用区块链确保AI漏洞检测结果可审计,兼顾速度与可信。
Zer0n: An AI-Assisted Vulnerability Discovery and Blockchain-Backed Integrity Framework
- 将大模型检测逻辑与区块链日志结合,实现可追溯的漏洞发现。
- 在500个端点上达到80%检测准确率,仅增加22.9%开销。
- 适合需要高可信安全自动化的企业或研究机构。
随着漏洞研究越来越多地采用生成式AI,对不可解释模型输出的依赖带来了安全自动化中的“信任缺口”。我们提出Zer0n框架,将大型语言模型(LLMs)的推理能力与区块链技术的不可篡改审计日志相结合。具体而言,利用Gemini 2.0 Pro进行基于逻辑的漏洞检测,并通过Avalanche C-Chain实现防篡改的成果记录。不同于完全去中心化的高延迟方案,Zer0n采用混合架构:执行过程保留在链外以保证性能,而完整性证明则在链上最终确认。在包含500个端点的数据集上的评估表明,该方法实现了80%的检测准确率,仅带来22.9%的边际开销,有效证明了去中心化完整性可在高速安全工作流中实现共存。
原文摘要 · Abstract (English)
As vulnerability research increasingly adopts generative AI, a critical reliance on opaque model outputs has emerged, creating a "trust gap" in security automation. We address this by introducing Zer0n, a framework that anchors the reasoning capabilities of Large Language Models (LLMs) to the immutable audit trails of blockchain technology. Specifically, we integrate Gemini 2.0 Pro for logic-based vulnerability detection with the Avalanche C-Chain for tamper-evident artifact logging. Unlike fully decentralized solutions that suffer from high latency, Zer0n employs a hybrid architecture: execution remains off-chain for performance, while integrity proofs are finalized on-chain. Our evaluation on a dataset of 500 endpoints reveals that this approach achieves 80% detection accuracy with only a marginal 22.9% overhead, effectively demonstrating that decentralized integrity can coexist with high-speed security workflows.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。