用GPT-2增强传统检测,提升物联网零日攻击识别能力
Hybrid LLM-Enhanced Intrusion Detection for Zero-Day Threats in IoT Networks
- 结合签名匹配与GPT-2语义分析,实现混合检测
- 准确率提升6.3%,误报率降低9.0%,响应接近实时
- 适合资源受限的物联网安全场景,具可扩展性
针对物联网(IoT)网络中日益复杂的零日攻击,本文提出一种融合传统签名检测与GPT-2大语言模型语义理解能力的混合入侵检测框架。在分布式、异构且资源受限的IoT环境中,传统方法虽能识别已知威胁,但难以发现新型攻击模式;而GPT-2擅长处理非结构化数据并捕捉复杂语义关系,有助于挖掘隐蔽的零日攻击特征。实验基于典型入侵数据集验证,所提方法使检测准确率提升6.3%,误报率下降9.0%,同时保持近实时响应性能。结果表明,将语言模型引入入侵检测可构建更智能、可扩展且鲁棒的安全防御体系。
原文摘要 · Abstract (English)
This paper presents a novel approach to intrusion detection by integrating traditional signature-based methods with the contextual understanding capabilities of the GPT-2 Large Language Model (LLM). As cyber threats become increasingly sophisticated, particularly in distributed, heterogeneous, and resource-constrained environments such as those enabled by the Internet of Things (IoT), the need for dynamic and adaptive Intrusion Detection Systems (IDSs) becomes increasingly urgent. While traditional methods remain effective for detecting known threats, they often fail to recognize new and evolving attack patterns. In contrast, GPT-2 excels at processing unstructured data and identifying complex semantic relationships, making it well-suited to uncovering subtle, zero-day attack vectors. We propose a hybrid IDS framework that merges the robustness of signature-based techniques with the adaptability of GPT-2-driven semantic analysis. Experimental evaluations on a representative intrusion dataset demonstrate that our model enhances detection accuracy by 6.3%, reduces false positives by 9.0%, and maintains near real-time responsiveness. These results affirm the potential of language model integration to build intelligent, scalable, and resilient cybersecurity defences suited for modern connected environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。