arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.21103cs.CRcs.NI

NetInspector:测量与提升LLM在可靠意图驱动网络策略生成中的能力

NetInspector: Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation

  • Texas A&M University(德克萨斯农工大学)
  • University at Buffalo(布法罗大学)

机构由 AI 辅助整理,请以论文原文为准。

Yuxuan Zhang, Hongxin Hu, Guofei Gu

AI总结:

NetInspector提出三层智能体框架,通过“先验证后行动”协议解耦检索与推理,将LLM策略决策锚定于实时网络事实,在2224样本基准上使假阴性率降低超30%,提升意图驱动网络策略生成的可靠性。

AI中文摘要:

现代网络规模庞大且配置异构,使得手动策略管理日益不切实际。意图驱动网络(IBN)通过将高层运营商目标自动转化为低层网络配置来解决这一问题。然而,现有的IBN系统依赖静态启发式和固定特征分类器,在面对分布偏移(如新服务定义或运营商请求中措辞的演变)时泛化能力较差。大型语言模型(LLM)在众多领域展现出强大的推理和翻译能力,是IBN策略生成的自然候选方案。然而,目前尚不清楚LLM能否可靠地应用于此任务,也不确定其使用是缓解还是加剧了潜在的安全风险。在本工作中,我们表明,虽然微调后的LLM在意图翻译方面表现出色,但在检查提议的意图是否违反现有安全策略时,它们表现出较高的假阴性率。根本原因并非缺乏逻辑推理能力,而是LLM缺乏对网络拓扑和组层次结构的持久性锚定。受此发现启发,我们提出了NetInspector,一个三层智能体框架,强制执行“先验证后行动”协议,将信息检索与推理解耦,使LLM专注于符号推理,同时每个策略决策在批准前都基于从实时环境层检索的可验证网络事实进行锚定。在NetInspector-Bench上,一个包含2224个样本、覆盖校园网、企业网和广域网拓扑的合成基准中,NetInspector相对于无锚定基线将假阴性率降低了超过30%,并在语言分布偏移下保持鲁棒性。

英文摘要:

Modern networks are large in scale and heterogeneous in configuration, making manual policy management increasingly impractical. Intent-Based Networking (IBN) addresses this by automating the translation of high-level operator goals into low-level network configurations. Yet existing IBN systems rely on static heuristics and fixed-feature classifiers that generalize poorly to distribution shifts such as new service definitions or evolving phrasing in operator requests. Large Language Models (LLMs), with strong reasoning and translation capabilities demonstrated across many domains, are a natural candidate for IBN policy generation. However, it is unclear whether LLMs can be reliably applied to this task, nor whether their use mitigates or worsens the underlying security risk. In this work, we show that while fine-tuned LLMs excel at intent translation, they exhibit false negative rates when checking whether a proposed intent violates an existing security policy. The root cause is not a lack of logical reasoning capability, but LLMs lack of persistent grounding in network topology and group hierarchy. Motivated by this finding, we introduce NetInspector, a three-layer agentic framework that enforces a verify-then-act protocol, decoupling information retrieval from reasoning so that the LLM focuses on symbolic reasoning while every policy decision is grounded in verifiable network facts retrieved from a live Environment Layer before approval. On NetInspector-Bench, a 2,224-sample synthetic benchmark spanning campus, enterprise, and WAN topologies, NetInspector reduces FNR by over 30\% relative to ungrounded baselines and remains robust under linguistic distribution shifts.

↑