arXiv:2502.15797cs.CRcs.AI2025-02被引 21

测试大模型在真实网络攻击中的能力,发现部分模型已能高效完成复杂攻防任务。

OCCULT: Evaluating Large Language Models for Offensive Cyber Operation Capabilities

  • 构建轻量评估框架OCCULT,可重复测试大模型的实战攻击能力。
  • DeepSeek-R1在攻防测试中正确率超90%,显著超越早期模型。
  • 适用于安全研究人员评估AI风险,尤其关注真实威胁场景下的潜在危害。

人工智能在网络安全对抗领域的应用被视为最具影响力、最具挑战性且最危险的领域之一。本文提出OCCULT框架,一种轻量级的实战化评估方法,使安全专家能够对大语言模型(LLM)或任何用于进攻性网络操作(OCO)的AI进行可重复、严谨的风险评估。我们还构建并评估了三个不同类型的OCO基准,作为该框架的示范案例。结果显示,当前大模型在真实威胁场景中的能力显著提升:在针对威胁行为者技能的多选题测试(TACTL)中,DeepSeek-R1模型正确率超过90%;在MITRE的高保真仿真环境CyberLayer中,Meta的Llama与Mistral的Mixtral系列模型相较早期模型表现大幅进步。该框架突破了传统‘全有或全无’测试局限,实现对风险指标的上下文化分析。

原文摘要 · Abstract (English)

The prospect of artificial intelligence (AI) competing in the adversarial landscape of cyber security has long been considered one of the most impactful, challenging, and potentially dangerous applications of AI. Here, we demonstrate a new approach to assessing AI's progress towards enabling and scaling real-world offensive cyber operations (OCO) tactics in use by modern threat actors. We detail OCCULT, a lightweight operational evaluation framework that allows cyber security experts to contribute to rigorous and repeatable measurement of the plausible cyber security risks associated with any given large language model (LLM) or AI employed for OCO. We also prototype and evaluate three very different OCO benchmarks for LLMs that demonstrate our approach and serve as examples for building benchmarks under the OCCULT framework. Finally, we provide preliminary evaluation results to demonstrate how this framework allows us to move beyond traditional all-or-nothing tests, such as those crafted from educational exercises like capture-the-flag environments, to contextualize our indicators and warnings in true cyber threat scenarios that present risks to modern infrastructure. We find that there has been significant recent advancement in the risks of AI being used to scale realistic cyber threats. For the first time, we find a model (DeepSeek-R1) is capable of correctly answering over 90% of challenging offensive cyber knowledge tests in our Threat Actor Competency Test for LLMs (TACTL) multiple-choice benchmarks. We also show how Meta's Llama and Mistral's Mixtral model families show marked performance improvements over earlier models against our benchmarks where LLMs act as offensive agents in MITRE's high-fidelity offensive and defensive cyber operations simulation environment, CyberLayer.

大模型安全攻防测试网络威胁

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。