A Network Security Knowledge Reasoning Method Based on Chain of Thought
By combining PEFT and FlashAttention2 technology for network security corpus training and designing thinking chain prompt examples, the problem of insufficient reasoning capabilities of large language models in the field of network security is solved, and logic and accuracy are improved.
Patent Information
- Application Number
- CN202411524822.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-30
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-10-30
AI Technical Summary
Large language models lack reasoning capabilities in the field of network security, especially in complex problems, and lack of logic and coherence. The improvement of existing thinking chain prompt methods is limited, due to the parameter size of the base model.
Combining PEFT technology and FlashAttention2 technology to train network security corpus, and design thinking chain prompt samples, and combining zero-sample and few-sample inference methods to enhance the reasoning ability of large language models.
It significantly improves the reasoning ability of large language models in the field of network security, especially the logic and accuracy of complex problems, and improves the interpretability and efficiency of the model.
Smart Images

Figure CN119514678B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer science and technology, and particularly relates to a method for reasoning network security knowledge based on chain of thought. Background Art
[0002] In recent years, language models have attracted more and more extensive attention due to their powerful performance demonstrated in various natural language tasks. In recent research on prompting engineering of large language models, chain of thought prompting has been proposed as an effective way to improve the reasoning ability and accuracy of large language models. With the gradual deepening of research on cyberspace security, the knowledge of the cyberspace security discipline has gradually become more complex and more cross-disciplinary, and the knowledge required by researchers in some research or development tasks has also become more. Therefore, it is necessary to enhance the reasoning ability of large language models in the field of network security to provide better assistance for researchers to retrieve network security-related knowledge.
[0003] Without using the chain of thought, the answers generated by the large language model are prone to problems of insufficient logic and coherence, and the ability to answer complex questions will also decline. The chain of thought can help the model reason step by step to solve complex problems. Without the step-by-step reasoning process of the chain of thought, the model may perform poorly when dealing with complex tasks. Without the chain of thought, the model may output smooth but illogical wrong results. At the same time, the interpretability of the reasoning results of the large model is reduced. Summary of the Invention
[0004] The purpose of the present invention is to provide a method for reasoning network security knowledge based on chain of thought, which can combine the zero-shot reasoning and few-shot reasoning methods of the chain of thought on the basis of the existing large model, and train and fine-tune a relatively excellent network security large model.
[0005] The technical solution adopted by the present invention is specifically as follows:
[0006] A method for reasoning network security knowledge based on chain of thought, the method comprising the following steps:
[0007] S1: Screen network security academic materials, uniformly format the screened materials to obtain network security data corpus for large model pre-training;
[0008] S2: Perform network security corpus training;
[0009] Use the PEFT technology and FlashAttention2 technology to perform network security corpus training on the basic large model;
[0010] In the said S2, the specific steps of the network security corpus training are as follows:
[0011] S21: First, use the PEFT technology to write the pre-training program, parse the pre-training corpus, define the work in the pre-training process, and adjust the dataset path, model configuration, and parameters according to the local configuration.
[0012] S22: Subsequently, initialize the model and the tokenizer, load the pre-trained model and the tokenizer, and perform data preprocessing. Let the model tokenize and chunk the input text data to prepare the training data. Then, optimize the model configuration again.
[0013] S23: The pre-training code quantizes and optimizes the settings of the model, matches the model vocabulary size with the tokenizer, and initializes the model.
[0014] S24: Finally, execute the training, including continuing the training, evaluation metrics, and automatically saving the intermediate training results.
[0015] The pre-training program receives the pre-training parameters input from the terminal and sets the pre-training log output by the terminal.
[0016] Then, check whether there is a checkpoint left from the previous unfinished pre-training in the corresponding file path:
[0017] If there is, load the corresponding checkpoint and continue to execute the previous unfinished pre-training.
[0018] If not, start the initialization of the model. First, tokenize the pre-training corpus, and then reconnect all the texts in the pre-trained corpus after tokenization, and divide the text into text chunks with a fixed length.
[0019] After completing the relevant initialization work, enable gradient checkpointing to save important nodes during the pre-training process. Then, initialize the Trainer and start executing the pre-training program, and output the pre-training log in the terminal.
[0020] S25: During the pre-training process, use the FlashAttention2 technology to optimize the training acceleration, reducing the time complexity of the self-attention calculation from O(n 2 ) to O(n).
[0021] In the standard self-attention calculation, the matrix multiplication in the self-attention contains a large number of matrix multiplications, and the complexity of the self-attention is O(N 2) Since the main calculations of the Transformer model focus on attention calculations, the application scenarios of Transformer are limited by the computational efficiency and complexity of attention. When the sequence length N is too long, the computational efficiency of the Transformer model will increase exponentially. Therefore, when the input length is too long, the execution efficiency of the model will decrease.
