arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.14370cs.CRcs.AIcs.SE

一种基于混合大语言模型(LLM)的业务流程模型自动安全标注生成框架

A Hybrid LLM-Based Framework for Automated Security Annotation Generation in Business Process Models

Md Kamrul Islam, Tiphaine Henry, Mattia Salnitri, Julius Köpke, Sami Souihi

首次发表
浏览论文内容

中文总结 AI 辅助

该研究提出一种混合LLM与规则的框架,输入BPMN模型和安全需求文档,自动生成符合SecBPMN2规范的安全标注,在27个流程模型数据集上验证,其准确率优于人工分析师,提升效率与可靠性。

中文摘要 AI 辅助

安全业务流程的建模与分析需要将安全标注融入流程模型。尽管存在用于此目的的BPMN扩展(包括SecBPMN2),但从自然语言规范中推导准确且完整的安全标注仍是一项人工、依赖专家且易出错的任务。本文提出一种混合框架,以BPMN流程模型和安全需求文档为输入,自动生成符合SecBPMN2规范的安全标注。该方法将基于大语言模型(LLM)的语义提取与模式约束映射、基于规则的归一化及确定性验证相结合。在来自不同领域的27个流程模型的精选数据集上对该框架进行了全面评估。结果表明,该框架始终能生成结构有效的SecBPMN2标注,具有较高的模式完整性。与人工安全分析师相比,该系统的准确率显著更高(0.58 vs. 0.29),同时保持相当的召回率(0.52 vs. 0.50),并减少了近50%的错误或错位标注。此外,标注生成速度显著快于人工标注。这些发现表明,基于LLM和规则的混合自动化可减少建模工作量,同时提高一致性和可靠性,从而为设计安全的业务流程管理(BPM)提供可扩展的基础。

英文摘要

The modelling and analysis of secure business processes require the incorporation of security annotations into process models. Although BPMN extensions, including SecBPMN2, exist for this purpose, the derivation of accurate and complete security annotations from natural-language specifications remains a manual, expert-intensive, and error-prone task. This paper presents a hybrid framework that takes a BPMN process model and a security requirements document as input and automatically generates security annotations adhering to the SecBPMN2 specification. The approach combines Large Language Model (LLM)--based semantic extraction with schema-constrained mapping, rule-based normalization, and deterministic validation. The framework is evaluated comprehensively on a curated dataset of 27 process models from various domains. The results indicate that it consistently produces structurally valid SecBPMN2 annotations with high schema completeness. Compared to human security analysts, the system achieves substantially higher precision (0.58 vs. 0.29) while maintaining comparable recall (0.52 vs. 0.50) and reduces erroneous or misplaced annotations by nearly 50%. In addition, annotation generation is significantly faster than manual annotation. These findings demonstrate that hybrid LLM- and rule-based automation can reduce modeling effort while improving consistency and reliability, thereby providing a scalable foundation for security-by-design BPM.

发表机构

  • CentraleSupélec(中央高等电力学院)
  • Université Paris-Saclay(巴黎-萨克雷大学)
  • University of Bergamo(贝加莫大学)
  • University of Klagenfurt(克拉根福大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