Multimodal Learning 相关度: 9/10

From Incomplete Architecture to Quantified Risk: Multimodal LLM-Driven Security Assessment for Cyber-Physical Systems

Shaofei Huang, Christopher M. Poskitt, Lwin Khin Shar
arXiv: 2604.05674v1 发布: 2026-04-07 更新: 2026-04-07

AI 摘要

ASTRAL利用多模态LLM进行CPS架构重建和安全风险评估,提高网络风险管理决策。

主要贡献

  • 提出ASTRAL,一种基于多模态LLM的架构中心安全威胁风险评估技术
  • 利用prompt chaining、few-shot learning和架构推理从分散数据源提取和综合系统表示
  • 将LLM推理与架构建模相结合,支持自适应威胁识别和量化风险估计

方法论

利用多模态LLM,通过prompt chaining、few-shot learning和架构推理重建CPS架构,进行威胁识别和风险评估。

原文摘要

Cyber-physical systems often contend with incomplete architectural documentation or outdated information resulting from legacy technologies, knowledge management gaps, and the complexity of integrating diverse subsystems over extended operational lifecycles. This architectural incompleteness impedes reliable security assessment, as inaccurate or missing architectural knowledge limits the identification of system dependencies, attack surfaces, and risk propagation pathways. To address this foundational challenge, this paper introduces ASTRAL (Architecture-Centric Security Threat Risk Assessment using LLMs), an architecture-centric security assessment technique implemented in a prototype tool powered by multimodal LLMs. The proposed approach assists practitioners in reconstructing and analysing CPS architectures when documentation is fragmented or absent. By leveraging prompt chaining, few-shot learning, and architectural reasoning, ASTRAL extracts and synthesises system representations from disparate data sources. By integrating LLM reasoning with architectural modelling, our approach supports adaptive threat identification and quantitative risk estimation for cyber-physical systems. We evaluated the approach through an ablation study across multiple CPS case studies and an expert evaluation involving 14 experienced cybersecurity practitioners. Practitioner feedback suggests that ASTRAL is useful and reliable for supporting architecture-centric security assessment. Overall, the results indicate that the approach can support more informed cyber risk management decisions.

标签

网络安全 网络物理系统 多模态LLM 风险评估

arXiv 分类

cs.CR cs.AI