[0022] S3: Design thinking chain prompting examples by using the current theory knowledge of thinking chain prompting;
[0023] In the above S3, the specific steps for designing thinking chain prompting examples are as follows:
[0024] S31: First, artificially construct thinking chain problem examples in the field of network security;
[0025] S32: Subsequently, use chatGPT to generate thinking chain answer examples, combine the artificial questions and the answers of chatGPT into a complete thinking chain prompting example, and repeat this process to construct a certain amount of thinking chain prompting examples;
[0026] S33: Then conduct a pre-experiment on the thinking chain prompting examples to screen out a small number of effective thinking chain prompting examples for subsequent use.
[0027] The thinking chain prompting examples need to meet the following requirements:
[0028] The questions need to cover the field of cyber security, including computer networks, cryptography, databases, blockchains, and network attacks and defenses;
[0029] The answers need to include a reasoning process of two to three steps, rather than simply outputting the answers.
[0030] S4: Design of the thinking chain prompting method.
[0031] Use the thinking chain prompting examples screened out in S3 and input them into the large language model as the learning samples for few-shot reasoning of the large model. Then, by adding "Let's think step by step" at the end of the input questions, combine the zero-shot reasoning and few-shot reasoning methods of the thinking chain prompting method.
[0032] The network security academic materials include four categories of documents: domestic conferences, academic journals, dissertations, and Chinese patents in the field of cyber security.
[0033] The technical effects achieved by the present invention are:
[0034] A method for inferring network security knowledge based on chain of thought. The existing chain of thought prompting methods used in large network security models are relatively simple, mostly pure zero-shot chain of thought prompting, which has limited enhancement effect on the inference ability of large models. On the other hand, simply using zero-shot or few-shot chain of thought prompting, its impact is greatly limited by the parameter size of the base model used.
[0035] A method for inferring network security knowledge based on chain of thought of the present invention gives full play to the inference ability of the current large language model, combines it with zero-shot and few-shot methods of chain of thought reasoning, enabling users to better use large models to solve network security problems. Description of the Drawings
[0036] Figure 1 is a schematic flowchart of an embodiment of the present invention;
[0037] Figure 2 is an example of a chain of thought for network security in an embodiment of the present invention;
[0038] Figure 3 is the inference process of combining zero-shot and few-shot of the chain of thought of the large model in an embodiment of the present invention. Detailed Embodiments
[0039] In order to make the purpose and advantages of the present invention clearer, the present invention will be specifically described below in conjunction with embodiments. It should be understood that the following text is only used to describe one or several specific implementation manners of the present invention, and does not strictly limit the specific protection scope claimed by the present invention.
[0040] As Figures 1-3 shown, a method for inferring network security knowledge based on chain of thought, the method includes the following steps:
[0041] S1: Screen network security academic materials, uniformly format the screened materials to obtain network security data corpus for large model pre-training;
[0042] S2: Conduct network security corpus training;
[0043] Use the PEFT technology and FlashAttention2 technology to train the base large model with the network security corpus;
[0044] In the said S2, the specific steps of network security corpus training are as follows:
[0045] S21: First, use the PEFT technology to write the pre-training program, parse the pre-training corpus, define the work in the pre-training process, and adjust the dataset path, model configuration and parameters according to the local configuration;
[0046] S22: Subsequently, initialize the model and the tokenizer, load the pre-trained model and tokenizer, and perform data preprocessing. Let the model tokenize and chunk the input text data to prepare the training data. Then, optimize the model configuration again;
[0047] S23: The pre-training code performs quantization and optimization settings on the model, matches the model vocabulary size and the tokenizer, and initializes the model;
[0048] S24: Finally, execute the training, including continued training, evaluation metrics, and automatic saving of intermediate training results;
[0049] The pre-training program receives the pre-training parameters input from the terminal and sets the pre-training log output by the terminal;
[0050] Then check whether there is a checkpoint left from the previous unfinished pre-training saved in the corresponding file path:
[0051] If there is, load the corresponding checkpoint and continue the previous unfinished pre-training;
[0052] If not, start the initialization of the model. First, tokenize the pre-training corpus, and then reconnect all the texts in the tokenized pre-training corpus and divide the text into text chunks of a fixed length;
[0053] After completing the relevant initialization work, enable gradient checkpointing to save important nodes during the pre-training process. Then initialize the Trainer and start executing the pre-training program, and output the pre-training log in the terminal.
