用可视化工具让大模型异常检测结果更透明,提升安全人员理解效率
AnomalyExplainer Explainable AI for LLM-based anomaly detection using BERTViz and Captum
- 结合BERTViz与Captum生成注意力热图和解释报告
- RoBERTa在HDFS数据集上达99.6%准确率,优于Falcon-7B等模型
- 适合需要快速理解模型决策的安全分析师使用
对话式AI与大语言模型在网络安全领域广泛应用,可提前发现威胁并加快响应。但误报率高、模型难管理等问题仍影响信任度。本文提出一种结合BERTViz与Captum的可解释AI框架,通过注意力可视化和自然语言报告提供高质量解释,降低人工分析负担,加速问题修复。对比实验表明,RoBERTa在LogHub的HDFS数据集上达到99.6%准确率,优于Falcon-7B和DeBERTa,且比Mistral-7B更具灵活性。用户反馈显示该聊天机器人易用性强,显著提升了对异常行为的理解能力,验证了该框架在增强网络安全工作流中的有效性。
原文摘要 · Abstract (English)
Conversational AI and Large Language Models (LLMs) have become powerful tools across domains, including cybersecurity, where they help detect threats early and improve response times. However, challenges such as false positives and complex model management still limit trust. Although Explainable AI (XAI) aims to make AI decisions more transparent, many security analysts remain uncertain about its usefulness. This study presents a framework that detects anomalies and provides high-quality explanations through visual tools BERTViz and Captum, combined with natural language reports based on attention outputs. This reduces manual effort and speeds up remediation. Our comparative analysis showed that RoBERTa offers high accuracy (99.6 %) and strong anomaly detection, outperforming Falcon-7B and DeBERTa, as well as exhibiting better flexibility than large-scale Mistral-7B on the HDFS dataset from LogHub. User feedback confirms the chatbot's ease of use and improved understanding of anomalies, demonstrating the ability of the developed framework to strengthen cybersecurity workflows.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。