攻击大模型的漏洞检测框架,用微小干扰破坏其防御能力。
RAG-targeted Adversarial Attack on LLM-based Threat Detection and Mitigation Framework
- 通过语义不变的词级扰动污染RAG知识库,实施定向数据投毒。
- 微小扰动使大模型误判攻击行为,缓解建议变得不具体且不实用。
- 揭示资源受限设备场景下大模型防御系统的脆弱性,适合安全研究者参考。
物联网的快速扩展重塑了各行业的通信与运营方式,但也扩大了攻击面并增加了安全漏洞风险。人工智能已成为保障物联网网络安全的重要手段,大语言模型(LLM)在入侵检测系统中实现攻击行为自动化分析与缓解建议生成。然而,该类系统引入了新攻击面,如提示注入和数据投毒,威胁整体网络。本文针对基于LLM的物联网攻击分析与缓解框架发起对抗性攻击,构建攻击描述数据集,采用词级、语义保持的扰动对检索增强生成(RAG)知识库实施定向数据投毒。对比攻击前后目标模型ChatGPT-5 Thinking的缓解响应,使用面向人类专家的评估标准衡量性能影响。结果表明,微小扰动会削弱网络流量特征与攻击行为间的关联性,并降低缓解建议对资源受限设备的针对性与实用性。
原文摘要 · Abstract (English)
The rapid expansion of the Internet of Things (IoT) is reshaping communication and operational practices across industries, but it also broadens the attack surface and increases susceptibility to security breaches. Artificial Intelligence has become a valuable solution in securing IoT networks, with Large Language Models (LLMs) enabling automated attack behavior analysis and mitigation suggestion in Network Intrusion Detection Systems (NIDS). Despite advancements, the use of LLMs in such systems further expands the attack surface, putting entire networks at risk by introducing vulnerabilities such as prompt injection and data poisoning. In this work, we attack an LLM-based IoT attack analysis and mitigation framework to test its adversarial robustness. We construct an attack description dataset and use it in a targeted data poisoning attack that applies word-level, meaning-preserving perturbations to corrupt the Retrieval-Augmented Generation (RAG) knowledge base of the framework. We then compare pre-attack and post-attack mitigation responses from the target model, ChatGPT-5 Thinking, to measure the impact of the attack on model performance, using an established evaluation rubric designed for human experts and judge LLMs. Our results show that small perturbations degrade LLM performance by weakening the linkage between observed network traffic features and attack behavior, and by reducing the specificity and practicality of recommended mitigations for resource-constrained devices.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。