Method for generating adversarial data set and related device

The method of generating adversarial data sets through large language models is automatically generated, which solves the problem of time-consuming and labor-consuming cooperation among multiple teams in the existing technology, and improves the generation efficiency and convenience.

CN120295913APending Publication Date: 2025-07-11SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510353435.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-11

Smart Images

  • Figure CN120295913A_ABST
    Figure CN120295913A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method for generating an adversarial data set and a related device, which are used for improving the convenience of generating the adversarial data set. The method provided by the embodiment of the invention comprises the following steps: inputting an adversarial demand statement into a large language model to obtain a performance function code in a preset format, which is output by the large language model and corresponds to the adversarial demand statement; compiling the performance function code in the preset format until a description file of the performance function code is generated; and storing the performance function code in the preset format and the description file of the performance function code in a code warehouse.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a method for generating an adversarial dataset and related devices. Background Art

[0002] In the field of network security, "terminal confrontation" refers to the confrontation between network attacks and network defenses. "Terminal" here refers to terminal devices connected to the network, such as computers, servers, smartphones, etc. In this confrontation, attackers attempt to intrude into, damage, or steal target systems or data through various means, while defenders strive to protect systems and data from attacks. This confrontation may involve the use of various technologies and strategies such as malware, vulnerability exploitation, social engineering, encryption technology, etc., and is an important aspect of network security work.

[0003] Currently, when generating an end-side adversarial dataset, it usually requires the cooperation of multiple security teams and various security tools. Among them, the adversarial sample dataset often needs to be written by security developers with rich attack and defense experience, and the collection and analysis of log alerts are usually completed by security investigators and security testers. The entire process is very labor-consuming and relies on the security experience of actual operators. Summary of the Invention

[0004] Embodiments of the present invention provide a method for generating an adversarial dataset and related devices, which are used to improve the convenience of generating an adversarial dataset.

[0005] A first aspect of an embodiment of the present application provides a method for generating an adversarial dataset, including:

[0006] Inputting an adversarial requirement statement into a large language model to obtain function code in a preset format corresponding to the adversarial requirement statement output by the large language model;

[0007] Compiling the function code in the preset format until a description file of the function code is generated;

[0008] Storing the function code in the preset format and the description file of the function code in a code repository.

[0009] As an optional embodiment, the method further includes:

[0010] Inputting an adversarial scenario into the large language model to obtain an adversarial template output by the large language model, where the adversarial template includes an adversarial stage and an adversarial simulation technology category in the adversarial scenario;

[0011] Find at least one target function code for implementing the confrontation stage and the confrontation simulation technology category in the code repository according to the confrontation stage and the confrontation simulation technology category in the confrontation scenario;

[0012] Generate a main function according to the identifier of the at least one target function code;

[0013] Compile the main function and the at least one target function code to obtain at least one confrontation sample corresponding to the confrontation scenario.

[0014] As an optional embodiment, the method further includes:

[0015] Execute the at least one confrontation sample to collect the alarm logs during the execution of the at least one confrontation sample;

[0016] Input the alarm logs and the confrontation template into the large language model for comparative analysis to obtain the analysis result output by the large language model, where the analysis result includes the detected confrontation stage and the corresponding confrontation simulation technology category, and the undetected confrontation stage and the corresponding confrontation simulation technology category.

[0017] As an optional embodiment, before inputting the confrontation requirement statement into the large language model, the method further includes:

[0018] Obtain at least one of the prompt information associated with the confrontation requirement statement and the prior open source code;

[0019] The inputting of the confrontation requirement statement into the large language model includes:

[0020] Input the confrontation requirement statement and at least one of the prompt information and the prior open source code into the large language model.

[0021] As an optional embodiment, compiling the function code in the preset format until a description file of the function code is generated includes:

[0022] Compile the function code in the preset format;

[0023] If the compilation fails, obtain the error log during the compilation;

[0024] Input the error log and the function code in the preset format into the large language model to obtain the function code in the preset format output again by the large language model;

[0025] Compile the function code of the preset format output again until a description file of the function code is generated.

[0026] As an optional embodiment, the description file includes a phase marker, a category marker, a path marker, and a dependency marker, where:

[0027] The phase marker is used to correspondingly describe the adversarial phase in the adversarial scenario;

[0028] The category marker is used to correspondingly describe the simulated technology category in the adversarial scenario;

[0029] The path marker is used to correspondingly describe the storage address of the function code;

[0030] The dependency marker is used to correspondingly describe other functions on which the function code depends.

