arXiv:2506.20806cs.CRcs.AI2025-06中稿 · the 10th IEEE Euro…被引 1

用AI专家代理分析图结构,提升GNN在真实攻击下的检测鲁棒性。

Poster: Enhancing GNN Robustness for Network Intrusion Detection via Agent-based Analysis

  • 引入LLM代理模拟安全专家,提前识别图数据中的可疑节点
  • 在物理测试床数据上验证,显著提升GNN对各类对抗攻击的抵抗能力
  • 适用于需要高可信度的物联网入侵检测场景

图神经网络(GNN)在物联网环境下的网络入侵检测系统中展现出巨大潜力,但因分布漂移和缺乏对现实对抗攻击的鲁棒性而性能下降。现有鲁棒性评估常依赖不切实际的合成扰动,且缺乏对黑盒与白盒攻击等不同攻击类型的系统性分析。本文提出一种新方法,通过大型语言模型(LLM)构建智能体管道,作为模拟网络安全专家,在GNN处理前对网络流量生成的图结构进行审视,识别并可能缓解可疑或对抗性扰动元素。实验基于真实评估框架,采用多种对抗攻击,包括来自物理测试床的实测数据集,结果表明集成LLM分析可显著增强基于GNN的入侵检测系统的韧性,凸显了LLM智能体作为入侵检测架构中互补层的潜力。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) show great promise for Network Intrusion Detection Systems (NIDS), particularly in IoT environments, but suffer performance degradation due to distribution drift and lack robustness against realistic adversarial attacks. Current robustness evaluations often rely on unrealistic synthetic perturbations and lack demonstrations on systematic analysis of different kinds of adversarial attack, which encompass both black-box and white-box scenarios. This work proposes a novel approach to enhance GNN robustness and generalization by employing Large Language Models (LLMs) in an agentic pipeline as simulated cybersecurity expert agents. These agents scrutinize graph structures derived from network flow data, identifying and potentially mitigating suspicious or adversarially perturbed elements before GNN processing. Our experiments, using a framework designed for realistic evaluation and testing with a variety of adversarial attacks including a dataset collected from physical testbed experiments, demonstrate that integrating LLM analysis can significantly improve the resilience of GNN-based NIDS against challenges, showcasing the potential of LLM agent as a complementary layer in intrusion detection architectures.

GNN入侵检测LLM代理对抗鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。