arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

深度信念:用于多阶段APT防御中忠实事件报告的基于证据的大语言模型

DeepFaith: Evidence-Grounded LLMs for Faithful Incident Reporting in Multi-Stage APT Defense

Trung V. Phan, Tri Gia Nguyen, Thomas Bauschert

arXiv 2607.24348首次发表:更新:

发表机构

IEEE(电气和电子工程师协会)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对多阶段APT防御中事件报告难检测解释、输出难理解及大语言模型内容缺乏依据等问题,提出深度信念框架,通过集成多种技术确保生成陈述有依据,实验表明该框架能提升多项指标,为安全运营中心提供可靠报告。

AI 中文摘要

高级持续性威胁(APT)因其多阶段和隐蔽性而难以检测和解释。虽然最近的自主防御系统利用溯源图和基于学习的模型进行检测和缓解,但其输出主要面向机器,分析师难以解释。大语言模型为报告生成提供了一个有前景的接口,但往往会产生幻觉或缺乏依据的内容。本文提出了深度信念,这是一个用于多阶段APT防御中忠实事件报告的基于证据的框架。深度信念将自主防御和可解释性模块的结构化输出转换为与基础系统证据明确对齐的自然语言报告。该框架集成了统一的证据表示、基于证据的提示、忠实性感知生成和生成后验证,以确保所有生成的陈述都有依据。在实际企业测试平台上的实验表明,深度信念将忠实性从0.68提高到0.92,将无依据的声明从0.32减少到0.08,并将时间一致性从0.6提高到0.88,同时保持报告简洁且错误率低于现有基于模板和大语言模型的解决方案。这些结果表明,基于证据的生成能够为安全运营中心提供可靠、可解释且可操作的报告。

英文摘要

Advanced Persistent Threats (APTs) are difficult to detect and interpret due to their multi-stage and stealthy nature. While recent autonomous defense systems leverage provenance graphs and learning-based models for detection and mitigation, their outputs remain largely machine-oriented and difficult for analysts to interpret. Large language models (LLMs) offer a promising interface for report generation, but often produce hallucinated or weakly grounded content. In this paper, we propose DeepFaith, an evidence-grounded framework for faithful incident reporting in multi-stage APT defense. DeepFaith transforms structured outputs from autonomous defense and explainability modules into natural-language reports that are explicitly aligned with underlying system evidence. The framework integrates a unified evidence representation, evidence-grounded prompting, faithfulness-aware generation, and post-generation verification to ensure that all generated statements are supported. Experiments in a realistic enterprise testbed demonstrate that DeepFaith improves faithfulness from 0.68 to 0.92, reduces unsupported claims from 0.32 to 0.08, and increases temporal consistency from 0.6 to 0.88, while maintaining concise reports and lower error rates than existing template-based and LLM-based solutions. These results show that evidence-grounded generation enables reliable, interpretable, and actionable reporting for security operations centers.

CommentsThis paper has been submitted to the IEEE International Conference on Network and Service Management (CNSM) 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