让AI生成的漏洞报告更真实可信,避免胡编乱造。
DeepFaith: Evidence-Grounded LLMs for Faithful Incident Reporting in Multi-Stage APT Defense

- 用证据锚定LLM生成内容,确保每句话都有系统记录支持。
- 报告忠实度从0.68升至0.92,虚假陈述减少至0.08。
- 适合安全团队快速理解复杂攻击链,提升响应效率。
高级持续性威胁(APTs)因其多阶段、隐蔽性强而难以检测与分析。现有自主防御系统虽借助溯源图和学习模型实现检测与缓解,但输出结果仍以机器可读为主,难以供分析师理解。大型语言模型(LLMs)虽可生成自然语言报告,但常出现幻觉或缺乏依据。本文提出DeepFaith,一种面向多阶段APT防御的证据锚定式可信报告框架。该框架将自主防御与可解释性模块的结构化输出转化为与底层系统证据显式对齐的自然语言报告,集成统一证据表示、证据锚定提示、忠实度感知生成及生成后验证机制,确保所有生成内容均有据可依。在真实企业测试环境中,实验表明DeepFaith将报告忠实度从0.68提升至0.92,不支持陈述比例从0.32降至0.08,时间一致性由0.6增至0.88,同时保持报告简洁且错误率低于现有基于模板和纯LLM的方案。结果证明,证据锚定生成能实现可靠、可解释、可操作的安全事件报告。
原文摘要 · Abstract (English)
Advanced Persistent Threats (APTs) are difficult to detect and interpret due to their multi-stage and stealthy nature. While recent autonomous defense systems leverage provenance graphs and learning-based models for detection and mitigation, their outputs remain largely machine-oriented and difficult for analysts to interpret. Large language models (LLMs) offer a promising interface for report generation, but often produce hallucinated or weakly grounded content. In this paper, we propose DeepFaith, an evidence-grounded framework for faithful incident reporting in multi-stage APT defense. DeepFaith transforms structured outputs from autonomous defense and explainability modules into natural-language reports that are explicitly aligned with underlying system evidence. The framework integrates a unified evidence representation, evidence-grounded prompting, faithfulness-aware generation, and post-generation verification to ensure that all generated statements are supported. Experiments in a realistic enterprise testbed demonstrate that DeepFaith improves faithfulness from 0.68 to 0.92, reduces unsupported claims from 0.32 to 0.08, and increases temporal consistency from 0.6 to 0.88, while maintaining concise reports and lower error rates than existing template-based and LLM-based solutions. These results show that evidence-grounded generation enables reliable, interpretable, and actionable reporting for security operations centers.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。