arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

评估开放权重语言模型用于生成自动驾驶车辆漏洞的结构化威胁信息

Evaluating Open-Weight LLMs for Generating Structured Threat Information for Autonomous Vehicle Vulnerabilities

Md Erfan, Ahmed Ryan, Md Kamal Hossain Chowdhury, Md Rayhanur Rahman

arXiv 2607.16175首次发表:更新:

发表机构

The University of Alabama; Alabama Water Institute(阿拉巴马大学; 阿拉巴马水研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究自动驾驶车辆漏洞相关结构化威胁信息生成问题,利用开放权重语言模型,通过构建CAV-STIXGen数据集评估11个模型,分析CWE和MITRE ATT&CK共现,展示AI辅助转换可自动化威胁情报并优先防御运输安全。

AI 中文摘要

联网和自动驾驶车辆(CAV)依赖相互连接的软硬件组件,其中漏洞会危及资产、用户和车辆运行。这些漏洞在通用漏洞披露(CVE)数据库中通常以纯文本记录,但安全从业者需要结构化信息来有效降低风险。为此,我们评估开放权重语言模型生成用于CAV相关CVE的结构化威胁信息表达式(STIX)。构建了CAV-STIXGen数据集,用其评估11个开放权重语言模型。单模型配置在SDO、SRO和CWE映射上有不同F1分数,多智能体设置中Gemma-4-31B和Codestral-22B在SDO和SRO上也有相应F1分数。最后分析CWE和MITRE ATT&CK共现以识别CAV领域反复出现的威胁模式,展示了人工智能辅助的漏洞到STIX转换可使威胁情报自动化并在运输安全中优先进行防御。

英文摘要

Connected and Autonomous Vehicles (CAVs) rely on interconnected software and hardware components, including sensors, Electronic Control Units, in-vehicle infotainment systems, and telematics units, where vulnerabilities can compromise assets, users, and vehicle operations. These vulnerabilities are commonly documented as plain text in the Common Vulnerabilities and Exposures (CVE) database; however, security practitioners require structured information about affected assets, types of weaknesses, and attack behaviors to effectively mitigate the risks from these vulnerabilities. To this end, we evaluate open-weight Large Language Models (LLMs) for generating Structured Threat Information Expression (STIX), a well-known structured format for representing threat information, for CAV-related CVEs. We construct a dataset called CAV-STIXGen that maps CAV vulnerability descriptions to STIX domain objects (SDO), STIX relationship objects (SRO), Common Weakness Enumeration (CWE), and MITRE ATT&CK techniques mappings. Using this dataset, we evaluated 11 open-weight LLMs (4B to 120B parameters) across various prompting strategies and temperatures. Single-model configurations achieve F1 scores of 0.94 for SDO, 0.63 for SRO, and 0.99 for CWE mapping, while complete MITRE ATT&CK mapping remains challenging. In a multi-agent setup, Gemma-4-31B and Codestral-22B achieve F1 scores of 0.91 for SDOs and 0.43 for SROs, respectively. Lastly, we analyze CWE and MITRE ATT&CK co-occurrences to identify recurring threat patterns in the CAV domain, demonstrating how AI-assisted vulnerability-to-STIX translation can automate threat intelligence and prioritize defense in transportation security.

Comments9 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