[0031] The second aspect of the embodiments of the present application provides a computer device, including:

[0032] A proxy component, configured to input an adversarial requirement statement into a large language model to obtain a function code of a preset format corresponding to the adversarial requirement statement output by the large language model;

[0033] The proxy component is further configured to compile the function code of the preset format until a description file of the function code is generated;

[0034] The proxy component is further configured to store the function code of the preset format and the description file of the function code in a code repository.

[0035] Preferably, the proxy component is further configured to:

[0036] Input an adversarial scenario into the large language model to obtain an adversarial template output by the large language model, where the adversarial template includes the adversarial phase and the adversarial simulation technology category in the adversarial scenario;

[0037] According to the adversarial phase and the adversarial simulation technology category in the adversarial scenario, search the code repository for at least one target function code for implementing the adversarial phase and the adversarial simulation technology category;

[0038] Generate a main function according to the identifier of the at least one target function code;

[0039] Compile the main function and the at least one target function code to obtain at least one adversarial sample corresponding to the adversarial scenario.

[0040] Preferably, the proxy component is further configured to:

[0041] Execute the at least one adversarial sample to collect the alarm logs during the execution of the at least one adversarial sample;

[0042] Input the alarm logs and the adversarial template into the large language model for comparative analysis to obtain the analysis result output by the large language model, where the analysis result includes the detected adversarial stage and the corresponding adversarial simulation technology category, as well as the undetected adversarial stage and the corresponding adversarial simulation technology category.

[0043] Preferably, before inputting the adversarial requirement statement into the large language model, the proxy component 301 is further configured to:

[0044] Obtain at least one of the prompt information associated with the adversarial requirement statement and the prior open source code;

[0045] Input the adversarial requirement statement and at least one of the prompt information and the prior open source code into the large language model.

[0046] Preferably, the proxy component is specifically configured to:

[0047] Compile the function code in the preset format;

[0048] If the compilation fails, obtain the error log during the compilation process;

[0049] Input the error log and the function code in the preset format into the large language model to obtain the function code in the preset format output again by the large language model;

[0050] Compile the function code in the preset format output again until a description file of the function code is generated.

[0051] Preferably, the description file includes a stage tag, a category tag, a path tag, and a dependency tag, where:

[0052] The stage tag is used to correspondingly describe the adversarial stage in the adversarial scenario;

[0053] The category tag is used to correspondingly describe the simulation technology category in the adversarial scenario;

[0054] The path tag is used to correspondingly describe the storage address of the function code;

[0055] The dependency tag is used to correspondingly describe other functions on which the function code depends.

[0056] In a third aspect of the embodiments of the present application, a computer device is provided, including a processor and a memory. When the processor executes a computer program stored in the memory, it is used to implement the method for generating an adversarial dataset provided in the first aspect of the embodiments of the present application.

[0057] In a fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it is used to implement the method for generating an adversarial dataset provided in the first aspect of the embodiments of the present application.

[0058] In a fifth aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it is used to implement the method for generating an adversarial dataset provided in the first aspect of the embodiments of the present application.

[0059] From the above technical solutions, it can be seen that the embodiments of the present invention have the following advantages:

[0060] In the embodiments of the present application, an adversarial requirement statement is input into a large language model to obtain functional function code in a preset format corresponding to the adversarial requirement statement output by the large language model; the functional function code in the preset format is compiled until a description file of the functional function code is generated; the functional function code in the preset format and the description file of the functional function code are stored in a code repository. That is, in the embodiments of the present application, by inputting an adversarial requirement statement into a large language model, corresponding functional function code in a preset format can be obtained. Therefore, compared with the prior art in which multiple security teams and multiple security tools need to cooperate with each other when generating an adversarial dataset on the generation side, the convenience and generation efficiency of generating an adversarial dataset are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 It is a schematic diagram of an embodiment of the method for generating an adversarial dataset in the embodiments of the present application;

[0062] Figure 2 It is a schematic diagram of another embodiment of the method for generating an adversarial dataset in the embodiments of the present application;

[0063] Figure 3 It is a schematic diagram of an embodiment of the computer device in the embodiments of the present application;

[0064] Figure 4 It is a schematic diagram of another embodiment of the computer device in the embodiments of the present application. DETAILED DESCRIPTION

[0065] The embodiments of the present invention provide a method for generating an adversarial dataset and related devices, which are used to improve the convenience of generating an adversarial dataset.

