arXiv:2511.05406cs.CL2025-11被引 2

用大模型+检索增强生成,让威胁情报分析更透明可解释。

Large Language Models for Explainable Threat Intelligence

  • 结合实时检索与领域数据,用大模型回答安全威胁问题。
  • 最佳组合下回复准确率超91%,显著提升分析可靠性。
  • 自动生成知识图谱可视化推理路径,适合安全分析师使用。

随着网络威胁日益复杂,传统安全机制难以应对。大语言模型(LLMs)凭借其强大的文本处理与生成能力,在网络安全中展现出巨大潜力。本文提出RAGRecon系统,利用带有检索增强生成(RAG)的大语言模型,结合实时信息检索与领域特定数据,回答网络安全威胁相关问题。该系统通过生成并可视化知识图谱,使AI推理过程可解释,增强模型的透明性与可理解性,帮助分析师理解RAG系统所依据的上下文关联。我们在两个数据集上对七种不同LLMs进行了实验评估,结果显示最优组合下,系统回复与参考答案匹配率超过91%。

原文摘要 · Abstract (English)

As cyber threats continue to grow in complexity, traditional security mechanisms struggle to keep up. Large language models (LLMs) offer significant potential in cybersecurity due to their advanced capabilities in text processing and generation. This paper explores the use of LLMs with retrieval-augmented generation (RAG) to obtain threat intelligence by combining real-time information retrieval with domain-specific data. The proposed system, RAGRecon, uses a LLM with RAG to answer questions about cybersecurity threats. Moreover, it makes this form of Artificial Intelligence (AI) explainable by generating and visually presenting to the user a knowledge graph for every reply. This increases the transparency and interpretability of the reasoning of the model, allowing analysts to better understand the connections made by the system based on the context recovered by the RAG system. We evaluated RAGRecon experimentally with two datasets and seven different LLMs and the responses matched the reference responses more than 91% of the time for the best combinations.

威胁情报大模型可解释性RAG

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。