arXiv:2601.22159cs.CRcs.AI2026-01被引 2

开源安全大模型RedSage,用专业数据训练,本地部署更安全。

RedSage: A Cybersecurity Generalist LLM

  • 用11.8亿文本 token 构建安全领域预训练数据,覆盖28600份文档。
  • 通过模拟专家流程生成26.6万条多轮问答,提升模型实战能力。
  • 80亿参数模型在安全任务上比基线高5.59分,适合安全人员使用。

网络安全操作需要能支持多样工作流且不泄露敏感数据的辅助大模型。现有方案或依赖有隐私风险的专有API,或使用缺乏领域适配的开源模型。为此,我们通过大规模网络过滤和人工收集,构建了11.8亿词元、覆盖28.6千份文档的网络安全持续预训练数据集,涵盖框架、攻击技术与安全工具。基于此,设计了模拟专家工作流的代理增强管道,生成26.6万条多轮网络安全样本用于监督微调。结合通用开源LLM数据,训练出可本地部署的开源模型RedSage,具备领域感知的预训练与后训练能力。为严格评估,引入RedSage-Bench基准,含3万道选择题与240道开放问答,覆盖安全知识、技能与工具使用。同时在CTI-Bench、CyberMetric、SECURE等安全基准及通用LLM基准上测试。80亿参数的RedSage在安全任务上表现优于基线模型,最高提升+5.59分,在Open LLM Leaderboard任务中提升+5.05分。结果表明,领域感知的代理增强与预/后训练不仅能提升安全专精能力,还能改善通用推理与指令遵循。所有模型、数据与代码均公开。

原文摘要 · Abstract (English)

Cybersecurity operations demand assistant LLMs that support diverse workflows without exposing sensitive data. Existing solutions either rely on proprietary APIs with privacy risks or on open models lacking domain adaptation. To bridge this gap, we curate 11.8B tokens of cybersecurity-focused continual pretraining data via large-scale web filtering and manual collection of high-quality resources, spanning 28.6K documents across frameworks, offensive techniques, and security tools. Building on this, we design an agentic augmentation pipeline that simulates expert workflows to generate 266K multi-turn cybersecurity samples for supervised fine-tuning. Combined with general open-source LLM data, these resources enable the training of RedSage, an open-source, locally deployable cybersecurity assistant with domain-aware pretraining and post-training. To rigorously evaluate the models, we introduce RedSage-Bench, a benchmark with 30K multiple-choice and 240 open-ended Q&A items covering cybersecurity knowledge, skills, and tool expertise. RedSage is further evaluated on established cybersecurity benchmarks (e.g., CTI-Bench, CyberMetric, SECURE) and general LLM benchmarks to assess broader generalization. At the 8B scale, RedSage achieves consistently better results, surpassing the baseline models by up to +5.59 points on cybersecurity benchmarks and +5.05 points on Open LLM Leaderboard tasks. These findings demonstrate that domain-aware agentic augmentation and pre/post-training can not only enhance cybersecurity-specific expertise but also help to improve general reasoning and instruction-following. All models, datasets, and code are publicly available.

网络安全大模型本地部署开源

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。