arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.15407cs.CRcs.AIcs.NE

变色龙:一种采用威胁校准粒子群优化算法与语义欺骗快速探索随机树的自适应AI驱动蜜罐架构

Chameleon: An Adaptive AI-Driven Honeypot Architecture Using Threat-Calibrated Particle Swarm Optimization and Semantic Deception Rapidly-Exploring Random Trees

Rohit Swami, Tushar Singh, Akash Warde, Sri Muthu

首次发表
浏览论文内容

中文总结 AI 辅助

Chameleon是一种开源自适应AI蜜罐平台,通过BiLSTM分类器、Qwen3.5-0.8B模型及TC-PSO、S-RRT引擎,解决传统蜜罐与商业产品的缺陷,性能显著提升且成本大幅降低。

中文摘要 AI 辅助

传统蜜罐部署的核心漏洞在于其行为特征是固定不变的:熟练的攻击者仅需几条诊断命令就能确认欺骗环境的存在,这限制了其情报价值。每年成本达10万至15万美元的高价商业欺骗产品也存在相关缺陷,即其响应引擎未与实时模型驱动的反馈机制耦合。本文提出的Chameleon是一种开源分布式自适应蜜罐平台,旨在解决上述两个问题。该平台集成了三个核心组件:一是双向长短期记忆(BiLSTM)分类器,在7类威胁类别上达到99.61%的准确率,CPU延迟约为2毫秒;二是本地部署的Qwen3.5-0.8B语言模型(通义千问团队,2026;Unsloth团队,2026),上下文生成准确率达90%,平均延迟为4.5毫秒;三是两个特定领域的元启发式引擎。威胁校准粒子群优化算法(TC-PSO)根据分类器的异常输出动态调整群体惯性和目标放大系数,实现连接保持延迟的实时调整。语义欺骗快速探索随机树(S-RRT)通过语言模型的严重程度评估生成指数级缩放的信息素更新来驱动欺骗模式演变,同时采用深度衰减乘数确保有限的内存占用。在5次基准运行(种子42至46)中,TC-PSO的平均适应度从标准PSO的2.60提升至3.85,性能提升48.1%,收敛速度提升32.7%;S-RRT的最优运行适应度从标准RRT的450.2提升至1615.8,性能提升258.9%,在关键严重程度下提升329.2%,内存占用减少24.9%(p<0.01)。该平台的运营成本约为每月17美元,较商业产品降低约490倍。

英文摘要

Traditional honeypots share an invariant behavioral profile: a skilled adversary can confirm the presence of a deception environment within a few diagnostic commands, limiting their intelligence value. Commercial deception products (USD 100,000-150,000/year) similarly lack real-time model-driven feedback. Chameleon, an openly distributed adaptive honeypot, addresses both shortcomings. It integrates: a BiLSTM classifier achieving 99.61% accuracy across seven threat categories at ~2 ms CPU latency; a locally deployed Qwen3.5-0.8B model delivering 90% generation accuracy at 4.5 ms latency; and two meta-heuristic engines. Threat-Calibrated PSO (TC-PSO) reshapes swarm inertia and objective amplification in proportion to the classifier's anomaly output, adjusting connection-holding delays in real time. Semantic Deception RRT (S-RRT) evolves deception schemas via exponentially scaled pheromone updates from a language-model severity assessment, with a depth-decay multiplier enforcing a finite memory footprint. A controlled 30-seed benchmark (42-71, identical trajectories and budgets) shows threat-calibrated inertia alone does not improve search over standard PSO on static or dynamic landscapes (p = 0.18); population-diversity mechanisms (GA/ACO) significantly outperform PSO-family optimizers on threat-regime shifts (p < 0.0001, d <= -37). S-RRT's depth-decay delivers a significant memory reduction versus standard RRT (53.1 vs. 119.2 units, p < 0.0001, d = -10.0); its severity-weighted pheromone does not improve raw fitness. Operating cost is ~USD 17/month, a ~490-fold reduction versus commercial alternatives.

发表机构

  • SIES Graduate School of Technology(SIES技术研究院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