[0054] S25: During the pre-training process, use the FlashAttention2 technology to optimize the training acceleration, reducing the time complexity of the self-attention calculation from O(n 2 ) to O(n).
[0055] In the standard self-attention calculation, there are a large number of matrix multiplications in the matrix multiplication of the self-attention, and the complexity of the self-attention is O(N 2 ). The main calculations of the Transformer model are concentrated in the attention calculation. Therefore, the application scenarios of the Transformer are limited by the calculation efficiency and complexity of the attention. When the sequence length N is too long, the calculation efficiency of the Transformer model will increase exponentially. So when the input length is too long, the execution efficiency of the model will decrease.
[0056] S3: Design thought chain prompting examples using the current theoretical knowledge of thought chain prompting;
[0057] In S3, the specific steps for designing the chain-of-thought prompt examples are as follows:
[0058] S31: First, artificially construct chain-of-thought problem examples in the field of network security;
[0059] S32: Subsequently, use chatGPT to generate chain-of-thought answer examples, combine the artificial questions with the answers of chatGPT into a complete chain-of-thought prompt example, and repeat this process to construct a certain amount of chain-of-thought prompt examples;
[0060] S33: Then conduct a pre-experiment on the chain-of-thought prompt examples to screen out a small number of effective chain-of-thought prompt examples for subsequent use.
[0061] The chain-of-thought prompt examples need to meet the following requirements:
[0062] The questions need to cover the field of cyberspace security, including computer networks, cryptography, databases, blockchains, and network attacks and defenses;
[0063] The answer needs to include a reasoning process of two to three steps, rather than simply outputting the answer.
[0064] Subsequently, a pre-experiment on the chain-of-thought prompt examples is conducted, aiming to screen out the chain-of-thought prompt examples that can enhance the network security reasoning ability of the large language model. After obtaining the chain-of-thought prompt examples with better tuning effects through the pre-experiment, we will input these prompt examples into the large model in step four to enhance the reasoning ability of the large model.
[0065] For a certain ability field, only about 10 chain-of-thought prompt examples need to be designed to significantly enhance the ability of the large language model. Therefore, in this step, we need to screen out about 10 prompt examples beneficial to the reasoning of the large model through the pre-experiment on the chain-of-thought prompt examples.
[0066] For example, 50 chain-of-thought prompt examples can be designed artificially first, and then each chain-of-thought prompt example is tested one by one to screen out 10 chain-of-thought prompt examples beneficial to the large language model. For the convenience of evaluating the effect of the subsequent pre-experiment, the reasoning questions used in the pre-experiment stage of the present invention are 10 multiple-choice questions that require an explanation of the answer. The large model will receive the question and the inputs of options A to D, and output an answer after reasoning. During the pre-experiment, the large language model separately receives the inputs of 50 chain-of-thought prompt examples, and then answers 10 reasoning questions in the field of cyberspace security one by one. After each round of receiving the input of a single chain-of-thought prompt example and completely answering 10 reasoning questions, the experimenter evaluates the answering effect of the large language model.
[0067] The evaluation of the answer effect of the large language model in the present invention is divided into two indicators, namely the completeness and accuracy of the reasoning process, which are denoted as φ here, where the value of φ ranges from 0 to 10 and is scored manually; and the correctness of the final answer, which is denoted as θ here, where the value of θ ranges from 0 to 10 and the initial value of θ is 0. For each correct answer given by the large language model, the value of θ is incremented by one. Since φ is manually evaluated and has strong subjectivity, and the differences in evaluation by different people may be relatively large, in order to ensure the objectivity of the preliminary experiment, the present invention decides to set its proportion in the final evaluation relatively low, with a weight coefficient of 0.2, while θ is only related to whether the multiple-choice question result is correct. Similarly, in order to ensure the objectivity of the experiment, the present invention decides to set the proportion of θ in the final evaluation relatively high, with a weight coefficient of 0.8. The final evaluation score is:
[0068] score = 0.2×φ + 0.8×θ
[0069] Among them, the value range of the evaluation score score is from 0 to 10. According to the corresponding evaluation indicators, the present invention tests 50 chain-of-thought prompt examples and calculates the evaluation score. Since there are four options in a multiple-choice question, in the case of random selection, the correct rate should be close to 25%. Therefore, we set θ = 2.5 as our evaluation benchmark. After using the chain-of-thought prompt examples, the large language model should have a θ of at least 3 when answering the 10 questions in the preliminary experiment, otherwise the chain-of-thought example will be excluded. Since we previously put forward the following requirements for the chain-of-thought prompt examples: (1) The retained chain-of-thought prompt examples need to cover all fields of cyberspace security, including computer networks, cryptography, databases, blockchains, network attacks and defenses, etc.; (2) The answer needs to include a reasoning process of two to three steps, rather than simply outputting the answer. Therefore, we hope that after the data results of the preliminary experiment, at least two chain-of-thought prompt examples in each sub-field are retained as answer templates.
