arXiv:2510.13817cs.LGcs.NI2025-10被引 4

用大模型分析网络数据,自动识别海量物联网设备

What's on My Network? Using Large Language Models to Identify Real-World IoT Devices at Scale

  • 将设备识别转为语言建模任务,利用大模型从网络元数据中推断设备身份
  • 在2015个厂商上达到98.69%准确率,对缺失字段和欺骗数据仍稳健
  • 适合安全监控、网络管理等需大规模设备溯源的场景

共享环境中物联网设备的增长速度已超过识别能力,带来隐私、安全与问责风险。尤其在开放世界环境下,网络流量元数据常稀疏、嘈杂或受干扰。为此,我们提出一种语义推理流程,将设备识别重构为基于真实网络元数据的语言建模任务。为确保监督信号可靠,我们使用由互信息与熵稳定性评分指导的大型语言模型集成,构建了物联网检查器数据集(IoT Inspector)中最高保真度的厂商标签,该数据集是同类中规模最大的真实世界语料库。随后,我们采用课程学习法对量化版LLaMA 3.1 8B模型进行指令微调,以应对数据稀疏性和长尾厂商分布。模型在2,015个厂商上实现98.69%的top-1准确率和90.73%的宏平均准确率,且对字段缺失、协议漂移及对抗性操纵均保持鲁棒。我们在独立物联网测试平台数据集上评估模型性能,分析解释质量,并进行对抗测试以检验在伪造与混淆输入下的韧性。结果表明,指令微调的大模型可作为可扩展、可解释、可信的设备识别基础。

原文摘要 · Abstract (English)

The growth of IoT devices in shared environments has outpaced our ability to identify them, posing urgent risks to privacy, safety, and accountability. This challenge is especially pronounced in open-world environments, where network traffic metadata is often sparse, noisy, or adversarial. To address this problem, we introduce a semantic inference pipeline that reframes device identification as a language modeling task over real-world network metadata. As this approach depends on reliable supervision, we first construct high-fidelity vendor labels for the IoT Inspector dataset, the largest real-world corpus of its kind, using an ensemble of large language models guided by mutual-information and entropy-based stability scores. We then instruction-tune a quantized LLaMA 3.1 8B model on this dataset using curriculum learning to support generalization under sparsity and long-tail vendor distributions. Our model achieves 98.69% top-1 and 90.73% macro accuracy across 2,015 vendors, while remaining robust to missing fields, protocol drift, and adversarial manipulation. We also evaluate the model on an independent IoT testbed dataset, assess explanation quality, and conduct adversarial tests to probe robustness under spoofed and obfuscated input. These results position instruction-tuned LLMs as a scalable, interpretable foundation for trustworthy device identification at scale.

物联网安全大模型应用设备识别

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。