arXiv:2512.06396cs.CRcs.AI2025-12被引 1

用生成式AI构建多智能体系统,实现跨模态威胁实时检测与自适应响应。

AgenticCyber: A GenAI-Powered Multi-Agent System for Multimodal Threat Detection and Adaptive Response in Cybersecurity

  • 设计多智能体协同架构,分别处理日志、视频、音频数据流。
  • 威胁检测F1得分96.2%,响应延迟低至420毫秒,MTTR降低65%。
  • 适合企业与物联网场景,支持跨模态推理和自动修复,可扩展性强。

分布式环境中的网络威胁日益复杂,亟需在多模态数据流中实现实时检测与响应的先进框架。本文提出AgenticCyber,一个基于生成式AI的多智能体系统,通过专用智能体同步监控云日志、监控视频与环境音频。系统在威胁检测上取得96.2%的F1分数,响应延迟降至420毫秒,并利用Google Gemini等多模态语言模型与LangChain实现智能体编排,支持自适应安全策略管理。基于AWS CloudTrail日志、UCF-Crime视频帧及UrbanSound8K音频片段的基准测试表明,该方案显著优于传统入侵检测系统,平均响应时间(MTTR)减少65%,显著提升态势感知能力。本工作构建了一种面向企业网络与物联网生态系统的可扩展、模块化主动安全架构,突破了传统安全技术的信息孤岛,实现跨模态推理与自动化修复。

原文摘要 · Abstract (English)

The increasing complexity of cyber threats in distributed environments demands advanced frameworks for real-time detection and response across multimodal data streams. This paper introduces AgenticCyber, a generative AI powered multi-agent system that orchestrates specialized agents to monitor cloud logs, surveillance videos, and environmental audio concurrently. The solution achieves 96.2% F1-score in threat detection, reduces response latency to 420 ms, and enables adaptive security posture management using multimodal language models like Google's Gemini coupled with LangChain for agent orchestration. Benchmark datasets, such as AWS CloudTrail logs, UCF-Crime video frames, and UrbanSound8K audio clips, show greater performance over standard intrusion detection systems, reducing mean time to respond (MTTR) by 65% and improving situational awareness. This work introduces a scalable, modular proactive cybersecurity architecture for enterprise networks and IoT ecosystems that overcomes siloed security technologies with cross-modal reasoning and automated remediation.

多智能体跨模态自适应响应生成式AI

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。