arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.12444cs.CRcs.LG

面向自动化安全决策的非退化风险认证:以适配ATT&CK的分类为实例的决策契约理论

Non-Degenerate Risk Certification for Automated Security Decisions: A Decision-Contract Theory with ATT\&CK-Aligned Triage as a Worked Instance

  • Guangzhou Health Science College(广州卫生职业技术学院)

机构由 AI 辅助整理,请以论文原文为准。

Zhenpeng Li

AI总结:

本文提出决策契约理论用于自动化安全决策的非退化风险认证,以适配ATT&CK的LLM入侵检测警报分类为实例,实验验证了该方法可有效控制风险并实现较高的正确自动化率。

AI中文摘要:

若选择器从不执行任何操作,可使无条件风险边界降至零,从而无需实现任何自动化即可满足自动化决策的无条件风险边界,这是一种结构性现象。本文证明,任何风险证书均定义于决策契约之上,决策契约包含系统作用的输入以及判定输出正确的语义关系,且弱化任一要素都会隐藏基分类器的误差。本文提出决策契约理论:一是误差守恒定律,表明误差仅在有害自动化、人工延迟和语义掩码之间重新分配;二是无标签单例容量,可证明结构性无能,且存在风险可行的细化方法,将可恢复的阈值错位与受风险约束的无能区分开;三是非退化可操作性证书,通过构造排除全弃权(不执行)解决方案。本文将该理论实例化到适配ATT&CK的警报分类任务中,该任务针对基于大语言模型(LLM)的入侵检测系统(IDS),正是该任务暴露了风险证书的空洞性缺陷。在3个IDS数据集、6种LLM和4个错误率阈值的实验中,90.3%的配置下经验错误归因风险维持在目标值或以下,平均正确自动化率达83.4%。容量诊断可解释所有低效用配置,其细化方法可将真正的错位与受风险约束的无能区分开,经展示的替代阈值验证了该结论;训练稳定性复现未发现任何经证实的结构性无能实例;真实细粒度攻击亚型标签证实了在真正的多对一映射下的粗化转移特性,掩码量较小但非零。

英文摘要:

An unconditional risk bound on automated decisions can be satisfied without automating anything, since a selector that never acts drives the bound to zero. We show this is structural: any risk certificate is defined over a decision contract, the inputs a system acts on plus the semantic relation under which an output counts correct, and weakening either hides base-classifier error. We develop a decision-contract theory: an error-conservation law showing error is only reassigned among harmful automation, human deferral, and semantic masking; a label-free singleton capacity certifying structural incapacity, with a risk-feasible refinement separating recoverable threshold misalignment from risk-constrained incapacity; and a non-degenerate actionability certificate excluding all-abstain solutions by construction. We instantiate this on ATT\&CK-aligned alert triage for LLM-based intrusion detection, the setting that exposed the vacuity failure. Across 3 IDS datasets, 6 LLMs, and 4 error-rate thresholds, empirical false-attribution risk stays at or below target in 90.3% of configurations, with 83.4% mean correct automation. The capacity diagnostic explains every low-utility configuration; its refinement separates genuine misalignment from risk-constrained incapacity, confirmed by an exhibited alternative threshold; a training-stability re-run finds no confirmed structural-incapacity instance; and real fine-grained attack-subtype labels confirm the coarsening-transfer identity under a genuine many-to-one map, with small but non-zero masking mass.

补充信息

↑