[0066] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0067] The terms "first", "second", "third", "fourth", etc. in the specification and claims of the present invention and the above accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order other than that illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0068] For the convenience of understanding, the method for generating an adversarial dataset in the embodiments of the present application will be described in detail below. Please refer to Figure 1 One embodiment of the method for generating an adversarial dataset in the embodiments of the present application includes:

[0069] 101. Input the adversarial requirement statement into a large language model to obtain the functional function code in a preset format output by the large language model corresponding to the adversarial requirement;

[0070] Different from the prior art, when generating an adversarial dataset, multiple security teams and multiple security tools need to cooperate with each other, resulting in time-consuming and laborious problems when generating an adversarial dataset. In the embodiments of the present application, by means of a large language model and an adversarial requirement, the adversarial requirement statement can be input into the large language model, so that the large language model outputs the functional function code in a preset format corresponding to the adversarial requirement statement.

[0071] Specifically, the large language model (LLM) in the embodiments of the present application may be GPT (Generative Pre-trained Transformer), BERT (Bidirectional Encoder Representations from Transformers), T5 (Text-to-Text Transfer Transformer), or M6 model, etc. There is no limitation on the specific type of the large language model here. The large language model in the embodiments of the present application has language understanding ability, code analysis ability, code generation ability, and log / alarm interpretation ability.

[0072] Optionally, the preset format of the functional function code in the embodiments of the present application refers to the functional function code edited in different languages, such as the functional function code in C++, .NET, or powershell format.

[0073] Optionally, the adversarial requirements in the embodiments of the present application may vary according to the requirements of the actual scenario. For example, the adversarial requirements here may be disk encryption requirements, email query requirements, data query requirements, etc. There is no limitation on the specific content of the adversarial requirement statement here.

[0074] 102. Compile the functional function code in the preset format until a description file of the functional function code is generated;

[0075] After obtaining the functional function code in the preset format, use a compilation component to compile the functional function code in the preset format until a description file of the functional function code is generated.

[0076] Specifically, in the embodiments of the present application, the process of compiling the functional function code is the process of compiling the functional function code into an executable program code.

[0077] Optionally, during the process of compiling the functional function code, since the functional function code output by the large language model may not be successfully compiled, in the embodiments of the present application, after inputting the functional function code in the preset format into the compilation component, if the compilation fails, obtain the error log during the compilation process, and input the error log and the functional function code in the preset format into the large language model, so that the large language model modifies the functional function code in the preset format according to the error log to obtain the functional function code in the preset format output again by the large language model, and then compile the functional function code in the preset format output again until a description file of the functional function code is generated.

[0078] Specifically, during the compilation of the functional function code, a description file of the functional function code is generated only when the compilation of the functional function code is successful; otherwise, a compilation failure is prompted and an error log is generated. The description file mainly includes a phase marker, a category marker, a path marker, and a dependency marker. The phase marker is mainly used to describe the adversarial phase in the adversarial scenario where the adversarial requirement statement is located, the category marker is used to describe the simulation technology category in the adversarial scenario, the path marker is used to describe the storage address of the functional function code, and the dependency marker is used to describe other functions on which the functional function code depends.

[0079] 103. Store the functional function code in the preset format and the description file of the functional function code in the code repository.

[0080] After the compilation of the functional function is completed, the functional function code in the preset format and the description file of the functional function code are correspondingly stored in the code repository.

[0081] In the embodiment of the present application, the adversarial requirement statement is input into the large language model to obtain the functional function code in the preset format corresponding to the adversarial requirement statement output by the large language model; the functional function code in the preset format is compiled until the description file of the functional function code is generated; the functional function code in the preset format and the description file of the functional function code are stored in the code repository.

[0082] That is, in the embodiment of the present application, when the adversarial requirement statement is input into the large language model, the corresponding functional function code in the preset format can be obtained. Therefore, compared with the prior art in which multiple security teams and various security tools need to cooperate with each other when generating the adversarial dataset on the terminal side, the convenience and generation efficiency of generating the adversarial dataset are improved.

[0083] As an alternative embodiment, Figure 1 In step 101 of the embodiment, when the large language model generates the functional function code according to the adversarial requirement statement, in order to improve the accuracy of the generated functional function code, in the embodiment of the present application, at least one of the prompt information associated with the adversarial requirement statement and the prior open source code can be input into the large language model together with the adversarial requirement statement, so as to improve the accuracy of the functional function code output by the large language model.

