用可解释AI和大模型实现物联网实时攻防,让安全决策更透明可信。
An Adaptive End-to-End IoT Security Framework Using Explainable AI and LLMs
- 融合机器学习、可解释AI与大模型,实现攻击检测与响应的端到端闭环。
- 在CIC-IOT-2023数据集上,Gemini和OpenAI LLM分别提供精准与全面的防御策略。
- 通过SHAP/LIME解析特征贡献,帮助优化模型并提升检测准确率。
物联网的指数级增长显著增加了网络安全威胁的复杂性和规模,亟需开发先进、可扩展且可解释的安全框架。本文提出一个创新的端到端框架,用于实时物联网攻击检测与响应,融合了机器学习(ML)、可解释人工智能(XAI)和大语言模型(LLM)。通过集成SHAP(SHapley Additive exPlanations)和LIME(Local Interpretable Model-agnostic Explanations)等XAI技术,并采用模型无关架构,确保框架在不同机器学习算法间的适应性。同时,引入LLM增强了检测决策的可解释性与可读性,为系统管理员提供可操作的人类可理解威胁说明。该框架不仅实现了从模型开发到部署的无缝过渡,还具备实际应用能力,弥补了现有研究的不足。基于对CIC-IOT-2023数据集的实验,Gemini和OpenAI LLM在攻击缓解中展现出独特优势:Gemini提供精确聚焦的策略,而OpenAI则给出全面深入的安全措施。在XAI中融入SHAP与LIME算法,为攻击检测提供了全面洞察,强调通过详细特征分析、微调及误分类适配来提升模型性能。
原文摘要 · Abstract (English)
The exponential growth of the Internet of Things (IoT) has significantly increased the complexity and volume of cybersecurity threats, necessitating the development of advanced, scalable, and interpretable security frameworks. This paper presents an innovative, comprehensive framework for real-time IoT attack detection and response that leverages Machine Learning (ML), Explainable AI (XAI), and Large Language Models (LLM). By integrating XAI techniques such as SHAP (SHapley Additive exPlanations) and LIME (Local Interpretable Model-agnostic Explanations) with a model-independent architecture, we ensure our framework's adaptability across various ML algorithms. Additionally, the incorporation of LLMs enhances the interpretability and accessibility of detection decisions, providing system administrators with actionable, human-understandable explanations of detected threats. Our end-to-end framework not only facilitates a seamless transition from model development to deployment but also represents a real-world application capability that is often lacking in existing research. Based on our experiments with the CIC-IOT-2023 dataset \cite{neto2023ciciot2023}, Gemini and OPENAI LLMS demonstrate unique strengths in attack mitigation: Gemini offers precise, focused strategies, while OPENAI provides extensive, in-depth security measures. Incorporating SHAP and LIME algorithms within XAI provides comprehensive insights into attack detection, emphasizing opportunities for model improvement through detailed feature analysis, fine-tuning, and the adaptation of misclassifications to enhance accuracy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。