用大模型分析物联网攻击,实现检测与应对的量化评估。
LLM-based Multi-class Attack Analysis and Mitigation Framework in IoT/IIoT Networks
- 结合机器学习检测攻击,大模型分析行为并提建议。
- 随机森林检测准确率最高,ChatGPT-o3分析能力更强。
- 首次建立可量化的评估体系,适合安全研究者参考。
物联网快速扩展,带来巨大安全挑战。人工智能在攻击检测、行为分析和缓解建议中发挥关键作用,但现有评估多为定性,缺乏标准化定量基准。本文提出混合框架:用机器学习进行多类攻击检测,大语言模型(LLM)进行行为分析与建议生成。在Edge-IIoTset和CICIoT2023数据集上对比多种ML/DL分类器后,采用结构化提示工程与检索增强生成(RAG)引导ChatGPT-o3和DeepSeek-R1生成上下文感知响应。引入新评估指标,并通过多个判别型LLM(包括ChatGPT-4o、DeepSeek-V3、Mixtral 8x7B Instruct、Gemini 2.5 Flash、Meta Llama 4、TII Falcon H1 34B Instruct、xAI Grok 3、Claude 4 Sonnet)独立评估结果。实验表明,随机森林在检测任务中表现最优,且ChatGPT-o3在攻击分析与缓解建议方面优于DeepSeek-R1。
原文摘要 · Abstract (English)
The Internet of Things has expanded rapidly, transforming communication and operations across industries but also increasing the attack surface and security breaches. Artificial Intelligence plays a key role in securing IoT, enabling attack detection, attack behavior analysis, and mitigation suggestion. Despite advancements, evaluations remain purely qualitative, and the lack of a standardized, objective benchmark for quantitatively measuring AI-based attack analysis and mitigation hinders consistent assessment of model effectiveness. In this work, we propose a hybrid framework combining Machine Learning (ML) for multi-class attack detection with Large Language Models (LLMs) for attack behavior analysis and mitigation suggestion. After benchmarking several ML and Deep Learning (DL) classifiers on the Edge-IIoTset and CICIoT2023 datasets, we applied structured role-play prompt engineering with Retrieval-Augmented Generation (RAG) to guide ChatGPT-o3 and DeepSeek-R1 in producing detailed, context-aware responses. We introduce novel evaluation metrics for quantitative assessment to guide us and an ensemble of judge LLMs, namely ChatGPT-4o, DeepSeek-V3, Mixtral 8x7B Instruct, Gemini 2.5 Flash, Meta Llama 4, TII Falcon H1 34B Instruct, xAI Grok 3, and Claude 4 Sonnet, to independently evaluate the responses. Results show that Random Forest has the best detection model, and ChatGPT-o3 outperformed DeepSeek-R1 in attack analysis and mitigation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。