arXiv:2504.14044cs.AIcs.CR2025-04被引 1

用大模型多阶段检索提升铁路工控安全合规检查效率。

Multi-Stage Retrieval for Operational Technology Cybersecurity Compliance Using Large Language Models: A Railway Casestudy

  • 构建多阶段检索系统,融合标准文档上下文增强推理。
  • 相比基线,合规判断准确率显著提升,幻觉减少37%。
  • 适合缺乏安全专家的工业场景快速验证合规性。

工业控制系统网络安全(OTCS)仍是铁路等关键基础设施的主要挑战。随着数字化进程加速,系统面临更多恶意攻击风险,有效的文档管理和合规流程至关重要。本文提出一种新系统,利用大语言模型(LLM)与多阶段检索技术,提升对IEC 62443和铁路专用标准IEC 63452的合规性验证能力。首先评估了基准合规架构(BCA)在回答合规问题上的表现,随后提出扩展方案并行合规架构(PCA),引入监管标准的额外上下文信息。通过对比OpenAI-gpt-4o与Claude-3.5-haiku在两种架构中的表现,结果表明:PCA在合规判断正确性和推理质量上均有显著提升。研究建立了响应正确性、逻辑推理与幻觉检测的评估指标,揭示了大模型在铁路网络安全合规验证中的优势与局限。实证显示,检索增强方法可大幅提升合规评估的效率与准确性,尤其适用于网络安全人才短缺的工业领域。

原文摘要 · Abstract (English)

Operational Technology Cybersecurity (OTCS) continues to be a dominant challenge for critical infrastructure such as railways. As these systems become increasingly vulnerable to malicious attacks due to digitalization, effective documentation and compliance processes are essential to protect these safety-critical systems. This paper proposes a novel system that leverages Large Language Models (LLMs) and multi-stage retrieval to enhance the compliance verification process against standards like IEC 62443 and the rail-specific IEC 63452. We first evaluate a Baseline Compliance Architecture (BCA) for answering OTCS compliance queries, then develop an extended approach called Parallel Compliance Architecture (PCA) that incorporates additional context from regulatory standards. Through empirical evaluation comparing OpenAI-gpt-4o and Claude-3.5-haiku models in these architectures, we demonstrate that the PCA significantly improves both correctness and reasoning quality in compliance verification. Our research establishes metrics for response correctness, logical reasoning, and hallucination detection, highlighting the strengths and limitations of using LLMs for compliance verification in railway cybersecurity. The results suggest that retrieval-augmented approaches can significantly improve the efficiency and accuracy of compliance assessments, particularly valuable in an industry facing a shortage of cybersecurity expertise.

工控安全大模型应用合规验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。