arXiv:2509.06920cs.CRcs.AI2025-09被引 2

用大模型生成真实感内鬼威胁日志,提升检测准确率。

An Ethically Grounded LLM-Based Approach to Insider Threat Synthesis and Detection

  • 用Claude Sonnet 3.7动态生成含内鬼特征的日志数据
  • 在1%极不平衡数据下实现高召回与低误报
  • 适合安全研究者和风控系统开发者参考

内鬼威胁因技术与行为特征复杂而日益严峻。现有研究多依赖静态、受限的数据集,难以支持自适应检测模型发展。本文提出一种基于大语言模型(LLM)Claude Sonnet 3.7的伦理合规方法,动态合成包含内鬼威胁指标的syslog消息,数据分布贴近现实(1%内鬼样本)。通过对比Sonnet 3.7与GPT-4o在准确率、精确率、召回率、F1、特异性、误报率、马修相关系数及ROC AUC等指标的表现,发现前者在几乎所有指标上均优于后者,尤其在降低误报和提升检测精度方面表现突出。结果表明,大模型在合成数据生成与内鬼检测中具有显著潜力。

原文摘要 · Abstract (English)

Insider threats are a growing organizational problem due to the complexity of identifying their technical and behavioral elements. A large research body is dedicated to the study of insider threats from technological, psychological, and educational perspectives. However, research in this domain has been generally dependent on datasets that are static and limited access which restricts the development of adaptive detection models. This study introduces a novel, ethically grounded approach that uses the large language model (LLM) Claude Sonnet 3.7 to dynamically synthesize syslog messages, some of which contain indicators of insider threat scenarios. The messages reflect real-world data distributions by being highly imbalanced (1% insider threats). The syslogs were analyzed for insider threats by both Sonnet 3.7 and GPT-4o, with their performance evaluated through statistical metrics including accuracy, precision, recall, F1, specificity, FAR, MCC, and ROC AUC. Sonnet 3.7 consistently outperformed GPT-4o across nearly all metrics, particularly in reducing false alarms and improving detection accuracy. The results show strong promise for the use of LLMs in synthetic dataset generation and insider threat detection.

内鬼检测大模型日志生成安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。