arXiv:2509.20190cs.CRcs.AI2025-09中稿 · 23rd escar Europe被引 3

用大模型自动生成汽车安全测试用例,提升效率与准确性

STAF: Leveraging LLMs for Automated Attack Tree-Based Security Test Generation

  • 基于大模型和自校正检索增强生成框架,自动从攻击树生成测试用例
  • 相比通用模型,本方法在准确性与可执行性上显著提升,支持全流程集成
  • 适合汽车安全开发团队快速构建自动化测试体系

在现代汽车开发中,安全测试对抵御日益复杂的威胁至关重要。攻击树被广泛用于系统化表示潜在攻击路径,但从中生成全面的测试用例仍依赖人工,易出错,且在车载系统测试中自动化程度有限。本文提出STAF(安全测试自动化框架),利用大语言模型(LLMs)和四步自校正检索增强生成(RAG)框架,实现从攻击树到可执行安全测试用例的自动化生成,提供覆盖完整攻击面的端到端解决方案。特别展示了使大模型生成合理且可执行的汽车安全测试套件所需的关键要素与流程,并实现了与自动化测试框架的集成。通过对比使用本方法与通用大模型(vanilla LLMs)及不同模型(GPT-4.1与DeepSeek)的表现,验证了其在效率、准确率、可扩展性方面的显著优势。在具体案例研究中逐步演示了操作流程。结果表明,该方法极大提升了自动化安全测试的能力,为汽车安全开发中的验证测试提供了有效协同。

原文摘要 · Abstract (English)

In modern automotive development, security testing is critical for safeguarding systems against increasingly advanced threats. Attack trees are widely used to systematically represent potential attack vectors, but generating comprehensive test cases from these trees remains a labor-intensive, error-prone task that has seen limited automation in the context of testing vehicular systems. This paper introduces STAF (Security Test Automation Framework), a novel approach to automating security test case generation. Leveraging Large Language Models (LLMs) and a four-step self-corrective Retrieval-Augmented Generation (RAG) framework, STAF automates the generation of executable security test cases from attack trees, providing an end-to-end solution that encompasses the entire attack surface. We particularly show the elements and processes needed to provide an LLM to actually produce sensible and executable automotive security test suites, along with the integration with an automated testing framework. We further compare our tailored approach with general purpose (vanilla) LLMs and the performance of different LLMs (namely GPT-4.1 and DeepSeek) using our approach. We also demonstrate the method of our operation step-by-step in a concrete case study. Our results show significant improvements in efficiency, accuracy, scalability, and easy integration in any workflow, marking a substantial advancement in automating automotive security testing methodologies. Using TARAs as an input for verfication tests, we create synergies by connecting two vital elements of a secure automotive development process.

安全测试大模型汽车安全自动化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。