arXiv:2507.06252cs.CRcs.AI2025-07被引 4

用伪造文本攻击文本类威胁情报系统,让其误判真实威胁。

False Alarms, Real Damage: Adversarial Attacks Using LLM-based Models on Text-based Cyber Threat Intelligence Systems

  • 用大模型生成欺骗性文本干扰威胁情报分类
  • 三种攻击方式破坏系统信息筛选能力,尤其规避检测最致命
  • 适合关注AI安全与网络安全交叉的从业者阅读

网络威胁情报(CTI)已成为网络安全早期阶段的关键补充手段,通过收集、处理和分析威胁数据,实现对网络威胁的快速准确识别。面对海量数据,机器学习(ML)与自然语言处理(NLP)模型在自动化提取中至关重要。这些系统依赖来自社交媒体、论坛和博客等开源情报(OSINT)来源,以识别恶意行为指标(IoCs)。尽管已有研究聚焦特定模型的对抗攻击,本文拓展至整个CTI流程中多个组件的漏洞,并评估其对对抗攻击的敏感性。由于系统接收来自各类开放源的文本输入(含真实与虚假内容),存在被攻击风险。本文分析了三类攻击:逃避、淹没与投毒,评估其对系统信息选择能力的影响。重点展示:利用对抗文本生成技术可构造出伪装成安全相关的内容,误导分类器、降低性能并破坏系统功能。其中,逃避攻击尤为关键,因其为后续的淹没与投毒攻击铺路。

原文摘要 · Abstract (English)

Cyber Threat Intelligence (CTI) has emerged as a vital complementary approach that operates in the early phases of the cyber threat lifecycle. CTI involves collecting, processing, and analyzing threat data to provide a more accurate and rapid understanding of cyber threats. Due to the large volume of data, automation through Machine Learning (ML) and Natural Language Processing (NLP) models is essential for effective CTI extraction. These automated systems leverage Open Source Intelligence (OSINT) from sources like social networks, forums, and blogs to identify Indicators of Compromise (IoCs). Although prior research has focused on adversarial attacks on specific ML models, this study expands the scope by investigating vulnerabilities within various components of the entire CTI pipeline and their susceptibility to adversarial attacks. These vulnerabilities arise because they ingest textual inputs from various open sources, including real and potentially fake content. We analyse three types of attacks against CTI pipelines, including evasion, flooding, and poisoning, and assess their impact on the system's information selection capabilities. Specifically, on fake text generation, the work demonstrates how adversarial text generation techniques can create fake cybersecurity and cybersecurity-like text that misleads classifiers, degrades performance, and disrupts system functionality. The focus is primarily on the evasion attack, as it precedes and enables flooding and poisoning attacks within the CTI pipeline.

对抗攻击威胁情报大模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。