arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

神经代理控制:一种基于深度学习的由大型语言模型驱动的用于控制安全控制的代理人工智能框架

Neuro-Agentic Control: A Deep Learning-based LLM-Powered Agentic AI Framework for Controlling Security Controls

Saroj Gopali, Bipin Chhetri, Deepika Giri, Sima Siami-Namini, Akbar Siami Namin

arXiv 2607.09076首次发表:更新:

发表机构

Texas Tech University; Cumberland University; Advanced Academic Programs Science; Johns Hopkins University(德克萨斯理工大学; 坎伯兰大学; 高级学术项目科学部; 约翰·霍普金斯大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对运营技术网络攻击问题,提出神经代理控制框架,结合基于LLM的规划器与预训练的TimesFM,并引入“反事实物理注入”机制,在工业数据集评估中表现优于基线,能有效保障关键基础设施中代理人工智能。

AI 中文摘要

对运营技术的网络攻击日益导致高昂的停机时间和物理损坏,暴露了工业物联网环境中传统基于规则监测的局限性。虽然大型语言模型(LLMs)有强大语义推理能力辅助决策支持,但其幻觉性质给闭环控制带来不可接受的安全责任。本文引入神经代理控制框架,将基于LLM的规划器与预训练的时间序列基础模型(TimesFM)结合以实现基于物理的自主防御。还引入“反事实物理注入”机制,在驱动前在基础模型的数值潜在空间模拟LLM提出干预的影响,让系统拒绝幻觉或不安全行动。在工业数据集上评估,该框架比LSTM和TCN基线表现更好,神经代理循环防止的低于阈值的违规比LSTM和TCN更多,且无执行物理无效(幻觉)行动,证明使用基础模型作为确定性“哨兵”保障关键基础设施中代理人工智能的有效性。

英文摘要

Cyberattacks on operational technology are increasingly causing costly downtime and physical damage, exposing the limitations of traditional rule-based monitoring in industrial IoT environments. While Large Language Models (LLMs) have strong semantic reasoning abilities to assist in decision support, their hallucinatory nature presents unacceptable safety liabilities for closed-loop control. This paper introduces a neuro-agentic control framework, a novel architecture that couples an LLM-based planner (i.e., such as Gemini 2.5 Flash-Lite) with a pre-trained Time-Series Foundation Model (TimesFM), to achieve physics-grounded autonomous defense. The paper introduces a ``Counterfactual Physics Injection'' mechanism that simulates the impact of LLM-proposed interventions within the numerical latent space of the foundation model before actuation, while allowing the system to reject hallucinatory or unsafe actions. Evaluated on an industrial dataset (e.g., the Secure Water Treatment (SWaT)) in the context of stochastic attack scenarios, the framework exhibited better performance compared to LSTM and TCN baselines. The Neuro-Agentic Loop prevented five breaches (33.3%) below the threshold versus LSTM (26.7%) and TCN (13.3%), with zero physically invalid (hallucinated) actions executed. These results demonstrate the efficacy of using foundation models as deterministic ``Sentinels'' to safeguard agentic AI in critical infrastructure.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