraints embedded directly in the environment. Compared to seven baselines over three IIoT datasets, CIC-IIoT 2025, WUSTL-IIoT 2021 and Edge-IIoTset, Co-ADAM attains an Attack Mitigation Rate (AMR) of 0.8363 under random and 0.8033 under adaptive attackers, with cumulative rewards of 147.91 and 102.52 respectively, all differences are statistically significant at p < 0.001. The learned policy transfers across heterogeneous IIoT environments with 99.61% mean AMR retention, scales to 1000 devices with less than 0.26% AMR degradation, and converges empirically at episode 1377. The most significant element of the architecture confirmed in ablation as adversarial skepticism (Cohen’s d = 3.57), forms the foundation of principled skepticism modeling as a critical component of deception-based IIoT defense. Physical validation on a 10-day IIoT testbed comprising a Centerm D660 honeypot, three ESP32 sensors, and a Kali Linux attack machine confirms simulation findings with testbed AMR of 0.9975 exceeding simulation AMR of 0.8363.
Authors would like to extend their appreciations to Princess Nourah bint Abdulrahman University Researchers Supporting Project number (PNURSP2026R235), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia, for supporting and funding this study. The author also acknowledges the support of the School of Computer Science and Technology at Chongqing University of Posts and Telecommunications for providing the computational resources and materials necessary for this research. The author also thanks the Canadian Institute for Cybersecurity (University of New Brunswick) for the CIC-IIoT-2025 dataset, Washington University in St. Louis for the WUSTL-IIoT-2021 dataset, and the authors of the Edge-IIoTset dataset for making these resources publicly available.
Princess Nourah bint Abdulrahman University Researchers Supporting Project number (PNURSP2026R235), Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia.
Usman Wushishi and Altaf Hussain have contributed equally to this work and are co-first authors.
School of Computer Science and Technology, Chongqing University of Posts and Telecommunications, Chongqing, 400065, China
Usman Wushishi, Nasir Hussain & Altaf Hussain
Department of Information Systems, College of Computer and Information Sciences, Princess Nourah Bint Abdulrahman University, P.O. Box 84428, 11671, Riyadh, Saudi Arabia
Information Systems Department, College of Computer and Information Sciences, Imam Mohammad Ibn Saud Islamic University (IMSIU), 11432, Riyadh, Saudi Arabia
author on: PubMed Google Scholar
author on: PubMed Google Scholar
author on: PubMed Google Scholar
author on: PubMed Google Scholar
author on: PubMed Google Scholar
Correspondence to Altaf Hussain .
The authors declare no competing interests.
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit .
Reprints and permissions
Wushishi, U., Hussain, N., Hussain, A. et al. Co-ADAM: a co-evolutionary signaling game framework for equilibrium cyber deception in industrial IoT. Sci Rep (2026).
Received : 30 March 2026
Accepted : 30 June 2026
Published : 06 July 2026
DOI :
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
