arXiv:2606.30953cs.AIcs.LG2026-06

用浅层网络实现可解释的网络安全风险评估,融合专家知识与因果推理。

Neuro-Bayesian-Symbolic Residual Attention Shallow Network: Explainable Deep Learning for Cybersecurity Risk Assessment

  • 设计浅层网络,将领域知识和因果逻辑作为可微分模块嵌入
  • 在20个开源项目上验证,置信度达0.79-0.97,且结果可追溯每项调整来源
  • 适合高风险场景,如安全审计,对可解释性要求高的应用

我们提出神经-贝叶斯-符号残差注意力浅层网络(NBS-RASN),一种用于开源生态中可解释网络安全风险评估的混合神经架构。该模型不以牺牲可解释性换取精度,而是通过80个可解释神经元分布在12层中,将领域知识、因果推理和专家判断编码为可微组件。其中门控机制强制执行五条认识论公理——精确性、因果性、可证伪性、透明性和完整性——作为传播前的硬约束。尽管深度有限,但通过残差注意力和反馈回路展现出深度学习特征,能学习复杂风险模式而不变成黑箱。输出为可完全分解的风险评分:确定性加权部分加上专家修正项,每项修正均可追溯至六个命名放大因子(影响范围、传播速度、结构特性、默认暴露、利用模式、机构关键性)。在涵盖所有OWASP Top 10:2025类别及语言风险类别的20个开源项目上验证,置信度达到0.79–0.97,且可解释性由设计保证,而非训练算法。这挑战了深度学习必须依赖深网络的假设,证明浅层网络结合深层推理可在高风险网络安全场景中超越不透明模型。

原文摘要 · Abstract (English)

We introduce the Neuro-Bayesian-Symbolic Residual Attention Shallow Network (NBS-RASN), a hybrid neural architecture for explainable cybersecurity risk assessment in open-source ecosystems. Unlike deep models that trade interpretability for accuracy, our shallow network encodes domain knowledge, causal reasoning, and expert judgment as differentiable components. It uses 80 interpretable neurons across 12 layers, including a gatekeeper that enforces five epistemological axioms - precision, causality, falsifiability, transparency, and completeness - as hard constraints before propagation. Despite limited depth, the network exhibits deep-learning traits via residual attention and feedback loops, learning complex risk patterns without becoming a black box. It produces fully decomposable scores: a deterministic weighted component plus an expert adjustment, with each adjustment traceable to named amplifiers (blast radius, propagation speed, structural nature, default exposure, exploitation pattern, institutional criticality). We validate on 20 open-source projects covering all OWASP Top 10:2025 categories and language risk classes, achieving confidence scores of 0.79-0.97, and show that explainability is guaranteed by design, not by a training algorithm. This challenges the assumption that deep learning requires deep networks, proving that shallow networks with deep reasoning can outperform opaque models in high-stakes cybersecurity, where interpretability is essential.

可解释AI网络安全浅层网络因果推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。