arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SecJev:将安全专业知识引入系统一决策模型

SecJev: Bringing Security Expertise to System One Decision Models

Zheng Chen, Fei Yu, Haohao Huang, Yang Li, Anlong Chen, Lei Chen

arXiv 2610.03073首次发表:更新:

发表机构

University of Electronic Science and Technology of China; National Key Laboratory of Security Communication(电子科技大学; 安全通信国家重点实验室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

SecJev是首个专为安全领域设计的Jev类决策模型家族,基于Kev单遍评分器,通过场景加权训练在14个任务上提升性能,0.8B模型在准确率上超越通用9B模型20.51个百分点。

AI 中文摘要

安全工作流需要能够将复杂观察和明确策略转化为决策的模型。Jev引入的系统一模型返回类型化预测和概率;安全专业化提供了这些预测背后的领域专业知识。我们提出SecJev,据我们所知,这是首个专为安全定制的Jev类决策模型家族,参数规模从0.8B到9B不等。基于Kev的单遍候选评分器,SecJev从文本、遥测和观察历史中学习布尔、选择和有序决策。我们开发了SecJev-Corpus,以统一跨14个任务和8个来源的源标签预测和显式策略评估。它涵盖工具输出、流量、联邦更新、共识、认证和车辆消息。场景加权训练使模型适应这些领域,同时保持共享的类型化决策接口。安全专业化提升了家族中每个模型的性能;SecJev-0.8B在任务宏平均准确率上比通用Kev-9B高出20.51个百分点。与仅答案的生成式微调相比,SecJev在准确率和延迟上接近,同时峰值推理内存更低。在新来源组上的测试重现了在提示注入和流量决策上优于Kev的效果,并存在依赖捕获的误报。我们发布了适配器、决策头、SecJev-Corpus以及训练和推理代码。

英文摘要

Security workflows need models that turn complex observations and explicit policies into decisions. System One models introduced by Jev return typed predictions and probabilities; security specialization supplies the domain expertise behind those predictions. We introduce SecJev, to our knowledge the first family of Jev-like decision models specialized for security, spanning 0.8B to 9B parameters. Built on Kev's single-pass candidate scorer, SecJev learns Boolean, choice, and ordered decisions from text, telemetry, and observation histories. We develop SecJev-Corpus to unify source-label prediction and explicit-policy evaluation across 14 tasks and eight sources. It covers tool outputs, traffic, federated updates, consensus, authentication, and vehicle messages. Scene-weighted training adapts the models across these domains while preserving a shared typed decision interface. Security specialization improves every model in the family; SecJev-0.8B outperforms general Kev-9B by 20.51 percentage points in task-macro accuracy. Comparisons with answer-only generative fine-tuning show close accuracy and latency with lower peak inference memory. Tests on new source groups reproduce gains over Kev in prompt-injection and traffic decisions, with capture-dependent false alarms. We release adapters, decision heads, SecJev-Corpus, and training and inference code.

Comments22 pages, 1 figure

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