arXiv:2506.12060cs.CRcs.AI2025-06被引 5

组织正通过混合流程适应生成式AI,提升安全防御能力。

Organizational Adaptation to Generative AI in Cybersecurity

  • 三类新模式:大模型应用、生成式AI风险响应、机器学习威胁匹配。
  • 金融与关键基础设施单位因成熟架构更易成功,中央银行引领变革。
  • 需关注数据质量、可解释性及人员培训,防范隐私与对抗攻击风险。

网络安全组织正通过调整框架与混合运营流程适应生成式AI,其成效受现有安全成熟度、监管要求及人力与基础设施投入影响。本研究基于2022至2025年25项文献的系统文档分析与比较案例研究,揭示威胁建模框架正从传统签名系统转向具备AI能力的模式,主要呈现三种趋势:大语言模型在安全场景的应用、生成式AI用于风险检测与响应自动化、人工智能/机器学习支持威胁狩猎与匹配。具备成熟基础设施的组织(如金融与关键基础设施领域)表现出更高适应力,体现于结构化治理、专职AI团队和强健的应急响应机制,其中央行与金融机构在监管压力下领先推进。成功整合依赖人工监督、数据质量与可解释性保障,且需制定行业特定治理策略,但隐私保护、偏见降低、人员培训与对抗防御仍存挑战。攻防能力失衡引发战略隐忧。研究为安全从业者提供可操作洞察,强调应对增强威胁需采用适应性方法、伦理框架与人才发展。

原文摘要 · Abstract (English)

Cybersecurity organizations are adapting to GenAI integration through modified frameworks and hybrid operational processes, with success influenced by existing security maturity, regulatory requirements, and investments in human capital and infrastructure. This qualitative research employs systematic document analysis and comparative case study methodology to examine how 25 studies from 2022 to 2025 document organizational adaptation of threat modeling frameworks, revealing a shift away from traditional signature-based systems toward AI-capable frameworks across three primary patterns: LLM integration for security applications, GenAI frameworks for risk detection and response automation, and AI/ML integration for threat hunting and matching. Organizations with mature infrastructures, particularly in finance and critical infrastructure, demonstrate higher readiness through structured governance, dedicated AI teams, and robust incident response processes, with central banks and financial institutions leading adaptation efforts under regulatory pressure. Successful integration requires human oversight of automated systems, attention to data quality and explainability, and sector-specific governance, though ongoing difficulties with privacy protection, bias reduction, personnel training, and adversarial defense persist. Notable imbalances between offensive and defensive GenAI capabilities create strategic concerns for security planning. The findings offer actionable insights for cybersecurity professionals and underscore the need for adaptive approaches, ethical frameworks, and staff development when managing AI-enhanced threats.

生成式AI安全防御组织适应威胁建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。