arXiv:2608.02422cs.CRcs.AI2026-08被引 1

用数字孪生增强的智能体系统,让安全响应更快速准确。

Agentic Incident Response through Digital Twin-Enhanced Multiscale Planning

论文配图:Agentic Incident Response through Digital Twin-Enhanced Multiscale Planning
图 1 · 摘自论文原文
  • 结合决策理论与大模型生成指令,分战术与操作两层规划。
  • 在三个攻击场景中,恢复时间减少15.1%,成功率提升33.6%。
  • 适合需要自动化、高可靠性的企业级安全运维团队使用。

当前安全事件响应依赖人工操作员执行预设手册,导致决策缓慢且耗时。为实现自动化响应规划,已有基于控制、优化和强化学习的决策理论方法被提出,但大多仅适用于抽象模型,无法直接部署于实际系统。一种有前景的方法是利用大语言模型(LLM)中的安全知识构建智能体响应系统。然而,现有智能体方法依赖反复调用LLM生成计划,存在不可靠性和幻觉问题,限制了规划深度。本文提出一种基于决策理论与LLM指令生成相结合的系统性规划方法:采用滚动规划器计算高层资源分配策略(战术层面),再由轻量级LLM代理转化为可执行命令(操作层面)。该架构引入数字孪生,支持战术规划的仿真与操作执行的模拟。在三个攻击场景中,所提方法平均将恢复执行时间缩短15.1%,恢复率较前沿LLM基线提升33.6%。

原文摘要 · Abstract (English)

Incident response is currently managed by security operators using predefined playbooks, resulting in slow, labor-intensive security decision-making processes. Consequently, there is a growing need for automated incident response planning. Decision-theoretic approaches based on control, optimization, and reinforcement learning have been proposed to automate such planning tasks with well-grounded approaches, yet most of which, while guaranteeing strong performance, are limited to abstract models and cannot be directly applied to operational systems. A promising approach to mitigate this limitation is to use the security knowledge embedded in large language models (LLMs) to develop agentic response systems. However, current agentic approaches rely on repeated invocations of the LLM to generate a response plan, which is unreliable and limits the planning horizon due to hallucination. In this paper, we develop a principled LLM-based planning method by combining decision-theoretic planning with LLM-generated response commands. The proposed agentic incident response approach uses a rollout planner to compute a high-level response strategy that allocates security resources (the tactical scale), which is then translated into executable commands by a lightweight LLM agent (the operational scale). Within this architecture, we use a digital twin that supports tactical planning through simulation and operational execution through emulation. Across three attack scenarios, our agentic approach reduces recovery execution time by 15.1\% on average and increases the recovery rate by 33.6\% over frontier LLM baselines.

智能体数字孪生安全响应

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。