arXiv:2603.07204cs.CRcs.IR2026-03

用多个大模型协作识别软件中的加密组件,助力后量子密码迁移。

Detecting Cryptographically Relevant Software Packages with Collaborative LLMs

  • 多大模型协同判断软件是否含加密功能,通过投票融合结果。
  • 在6.5万多个Fedora包上验证,显著减少人工排查工作量。
  • 支持本地部署,保护数据隐私,适合企业级安全资产盘点。

信息系统正面临日益严峻的安全威胁,包括高级持续性攻击和未来量子计算带来的风险。向密码敏捷性和后量子密码(PQC)过渡,需要在异构IT环境中建立可靠的加密资产清单。由于包数量庞大,手动检测加密相关软件不现实;而传统静态代码分析难以应对现代生态系统的多样性。本研究探索将大语言模型(LLMs)作为启发式工具用于加密资产发现。提出一种协作框架,利用多个LLM评估软件相关性,并通过多数投票聚合输出。为保障数据隐私,该方法在本地部署,无需依赖外部服务器。基于超过65,000个Fedora Linux包,通过统计分析、模型间一致性及人工验证评估其可靠性。初步结果表明,LLM集成可作为高效的一轮筛选工具,有效降低人工工作量,辅助PQC转型。研究还对比了本地与在线LLM配置,揭示了自动化加密资产发现的关键优势、局限与未来方向。

原文摘要 · Abstract (English)

IT systems are facing an increasing number of security threats, including advanced persistent attacks and future quantum-computing vulnerabilities. The move towards crypto-agility and post-quantum cryptography (PQC) requires a reliable inventory of cryptographic assets across heterogeneous IT environments. Due to the sheer amount of packets, it is infeasible to manually detect cryptographically relevant software. Further, static code analysis pipelines often fail to address the diversity of modern ecosystems. Our research explores the use of large language models (LLMs) as heuristic tools for cryptographic asset discovery. We propose a collaborative framework that employs multiple LLMs to assess software relevance and aggregates their outputs through majority voting. To preserve data privacy, the approach operates on-premises without reliance on external servers. Using over 65,000 Fedora Linux packages, we evaluate the reliability of this method through statistical analysis, inter-model agreement, and manual validation. Preliminary results suggest that~LLM ensembles can serve as an efficient first-pass filter for identifying cryptographic software, resulting in reduced manual workload and assisting PQC transition. The study also compares on-premises and online LLM configurations, highlighting key advantages, limitations, and future directions for automated cryptographic asset discovery.

大模型加密发现信息安全本地部署

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。