AI平台融合威胁检测与安全培训,一键化解技术与人为漏洞
SentinelSphere: Integrating AI-Powered Real-Time Threat Detection with Cybersecurity Awareness Training

- 用改进的深度神经网络+网页层特征识别攻击,精准率高
- 检测模型误报低,对暴力破解等关键攻击召回率超90%
- 轻量级AI助手可跑在普通电脑上,适合非技术人员用
网络安全面临两大难题:专业人才短缺和人为失误导致多数安全事件。为此,我们提出SentinelSphere平台,整合基于AI的威胁检测与大语言模型驱动的安全教育。检测模块采用在CIC-IDS2017和CIC-DDoS2019数据集上训练的增强型深度神经网络(Enhanced DNN),并引入新型HTTP层特征工程,捕捉应用层攻击指纹。教育模块部署了经过微调的量化版Phi-4模型(Q4_K_M),可在仅需16 GB内存、无专用显卡的通用硬件上运行。实验表明,该增强模型在保持高检测准确率的同时,显著降低误报率,并在拒绝服务(DDoS)、暴力破解及网页攻击等关键类别中维持强召回率。面向行业从业者与大学生的验证工作坊显示,交通灯式可视化与对话式AI助手对非技术人员也直观有效。SentinelSphere证明,将智能威胁检测与自适应的LLM教学结合,能在单一框架内协同解决技术和人为安全短板。
原文摘要 · Abstract (English)
The field of cybersecurity is confronted with two interrelated challenges: a worldwide deficit of qualified practitioners and ongoing human-factor weaknesses that account for the bulk of security incidents. To tackle these issues, we present SentinelSphere, a platform driven by artificial intelligence that unifies machine learning-based threat identification with security training powered by a Large Language Model (LLM). The detection module uses an Enhanced Deep Neural Network (DNN) trained on the CIC-IDS2017 and CIC-DDoS2019 benchmark datasets, enriched with novel HTTP-layer feature engineering that captures application level attack signatures. For the educational component, we deploy a quantised variant of Phi-4 model (Q4_K_M), fine-tuned for the cybersecurity domain, enabling deployment on commodity hardware requiring only 16 GB of RAM without dedicated GPU resources. Experimental results show that the Enhanced DNN attains high detection accuracy while substantially lowering false positives relative to baseline models, and maintains strong recall across critical attack categories such as DDoS, brute force, and web-based exploits. Validation workshops involving industry professionals and university students confirmed that the Traffic Light visualisation system and conversational AI assistant are both intuitive and effective for users without technical backgrounds. SentinelSphere illustrates that coupling intelligent threat detection with adaptive, LLM-driven security education can meaningfully address both technical and human-factor cybersecurity vulnerabilities within a single, cohesive framework.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。