arXiv:2504.04187cs.CRcs.LG2025-04被引 15

用大模型自动生成工业控制系统攻击模式,提升安全检测能力。

AttackLLM: LLM-based Attack Pattern Generation for an Industrial Control System

  • 基于多智能体框架,利用大语言模型生成攻击模式。
  • 生成的攻击模式数量和质量均超过人工设计。
  • 无需昂贵测试平台,适合快速构建安全评估数据集。

恶意样本对评估机器学习算法在攻击下的鲁棒性至关重要,尤其在工业控制系统(ICS)中。然而,由于测试平台稀缺且人工专家成本高昂,获取正常与攻击数据极为困难。现有数据集受限于实践者的领域知识,导致过程成本高、效率低。缺乏全面的攻击模式数据严重制约了异常检测方法的发展。本文提出一种结合数据驱动与设计驱动的方法,利用大语言模型(LLMs)生成攻击模式。实验表明,由大模型生成的攻击模式在质量和数量上均优于人工设计,且不依赖昂贵测试平台或已有攻击样本,具有可扩展性。该多智能体方法为提升ICS环境的安全性与韧性提供了有效路径。

原文摘要 · Abstract (English)

Malicious examples are crucial for evaluating the robustness of machine learning algorithms under attack, particularly in Industrial Control Systems (ICS). However, collecting normal and attack data in ICS environments is challenging due to the scarcity of testbeds and the high cost of human expertise. Existing datasets are often limited by the domain expertise of practitioners, making the process costly and inefficient. The lack of comprehensive attack pattern data poses a significant problem for developing robust anomaly detection methods. In this paper, we propose a novel approach that combines data-centric and design-centric methodologies to generate attack patterns using large language models (LLMs). Our results demonstrate that the attack patterns generated by LLMs not only surpass the quality and quantity of those created by human experts but also offer a scalable solution that does not rely on expensive testbeds or pre-existing attack examples. This multi-agent based approach presents a promising avenue for enhancing the security and resilience of ICS environments.

工业控制大模型攻击生成安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。