arXiv:2604.09998cs.CRcs.AI2026-04被引 1

分析黑客论坛讨论,揭示安全人员如何用大模型提效又担忧风险。

Like a Hammer, It Can Build, It Can Break: Large Language Model Uses, Perceptions, and Adoption in Cybersecurity Operations on Reddit

  • 通过分析892篇Reddit帖子,研究安全人员对大模型的实际使用场景。
  • 大模型提升效率但可靠性差、验证成本高,难完全信任。
  • 适合关注安全领域AI落地的从业者与产品设计者参考。

大型语言模型(LLMs)近年来被视作增强安全运营中心(SOC)工作流程的潜在工具,厂商也不断推出面向SOC的自主AI解决方案。然而,目前对这些工具在真实安全从业者中的使用方式、感知和采纳情况仍缺乏实证研究。为填补这一空白,我们对三个网络安全主题的Reddit论坛中2022年12月至2025年9月间的892篇帖子进行了混合方法分析,结合定性编码与统计分析,考察了安全从业者在三大维度上的讨论:(1)实际使用的工具与应用场景;(2)各工具在关键因素上的优缺点感知;(3)工具采纳情况及其对网络安全行业与分析师个人的影响。研究发现,从业者普遍将大模型用于低风险、提升效率的任务,同时对具备企业级、安全导向的平台表现出浓厚兴趣。尽管能显著提升工作效率与效果,但模型可靠性不足、验证开销大及安全风险等问题严重制约其自主性。基于此,本文提出开发与采纳建议,以保障组织安全与从业者安全。

原文摘要 · Abstract (English)

Large language models (LLMs) have recently emerged as promising tools for augmenting Security Operations Center (SOC) workflows, with vendors increasingly marketing autonomous AI solutions for SOCs. However, there remains a limited empirical understanding of how such tools are used, perceived, and adopted by real-world security practitioners. To address this gap, we conduct a mixed-methods analysis of discussions in cybersecurity-focused forums to learn how a diverse group of practitioners use and perceive modern LLM tools for security operations. More specifically, we analyzed 892 posts between December 2022 and September 2025 from three cybersecurity-focused forums on Reddit, and, using a combination of qualitative coding and statistical analysis, examined how security practitioners discuss LLM tools across three dimensions: (1) their stated tools and use cases, (2) the perceived pros and cons of each tool across a set of critical factors, and (3) their adoption of such tools and the expected impacts on the cybersecurity industry and individual analysts. Overall, our findings reveal nuanced patterns in LLM tools adoption, highlighting independent use of LLMs for low-risk, productivity-oriented tasks, alongside active interest around enterprise-grade, security-focused LLM platforms. Although practitioners report meaningful gains in efficiency and effectiveness in LLM-assisted workflows, persistent issues with reliability, verification overheads, and security risks sharply constrain the autonomy granted to LLM tools. Based on these results, we also provide recommendations for developing and adopting LLM tools to ensure the security of organizations and the safety of cybersecurity practitioners.

大模型安全运维用户研究

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。