用于保障案例生成的智能检索增强生成与评估框架:欧盟网络弹性法案合规性的工业用例
An Agentic RAG and Evaluation Framework for Assurance Case Generation: Industrial Use Case for the EU Cyber Resilience Act Compliance
AI总结:
该研究提出基于智能RAG的保障案例生成与评估框架,通过案例研究验证其可自动化欧盟网络弹性法案合规评定,减少人工并提升证据可追溯性。
AI中文摘要:
欧盟网络弹性法案(CRA)合规性对中小企业而言是资源密集型挑战,原因在于网络安全合格评定的复杂性,而合规性对证明监管遵从性、确保产品安全性与弹性至关重要。为解决该问题,我们提出一种基于智能检索增强生成(agentic RAG)的自动化保障案例(AC)生成框架,该框架以正式的主张-论证-证据逻辑为基础,通过系统映射技术文档要求,简化认证证据的生成流程。我们在Catalink的PATROLIoT野火监测系统案例研究中验证了该方法,其中智能RAG生成了70个AC,每个AC的基础密度约为4.4个制品。所提出的自然语言推理(NLI)评估器达到0.88的准确率,提供了稳健的证据基础与可追溯性,而经专家验证的可信度(3.06)支持可解释的论证。对于从业者而言,本研究提供了一种可扩展、可解释的方法,用于自动化强制性CRA合格评定,在保持透明决策支持的同时减少人工工作量。
英文摘要:
Complying with the EU Cyber Resilience Act (CRA) is a resource-intensive challenge for SMEs due to the complexity of cybersecurity conformity assessment. Yet, it is essential for demonstrating regulatory compliance and ensuring product security and resilience. To address this, we introduce an automated framework for generating Assurance Cases (ACs) using an agentic Retrieval-Augmented Generation grounded in a formal Claim-Argument-Evidence logic. By systematically mapping technical documentation requirements, the framework streamlines the generation of certification evidence. We validate our approach on a case study of Catalink's PATROLIoT wildfire monitoring system, where the agentic RAG generated 70 ACs with high grounding density (~4.4 artefacts per AC). The proposed Natural Language Inference (NLI) evaluator achieves 0.88 accuracy, which provides robust evidence grounding and traceability, while expert-validated plausibility (3.06) supports interpretable justifications. For practitioners, this work provides a scalable, interpretable approach for automating mandatory CRA conformity assessments, reducing manual effort while maintaining transparent decision support.