发表机构
The University of Texas at El Paso(德克萨斯大学艾尔帕索分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
研究针对网络安全新威胁无标注数据问题,提出SMETA-ZSL方法,通过对比微调、情景元学习和知识蒸馏等,从重叠语言描述学习语义原型并对齐行为特征,实现跨可见-未见类别的泛化,在7个基准测试中性能远超先前方法。
AI 中文摘要
网络安全系统必须迅速适应新出现的威胁。然而,新威胁类别首次出现时,其标注数据不可用。广义零样本学习通过辅助语义知识而非标注示例来识别未见类别,提供了自然的解决方案。大语言模型在此场景中很有前景,因其能将非结构化的CTI报告转化为新威胁的语义原型。但将语言驱动的零样本学习应用于网络安全存在困难,如威胁描述间语义重叠、行为属性与文本的异质性、严重的类别不平衡以及训练时未见威胁的开放集条件。我们提出SMETA-ZSL,它通过对比微调从重叠语言描述中学习语义原型,通过情景元学习和知识蒸馏对齐行为特征,并进行自适应路由以实现跨可见-未见类别的泛化。在7个基准测试中,SMETA-ZSL在最严格的归纳设置下提供了最强的总体广义零样本性能,平均比先前方法高出10.8分,增益高达18.1分。
英文摘要
Cybersecurity systems must adapt rapidly to emerging threats. However, labeled data for new threat categories is unavailable when those threats first appear. Generalized zero-shot learning offers a natural solution by enabling recognition of unseen classes through auxiliary semantic knowledge rather than labeled examples. Large language models are particularly promising in this setting because they can convert unstructured CTI reports into semantic prototypes for emerging threats. However, applying language-driven zero-shot learning to cybersecurity is difficult due to strong semantic overlap between threat descriptions, heterogeneity between behavioral attributes and text, severe class imbalance, and open-set conditions where unseen threats are unknown during training. We propose SMETA-ZSL, that learns semantic prototypes from overlapping language descriptions through contrastive finetuning, aligns behavioral features through episodic meta-learning and knowledge distillation, and performs adaptive routing for generalization across seen-unseen classes. Across 7 benchmarks, SMETA-ZSL delivers the strongest overall generalized zero-shot performance under the strictest inductive setting, surpassing prior methods by 10.8 points on average, with gains up to 18.1 points. Github:https://github.com/Security-And-Intelligence-Lab-UTEP/SMETA-ZSL