用大模型实现多步证据检索与推理,提升网络威胁情报可信度验证准确率。
LRCTI: A Large Language Model-Based Framework for Multi-Step Evidence Retrieval and Reasoning in Cyber Threat Intelligence Credibility Verification
- 基于大模型分步处理:摘要提炼、迭代检索证据、提示驱动推理
- 在两个数据集上F1-Macro达90.9%,比现有方法提升超5%
- 结果可解释,适合需要透明决策的网络安全场景
验证网络威胁情报(CTI)的可信度对可靠网络安全防御至关重要。传统方法通常将此任务视为静态分类问题,依赖手工特征或孤立的深度学习模型,难以应对不完整、异构或嘈杂的情报信息,且决策过程缺乏透明度,限制了其在真实威胁环境中的有效性。为此,我们提出LRCTI,一个基于大语言模型(LLM)的多步CTI可信度验证框架。该框架首先通过文本摘要模块将复杂情报报告提炼为简洁可操作的威胁声明;随后采用自适应多步证据检索机制,基于LLM反馈从专用CTI语料库中迭代识别并精炼支持性信息;最后利用提示式自然语言推理(NLI)模块评估每条声明的可信度,并生成可解释的判断依据。在两个基准数据集CTI-200和PolitiFact上的实验表明,相比最先进基线,LRCTI在F1-Macro和F1-Micro上分别提升超过5%,分别达到90.9%和93.6%。结果表明,LRCTI有效克服了以往方法的核心局限,提供了一种可扩展、高精度且可解释的自动化CTI可信度验证方案。
原文摘要 · Abstract (English)
Verifying the credibility of Cyber Threat Intelligence (CTI) is essential for reliable cybersecurity defense. However, traditional approaches typically treat this task as a static classification problem, relying on handcrafted features or isolated deep learning models. These methods often lack the robustness needed to handle incomplete, heterogeneous, or noisy intelligence, and they provide limited transparency in decision-making-factors that reduce their effectiveness in real-world threat environments. To address these limitations, we propose LRCTI, a Large Language Model (LLM)-based framework designed for multi-step CTI credibility verification. The framework first employs a text summarization module to distill complex intelligence reports into concise and actionable threat claims. It then uses an adaptive multi-step evidence retrieval mechanism that iteratively identifies and refines supporting information from a CTI-specific corpus, guided by LLM feedback. Finally, a prompt-based Natural Language Inference (NLI) module is applied to evaluate the credibility of each claim while generating interpretable justifications for the classification outcome. Experiments conducted on two benchmark datasets, CTI-200 and PolitiFact show that LRCTI improves F1-Macro and F1-Micro scores by over 5%, reaching 90.9% and 93.6%, respectively, compared to state-of-the-art baselines. These results demonstrate that LRCTI effectively addresses the core limitations of prior methods, offering a scalable, accurate, and explainable solution for automated CTI credibility verification
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。