arXiv:2604.15590cs.CRcs.AI2026-04中稿 · the Ninth Annual C…被引 2

构建真实环境下的安全自治平台,让强化学习在实战中有效落地。

CSLE: A Reinforcement Learning Platform for Autonomous Security Management

论文配图:CSLE: A Reinforcement Learning Platform for Autonomous Security Management
图 1 · 摘自论文原文
  • 用仿真与仿真环境结合的方式构建安全策略学习闭环
  • 四类控制场景实测逼近最优安全管理水平
  • 适合研究网络自治安全的学者与工程师参考

强化学习是实现网络系统自主自适应安全管理的有前景方法。然而,当前多数安全管理的强化学习方案仅限于仿真环境,其在实际系统中的泛化能力尚不明确。本文提出CSLE:一个面向自主安全管理的强化学习平台,支持在真实条件下的实验验证。概念上,CSLE包含两个系统:首先是一个仿真环境,用于复现目标系统的关键组件并收集测量数据和日志,据此构建如马尔可夫决策过程等系统模型;其次是一个仿真系统,通过系统模型高效学习安全策略。学习后的策略再返回仿真环境进行评估与优化,以缩小理论性能与实际表现之间的差距。我们通过四个用例——流量控制、复制控制、分段控制和恢复控制——验证了该平台的有效性。结果表明,CSLE能在接近真实运行环境的条件下实现近最优的安全管理。

原文摘要 · Abstract (English)

Reinforcement learning is a promising approach to autonomous and adaptive security management in networked systems. However, current reinforcement learning solutions for security management are mostly limited to simulation environments and it is unclear how they generalize to operational systems. In this paper, we address this limitation by presenting CSLE: a reinforcement learning platform for autonomous security management that enables experimentation under realistic conditions. Conceptually, CSLE encompasses two systems. First, it includes an emulation system that replicates key components of the target system in a virtualized environment. We use this system to gather measurements and logs, based on which we identify a system model, such as a Markov decision process. Second, it includes a simulation system where security strategies are efficiently learned through simulations of the system model. The learned strategies are then evaluated and refined in the emulation system to close the gap between theoretical and operational performance. We demonstrate CSLE through four use cases: flow control, replication control, segmentation control, and recovery control. Through these use cases, we show that CSLE enables near-optimal security management in an environment that approximates an operational system.

强化学习网络安全自主管理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。