arXiv:2605.12507cs.SIcs.AI2026-05被引 1

用LLM模拟邮件网络,能真实还原动态传播与钓鱼攻击

Can LLM Agents Simulate Dynamic Networks? A Case Study on Email Networks with Phishing Synthesis

论文配图:Can LLM Agents Simulate Dynamic Networks? A Case Study on Email Networks with Phishing Synthesis
图 1 · 摘自论文原文
  • 给LLM代理加入数据驱动事件触发,维持长期交互
  • 引入霍克斯过程精准建模时间激活,提升网络拓扑真实性
  • 可生成逼真钓鱼攻击数据,适合网络安全研究者

尽管大语言模型多智能体系统(LLM MAS)为复杂系统中人类行为的模拟提供了变革性方法,但其在动态网络视角下是否能再现真实的结构与时间动态仍不明确。我们的评估表明,现有框架虽能生成合理的微观交互,却难以捕捉信息传播和网络安全等领域的宏观拓扑特征。为此,我们提出两个易于集成的扩展:1)为LLM代理添加数据驱动事件触发,以自然维持长时交互;2)整合霍克斯过程(Hawkes processes),准确建模时间激活动态。该方法使LLM MAS同时具备合理的微观模式与宏观拓扑。我们进一步展示了该框架在演化通信网络中合成真实钓鱼攻击的实用性。研究揭示了威胁如何利用结构漏洞,凸显其在下一代防御系统中的潜力。代码已开源:https://github.com/Graph-COM/NSL。

原文摘要 · Abstract (English)

While Large Language Model (LLM) multi-agent systems (MAS) offer a transformative approach to simulating human behavior in complex systems, it remains largely unexplored whether these simulations can replicate realistic structural and temporal dynamics from a dynamic network perspective. Our evaluation indicates that existing frameworks excel at generating plausible micro-level interactions but fail to capture the emergent, macroscopic topologies necessary for domains that rely on realistic network dynamics, such as modeling information propagation and cybersecurity threats. To bridge this gap, we introduce two easily integrable extensions to simulation frameworks to ensure they preserve macroscopic network fidelity: 1) augmenting LLM agents with data-driven event triggers to organically sustain long-horizon interactions, and 2) integrating Hawkes processes to accurately model temporal activation dynamics. Our approach allows LLM MAS to capture both plausible micro-level patterns and macroscopic topologies. We further demonstrate the utility of this framework in synthesizing realistic phishing campaigns within evolving communication networks. The study reveals how threats exploit structural vulnerabilities, highlighting the potential of our framework for developing next-generation defenses. Our code is available at https://github.com/Graph-COM/NSL.

LLM代理网络模拟钓鱼攻击动态网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。