用领域适配的句子模型自动匹配云安全规范与技术指标
Automated Compliance Mapping in Cloud Security with Domain-Adapted Sentence Transformers
- 用多源安全标准构建语义对数据集,通过回译和大模型改写扩充至1.4万条
- 最佳模型在指标匹配任务上提升23 nDCG@10,跨标准关联达0.870 nDCG@10
- 证明领域训练数据是性能关键,适合安全合规自动化研究者
将云安全控制映射到技术指标目前仍依赖人工。本文提出对句子嵌入模型进行领域适配以实现自动化。我们从五个欧洲安全标准与一组技术指标中构建了包含3,499个语义对的训练语料,并通过回译和基于大语言模型的改写扩展至13,996个样本,覆盖四种场景。我们微调了五种模型架构,并在两个独立任务上评估其表现:控制到指标匹配与跨标准控制关联。所有微调模型均优于零样本基线。在控制到指标任务中,最优模型提升最高达23 nDCG@10;在跨标准控制任务中,multi-qa-mpnet-dot-v1在回译数据下达到0.870 nDCG@10。结果表明,在所考虑案例中,领域内训练数据是性能的主要驱动因素。
原文摘要 · Abstract (English)
Mapping cloud security controls to technical metrics is currently a manual process. This paper proposes domain adaptation of Sentence Transformer models to automate it. We build a training corpus of 3,499 semantic pairs from five European security standards and a set of technical metrics, then expand it via back-translation and LLM-based paraphrasing to up to 13,996 samples across four scenarios. We fine-tune five architectures and evaluate their performance on two independent tasks: control-to-metric and cross-standard controls association. All fine-tuned models outperform their zero-shot baselines. On the control-to-metric task, the best model gains up to 23 nDCG@10 points, while on the cross-standard control task, \textit{multi-qa-mpnet-dot-v1} under back-translation reaches 0.870 nDCG@10. The results show that in-domain training data is a primary driver of performance for the considered case studies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。