arXiv:2507.04752cs.CRcs.AI2025-07被引 16

用大模型提升网络入侵检测的智能与可解释性

Large Language Models for Network Intrusion Detection Systems: Foundations, Implementations, and Future Directions

论文配图:Large Language Models for Network Intrusion Detection Systems: Foundations, Implementations, and Future Directions
图 1 · 摘自论文原文
  • 将大模型用于处理结构化与非结构化安全数据,实现上下文推理
  • 构建以大模型为核心的控制器,协调检测流程并优化系统性能
  • 适合关注智能安全、可解释检测的科研与工程人员

大语言模型(LLMs)在理解、处理和生成类人文本方面展现出卓越能力。本文探讨了LLMs在推进网络入侵检测系统(NIDS)中的潜力,分析当前挑战、方法及未来机遇。传统智能NIDS依赖机器学习和深度学习识别已知模式,但缺乏上下文感知与可解释性。认知型NIDS则引入LLMs,融合处理结构化与非结构化安全数据,实现深层上下文推理、可解释决策与自动化响应。文中详细阐述了LLMs在检测流程中作为处理器、检测器与解释器的应用,并提出以LLM为中心的控制器概念,强调其在协调检测工作流、优化工具协同与系统性能方面的潜力。最后,论文指出了关键挑战与发展方向,旨在推动更可靠、自适应且可解释的下一代NIDS研发。

原文摘要 · Abstract (English)

Large Language Models (LLMs) have revolutionized various fields with their exceptional capabilities in understanding, processing, and generating human-like text. This paper investigates the potential of LLMs in advancing Network Intrusion Detection Systems (NIDS), analyzing current challenges, methodologies, and future opportunities. It begins by establishing a foundational understanding of NIDS and LLMs, exploring the enabling technologies that bridge the gap between intelligent and cognitive systems in AI-driven NIDS. While Intelligent NIDS leverage machine learning and deep learning to detect threats based on learned patterns, they often lack contextual awareness and explainability. In contrast, Cognitive NIDS integrate LLMs to process both structured and unstructured security data, enabling deeper contextual reasoning, explainable decision-making, and automated response for intrusion behaviors. Practical implementations are then detailed, highlighting LLMs as processors, detectors, and explainers within a comprehensive AI-driven NIDS pipeline. Furthermore, the concept of an LLM-centered Controller is proposed, emphasizing its potential to coordinate intrusion detection workflows, optimizing tool collaboration and system performance. Finally, this paper identifies critical challenges and opportunities, aiming to foster innovation in developing reliable, adaptive, and explainable NIDS. By presenting the transformative potential of LLMs, this paper seeks to inspire advancement in next-generation network security systems.

大模型入侵检测可解释性智能安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。