用大模型检测无线网络攻击,还能解释原因并提应对建议。
Investigating cybersecurity incidents using large language models in latest-generation wireless networks
- 用大模型分析模拟的无线信号数据,识别恶意攻击
- Gemma-7b模型准确率达89%,可发现被污染数据异常
- 能解释判断依据,适合安全团队做决策支持
研究旨在基于现代生成式模型,检测网络安全事件,并评估应对措施的有效性。通过模拟MIMO系统中的信号传播数据,生成对抗样本并对机器学习模型实施攻击;对六种大语言模型进行微调以检测对抗攻击,并利用提示技术提升决策可解释性。研究首次采用大语言模型对数据投毒攻击进行二分类,验证其在最新一代无线网络中调查安全事件的可行性。实验结果表明,微调后的Gemma-7b模型在精度、召回率和F1分数上均达到0.89,能通过不同解释性提示识别数据异常、分析特征重要性,并提出缓解建议。结合二分类器的大语言模型在安全事件调查、辅助决策及效果评估方面具有显著应用潜力。
原文摘要 · Abstract (English)
The purpose of research: Detection of cybersecurity incidents and analysis of decision support and assessment of the effectiveness of measures to counter information security threats based on modern generative models. The methods of research: Emulation of signal propagation data in MIMO systems, synthesis of adversarial examples, execution of adversarial attacks on machine learning models, fine tuning of large language models for detecting adversarial attacks, explainability of decisions on detecting cybersecurity incidents based on the prompts technique. Scientific novelty: A binary classification of data poisoning attacks was performed using large language models, and the possibility of using large language models for investigating cybersecurity incidents in the latest generation wireless networks was investigated. The result of research: Fine-tuning of large language models was performed on the prepared data of the emulated wireless network segment. Six large language models were compared for detecting adversarial attacks, and the capabilities of explaining decisions made by a large language model were investigated. The Gemma-7b model showed the best results according to the metrics Precision = 0.89, Recall = 0.89 and F1-Score = 0.89. Based on various explainability prompts, the Gemma-7b model notes inconsistencies in the compromised data under study, performs feature importance analysis and provides various recommendations for mitigating the consequences of adversarial attacks. Large language models integrated with binary classifiers of network threats have significant potential for practical application in the field of cybersecurity incident investigation, decision support and assessing the effectiveness of measures to counter information security threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。