自适应内鬼能反向降低被怀疑概率,挑战传统检测逻辑。
HBEE: Human Behavioral Entropy Engine -- Pre-Registered Multi-Agent LLM Simulation of Peer-Suspicion-Based Detection Inversion

- 用多智能体模拟器测试大模型驱动的自适应内鬼行为。
- 自适应内鬼在60分钟时被怀疑程度低于无辜者,检测失效。
- 结果与预注册预测相反,揭示了新型检测机制的脆弱性。
内鬼检测假设自适应内鬼会留下可识别的行为痕迹。本文在受控多智能体模拟器中,通过大模型驱动的自适应内鬼检验该假设。预注册的五条件研究将防御模式(级联式与盲式UEBA)与攻击者类型(非自适应与自适应OPSEC)交叉,共进行100次运行(经预设排除后保留95次有效)。主要发现为检测倒置:在T_60时刻,自适应内鬼的同行怀疑度中心性显著低于随机选取的无辜者(Cliff's delta = -0.694,95% BCa置信区间[-0.855, -0.519],Mann-Whitney p << 0.01),而预注册预测方向相反。预注册等价性检验(H2)显示,自适应OPSEC在任一防御模式下均未导致内鬼的UEBA排名发生可检测变化。两种检测信号(同行怀疑图入度与个体UEBA排名)在自适应攻击下解耦。我们明确限定泛化边界:预注册的基尼系数校准检查(H4)失败,HBEE消息暴露基尼系数(0.213)与SNAP Enron参考值(0.730)差异|Delta Gini| = 0.52,超出等价界限5倍。论文提出一个狭窄但惊人的结论:在可控环境中,当自适应OPSEC可作为大模型指令实现时,基于同行怀疑的级联检测会反转。代码、预注册文档、冻结场景、原始日志与分析流程均已开源。
原文摘要 · Abstract (English)
Insider threat detection assumes that an adaptive insider leaves behavioral residue distinguishing them from legitimate users. We test this assumption against an LLM-driven adaptive insider in a controlled multi-agent simulator. Our pre-registered five-condition study isolates defender mode (cascade vs. blind UEBA) crossed with adversary type (naive vs. adaptive OPSEC) plus a no-mole control, across 100 runs (95 valid after pre-committed exclusions). The primary finding is a detection inversion: at T_60, the adaptive mole's suspicion in-degree is statistically lower than a randomly selected innocent agent (Cliff's delta = -0.694, 95% BCa CI [-0.855, -0.519], Mann-Whitney p << 0.01). The pre-registered prediction was the opposite direction. A pre-registered equivalence test (H2) shows adaptive OPSEC produces no detectable shift in the mole's UEBA rank under either defender mode. The two detection signals (peer suspicion graph in-degree and per-agent UEBA rank) decouple under adaptive adversary behavior. We bound generalization explicitly: a pre-registered Gini calibration check (H4) returns FAIL, with HBEE pairwise message-exposure Gini (0.213) diverging from the SNAP Enron reference (0.730) by |Delta Gini| = 0.52, exceeding the equivalence bound by 5x. The paper makes a narrow but surprising claim: in a controlled environment where adaptive OPSEC is implementable as an LLM directive, peer-suspicion-cascade detection inverts. We release the simulator, pre-registration document, frozen scenarios, raw telemetry, and analysis pipeline under an open-source license.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。