用检索增强生成提升多智能体网络安全响应的决策能力
AutoBnB-RAG: Enhancing Multi-Agent Incident Response with Retrieval-Augmented Generation
- 让智能体在调查中检索技术文档或事故报告以补充知识
- 相比基础模型,决策准确率和任务成功率显著提升
- 适合研究智能体协同与网络安全自动化响应的人看
网络事件响应需要快速、协调且基于充分信息的决策来遏制威胁。尽管大语言模型在模拟环境中展现为自主智能体的潜力,但其推理常受限于缺乏外部知识访问。本文提出 AutoBnB-RAG,是 AutoBnB 框架的扩展,将检索增强生成(RAG)引入多智能体事件响应仿真。基于 Backdoors & Breaches(B&B)桌面游戏环境,AutoBnB-RAG 使智能体可发起检索查询并融入外部证据进行协作调查。我们设计两种检索模式:一种基于整理的技术文档(RAG-Wiki),另一种使用叙事风格的事件报告(RAG-News)。在八种团队结构下评估表现,包括新引入的促进批判性推理的辩论式配置。为验证实际价值,我们还基于公开泄露报告模拟真实网络事件,展示 AutoBnB-RAG 重建复杂多阶段攻击的能力。结果表明,检索增强在不同组织模型下均提升了决策质量与成功率。本工作证明,在基于 LLM 的多智能体系统中集成检索机制对网络安全决策具有重要价值。
原文摘要 · Abstract (English)
Incident response (IR) requires fast, coordinated, and well-informed decision-making to contain and mitigate cyber threats. While large language models (LLMs) have shown promise as autonomous agents in simulated IR settings, their reasoning is often limited by a lack of access to external knowledge. In this work, we present AutoBnB-RAG, an extension of the AutoBnB framework that incorporates retrieval-augmented generation (RAG) into multi-agent incident response simulations. Built on the Backdoors & Breaches (B&B) tabletop game environment, AutoBnB-RAG enables agents to issue retrieval queries and incorporate external evidence during collaborative investigations. We introduce two retrieval settings: one grounded in curated technical documentation (RAG-Wiki), and another using narrative-style incident reports (RAG-News). We evaluate performance across eight team structures, including newly introduced argumentative configurations designed to promote critical reasoning. To validate practical utility, we also simulate real-world cyber incidents based on public breach reports, demonstrating AutoBnB-RAG's ability to reconstruct complex multi-stage attacks. Our results show that retrieval augmentation improves decision quality and success rates across diverse organizational models. This work demonstrates the value of integrating retrieval mechanisms into LLM-based multi-agent systems for cybersecurity decision-making.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。