用大模型实现多智能体自动攻防,提升响应效率与可解释性。
Large Language Models are Autonomous Cyber Defenders
- 将大语言模型融入多智能体攻防环境,实现协同决策。
- 实验表明大模型在可解释性上优于强化学习,但响应速度较慢。
- 提出新通信协议,适合安全研究者探索智能体协作新方向。
快速有效的事件响应对防范网络攻击至关重要。自主网络安全防御(ACD)通过人工智能代理进行规划和执行来实现自动化。现有ACD方法多聚焦单智能体场景,依赖强化学习(RL),但训练成本高,且推理过程缺乏可解释性与泛化能力。大语言模型(LLMs)可在通用安全场景中提供可解释的行动方案,弥补上述缺陷。尽管已有研究尝试将LLM代理用于ACD,但尚未在多智能体环境或与其他ACD代理交互的场景中评估。本文首次在CybORG CAGE 4环境中研究了多智能体ACD下LLM的表现,并提出一种新型通信协议,考察由LLM与RL代理组成的防御团队如何协同工作。结果揭示了两类模型的优势与局限,为未来团队型ACD代理的构建、训练与部署指明了有前景的研究方向。
原文摘要 · Abstract (English)
Fast and effective incident response is essential to prevent adversarial cyberattacks. Autonomous Cyber Defense (ACD) aims to automate incident response through Artificial Intelligence (AI) agents that plan and execute actions. Most ACD approaches focus on single-agent scenarios and leverage Reinforcement Learning (RL). However, ACD RL-trained agents depend on costly training, and their reasoning is not always explainable or transferable. Large Language Models (LLMs) can address these concerns by providing explainable actions in general security contexts. Researchers have explored LLM agents for ACD but have not evaluated them on multi-agent scenarios or interacting with other ACD agents. In this paper, we show the first study on how LLMs perform in multi-agent ACD environments by proposing a new integration to the CybORG CAGE 4 environment. We examine how ACD teams of LLM and RL agents can interact by proposing a novel communication protocol. Our results highlight the strengths and weaknesses of LLMs and RL and help us identify promising research directions to create, train, and deploy future teams of ACD agents.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。