[0070] Examples of the 10 test questions used in this preliminary experiment are shown in Table 1.
[0071] Table 1 Examples of Preliminary Experiment Test Questions
[0072]
[0073]
[0074] S4: Design of the chain-of-thought prompt method.
[0075] Using the chain-of-thought prompting examples screened in S3, input them into the large language model as the learning samples for few-shot inference of the large model, and then combine the zero-shot inference of the chain-of-thought prompting method with the few-shot inference method by adding "Let's think step by step" at the end of the input question. Through this method, the inference ability of the large language model in the field of network security can be maximally improved.
[0076] The network security academic materials include four categories of documents: domestic conferences, academic journals, dissertations, and Chinese patents in the field of cyberspace security.
[0077] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. The structures, devices, and operation methods not specifically described and explained in the present invention are implemented according to the conventional means in the art without special description and limitation.
Claims
1. A network security knowledge reasoning method based on the chain of thought, characterized in that: The method includes the following steps: S1: Screen network security academic materials, uniformly format the screened materials to obtain network security data corpora for large model pre-training; S2: Conduct network security corpus training; Use the PEFT technology and FlashAttention2 technology to conduct network security corpus training on the basic large model; In S2, the specific steps of network security corpus training are as follows: S21: First, use the PEFT technology to write a pre-training program, parse the pre-training corpus, define the work in the pre-training process, and adjust the dataset path, model configuration, and parameters according to the local configuration; S22: Subsequently, initialize the model and tokenizer, load the pre-trained model and tokenizer, and perform data preprocessing. Let the model tokenize and chunk the input text data to prepare the training data, and then optimize the model configuration again; S23: The pre-training code quantifies and optimizes the settings of the model, matches the model vocabulary size and tokenizer, and initializes the model; S24: Finally, execute the training, including continuing training, evaluation metrics, and automatically saving intermediate training results; S25: During the pre-training process, the FlashAttention2 technology is used to optimize the training acceleration, reducing the time complexity of self-attention calculation from O(n 2 ) to O(n); The pre-training program will receive the pre-training parameters input by the terminal, and the program sets the pre-training log output by the terminal; Then check whether there is a checkpoint left from the previous unfinished pre-training saved in the corresponding file path: If so, load the corresponding checkpoint and continue to execute the previous unfinished pre-training; If not, start initializing the model, first tokenize the pre-training corpus, and then reconnect all the texts in the pre-trained corpus after tokenization, and divide the text into text chunks with a fixed length; After completing the relevant initialization work, enable gradient checkpointing to save important nodes during the pre-training process, then initialize the Trainer, start executing the pre-training program, and output the pre-training log in the terminal; S3: Design thought chain prompt examples using the current thought chain prompting theoretical knowledge; S31: First, artificially construct thought chain problem examples in the field of network security; S32: Subsequently, use chatGPT to generate thought chain answer examples, combine the artificial questions and the answers of chatGPT into a complete thought chain prompt example, and repeat this process to construct a certain amount of thought chain prompt examples; S33: Then conduct a pre-experiment on the thought chain prompt examples to screen out a small number of effective thought chain prompt examples for subsequent use; S4: Design of the thought chain prompting method.
2. The network security knowledge reasoning method based on the chain of thought according to claim 1, wherein: In S3, the thought chain prompt examples need to meet the following requirements: The questions need to cover the field of cyberspace security, including computer networks, cryptography, databases, blockchains, and network attacks and defenses; The answers need to include a reasoning process of two to three steps, rather than simply outputting the answers.
3. A method for reasoning network security knowledge based on a chain of thought according to claim 1, characterized in that: In S4, the thought chain prompt examples screened in S3 are input into the large language model as the learning samples for few-shot inference of the large model. Then, by adding "Let's think step by step" to the end of the input question, the zero-shot inference of the thought chain prompt method is combined with the few-shot inference method.
4. A method for inferring network security knowledge based on a chain of thought according to claim 1, characterized in that: The network security academic materials include four categories of literature: domestic conferences, academic journals, dissertations, and Chinese patents in the field of cyberspace security.
Citation Information
Patent Citations
Question answer generation method and device based on large language model, equipment and medium
CN118093830A
Telephone traffic tag generation method and device, electronic equipment and storage medium
CN118796998A