arXiv:2512.09485cs.CRcs.AI2025-12中稿 · IEEE JSAC被引 6

用大模型实现网络自动安全防护,从生成到反馈全程无需人工干预。

Advancing LLM-Based Security Automation with Customized Group Relative Policy Optimization for Zero-Touch Networks

  • 构建全流程自动化框架SecLoop,集成大模型完成策略生成与响应闭环。
  • 提出SA-GRPO算法,通过并行执行对比反馈优化安全策略,适应动态威胁。
  • 在11个MITRE ATT&CK场景和20+攻击类型上验证有效,支持6G零接触网络。

零接触网络(ZTN)是第六代(6G)网络智能化管理的变革范式,具备应对复杂网络所需的可扩展性与自适应能力。然而,6G网络的分布式架构、高开放性和深度异构性扩大了攻击面,带来前所未有的安全挑战。安全自动化旨在实现动态复杂环境下的智能安全管理,是保障6G ZTN的关键能力。尽管前景广阔,其落地仍面临两大挑战:一是实现在真实、并行、对抗条件下的安全策略生成、验证与更新全生命周期自动化;二是使策略能适应不断演进的威胁与动态环境。为此,我们提出SecLoop和SA-GRPO。SecLoop是首个全流程自动化框架,将大语言模型(LLMs)贯穿于安全策略生成、编排、响应与反馈全过程,实现动态网络环境下的智能自适应防御,解决第一项挑战。同时,提出SA-GRPO——一种新型安全感知组相对策略优化算法,通过并行执行中收集的群体反馈进行迭代优化,提升策略鲁棒性,应对第二项挑战。在五个基准测试上的实证实验,涵盖11个MITRE ATT&CK流程及超过20类攻击,充分证明了SecLoop与SA-GRPO的优越性。我们将开源平台,推动下一代通信安全自动化发展。

原文摘要 · Abstract (English)

Zero-Touch Networks (ZTNs) represent a transformative paradigm toward fully automated and intelligent network management, providing the scalability and adaptability required for the complexity of sixth-generation (6G) networks. However, the distributed architecture, high openness, and deep heterogeneity of 6G networks expand the attack surface and pose unprecedented security challenges. To address this, security automation aims to enable intelligent security management across dynamic and complex environments, serving as a key capability for securing 6G ZTNs. Despite its promise, implementing security automation in 6G ZTNs presents two primary challenges: 1) automating the lifecycle from security strategy generation to validation and update under real-world, parallel, and adversarial conditions, and 2) adapting security strategies to evolving threats and dynamic environments. This motivates us to propose SecLoop and SA-GRPO. SecLoop constitutes the first fully automated framework that integrates large language models (LLMs) across the entire lifecycle of security strategy generation, orchestration, response, and feedback, enabling intelligent and adaptive defenses in dynamic network environments, thus tackling the first challenge. Furthermore, we propose SA-GRPO, a novel security-aware group relative policy optimization algorithm that iteratively refines security strategies by contrasting group feedback collected from parallel SecLoop executions, thereby addressing the second challenge. Extensive real-world experiments on five benchmarks, including 11 MITRE ATT&CK processes and over 20 types of attacks, demonstrate the superiority of the proposed SecLoop and SA-GRPO. We will release our platform to the community, facilitating the advancement of security automation towards next generation communications.

安全自动化大模型应用6G网络策略优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。