用大模型+时间序列模型实现工业安全的自主防御,杜绝幻觉动作。
Neuro-Agentic Control: A Deep Learning-based LLM-Powered Agentic AI Framework for Controlling Security Controls

- 大模型规划+时间序列基础模型协同,用物理模拟验证干预可行性。
- 在SWaT数据集上防住5次攻击(33.3%),优于LSTM和TCN基线。
- 适合关键基础设施安全系统,避免大模型幻觉导致的物理破坏。
工业物联网环境中的网络攻击正导致高昂停机与物理损伤,传统规则式监控已显不足。尽管大语言模型(LLMs)具备强大的语义推理能力,但其幻觉特性在闭环控制中带来不可接受的安全风险。本文提出神经代理控制框架,将基于大模型的规划器(如Gemini 2.5 Flash-Lite)与预训练的时间序列基础模型(TimesFM)结合,实现基于物理规律的自主防御。引入“反事实物理注入”机制,在基础模型的数值隐空间中预先模拟大模型建议干预的影响,以拒绝幻觉或不安全动作。在包含随机攻击场景的工业数据集(如安全水处理系统SWaT)上评估,该框架性能优于LSTM与TCN基线:在阈值以下防止5次攻击(占比33.3%),高于LSTM的26.7%与TCN的13.3%,且执行零次物理无效动作。结果表明,基础模型可作为确定性“哨兵”,保障代理型AI在关键基础设施中的安全运行。
原文摘要 · Abstract (English)
Cyberattacks on operational technology are increasingly causing costly downtime and physical damage, exposing the limitations of traditional rule-based monitoring in industrial IoT environments. While Large Language Models (LLMs) have strong semantic reasoning abilities to assist in decision support, their hallucinatory nature presents unacceptable safety liabilities for closed-loop control. This paper introduces a neuro-agentic control framework, a novel architecture that couples an LLM-based planner (i.e., such as Gemini 2.5 Flash-Lite) with a pre-trained Time-Series Foundation Model (TimesFM), to achieve physics-grounded autonomous defense. The paper introduces a ``Counterfactual Physics Injection'' mechanism that simulates the impact of LLM-proposed interventions within the numerical latent space of the foundation model before actuation, while allowing the system to reject hallucinatory or unsafe actions. Evaluated on an industrial dataset (e.g., the Secure Water Treatment (SWaT)) in the context of stochastic attack scenarios, the framework exhibited better performance compared to LSTM and TCN baselines. The Neuro-Agentic Loop prevented five breaches (33.3%) below the threshold versus LSTM (26.7%) and TCN (13.3%), with zero physically invalid (hallucinated) actions executed. These results demonstrate the efficacy of using foundation models as deterministic ``Sentinels'' to safeguard agentic AI in critical infrastructure.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。