arXiv:2411.10918cs.CRcs.AI2024-11被引 5

用大模型从文档提取物理规律,自动检测工控系统异常

INVARLLM: LLM-assisted Physical Invariant Extraction for Cyber-Physical Systems Anomaly Detection

  • 用大模型解析工控文档,生成可解释的物理不变性规则
  • 在SWaT和WADI数据集上实现100%精确率,零误报
  • 适合需要高可靠性且需可解释性的工业安全场景

工控系统(CPS)易受违反物理规律的网络物理攻击。基于不变性的异常检测虽有效,但现有方法受限:数据驱动方法缺乏语义上下文,物理模型需大量人工工作。本文提出INVARLLM,一种混合框架,利用大语言模型(LLM)从工控文档中提取语义信息并生成物理不变性规则,再通过受PCMCI+启发的K-means方法在真实系统数据上进行验证。该方法结合了LLM的语义理解与实证验证,确保规则可解释且可靠。在SWaT和WADI数据集上评估,实现100%精确率,无误报,优于所有现有方法。结果表明,将LLM生成的语义与统计验证相结合,能提供可扩展且可靠的工控系统安全解决方案。

原文摘要 · Abstract (English)

Cyber-Physical Systems (CPS) are vulnerable to cyber-physical attacks that violate physical laws. While invariant-based anomaly detection is effective, existing methods are limited: data-driven approaches lack semantic context, and physics-based models require extensive manual work. We propose INVARLLM, a hybrid framework that uses large language models (LLMs) to extract semantic information from CPS documentation and generate physical invariants, then validates these against real system data using a PCMCI+-inspired K-means method. This approach combines LLM semantic understanding with empirical validation to ensure both interpretability and reliability. We evaluate INVARLLM on SWaT and WADI datasets, achieving 100% precision in anomaly detection with no false alarms, outperforming all existing methods. Our results demonstrate that integrating LLM-derived semantics with statistical validation provides a scalable and dependable solution for CPS security.

工控安全大模型不变性检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。