[0084] For easy understanding, the following is an example:

[0085] Suppose the user needs to implement an X function for querying email data, then the following prompt information, adversarial requirement statement, and reference open source code can be given:

[0086] {prompt}: Assume you are a senior development engineer with many years of security development experience, proficient in three programming languages: C++, .NET, and PowerShell. Next, I will provide the code implementation of a certain functional function, and its implementation method may be in any programming language. You need to re-implement the functional function I provided according to the programming languages you are proficient in. When implementing, the following points need to be noted:

[0087] ① You need to implement it in turn using all the languages you are proficient in, and ensure that the parameters received by the functional function are the same when implementing;

[0088] ② If the functional function I provided contains a Main function or a test function, please delete it;

[0089] ③ If the judgment of the execution result is missing in the functional function I provided, please supplement the judgment of the execution result and print the log.

[0090] {question}: My question is: Please re-implement the X function for querying email data for me....

[0091] {Code for reference}: {code......}

[0092] In the embodiments of the present application, when inputting to the large language model, not only the adversarial requirement statements are input, but also the prompt information and the reference open source code are input. As a result, the large language model can generate functional function codes more related to the adversarial requirement statements according to the prompt information, and the reference open source code enables the large language model to have more learning objects. Therefore, the large language model in the embodiments of the present application can output more accurate functional function codes corresponding to the adversarial requirement statements.

[0093] Based on Figure 1 the above-mentioned embodiments, after obtaining the functional function code, in order to obtain more complete adversarial samples, the embodiments of the present application can also perform the following process. Please refer to Figure 2 :

[0094] 201. Input the adversarial scenario into the large language model to obtain the adversarial template output by the large language model, where the adversarial template includes the adversarial stage and the adversarial simulation technology category in the adversarial scenario;

[0095] After obtaining the functional function code corresponding to the adversarial requirement statement, in order to further obtain more adversarial samples, the embodiments of the present application can also input the adversarial scenario into the large language model to obtain the adversarial template output by the large language model, where the adversarial template includes the adversarial stage and the adversarial simulation technology category in the adversarial scenario.

[0096] Specifically, the adversarial scenario in the embodiments of the present application is similar to the ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework. The ATT&CK framework is proposed by the non-profit U.S. research and technology organization MITRE (The MITRE Corporation) to describe the attacker's goals and specific behaviors, mainly including three components: tactics (the goals of performing an action), techniques (the ways to achieve tactical goals), and sub-techniques (more specific or lower-level descriptions compared to techniques). The adversarial phases in the adversarial scenario of the embodiments of the present application are similar to the tactics in the ATT&CK framework, and the adversarial model technology categories are similar to the techniques and sub-techniques in the ATT&CK framework.

[0097] Since the large language model is pre-trained, the large language module has learned various adversarial scenarios, as well as the adversarial phases and adversarial simulation technology categories included in the adversarial scenarios. Therefore, after inputting the adversarial scenario into the large language model, the adversarial phases and adversarial simulation technology categories output by the large language model can be obtained.

[0098] Specifically, the adversarial scenario here can be a document phishing attack activity in the black and gray production scenario, or a disk encryption attack activity in the ransomware scenario, or the latter can be an email phishing and data theft activity in the APT scenario. The specific details of the adversarial scenario are not limited here.

[0099] 202. According to the adversarial phase and the adversarial simulation technology category in the adversarial scenario, find at least one target function code for implementing the adversarial phase and the adversarial simulation technology category from the code repository;

[0100] After obtaining the adversarial phase and the adversarial simulation technology category in the adversarial scenario, the generator can find at least one target function code for implementing each adversarial phase and the corresponding simulation technology category from the code repository according to the adversarial phase and the adversarial simulation technology category.

[0101] Specifically, the more the target function codes here, the more adversarial samples can be generated later.

[0102] 203. Generate a main function according to the identifier of the at least one target function code;

[0103] After obtaining the target objective function, the main function can be generated according to the identifier of the target objective function and the execution order among the target objective functions. The main function contains the identifiers of the codes of each target objective function and the execution order of the codes of each target objective function, so that the compilation component can compile the main function and the codes of at least one target objective function, thereby obtaining multiple adversarial samples corresponding to the adversarial scenario.

[0104] 204. Compile the main function and the codes of the at least one target objective function to obtain at least one adversarial sample corresponding to the adversarial scenario.

[0105] Specifically, after obtaining the main function, the compilation component can be used to repeatedly compile the main function and the codes of at least one target objective function, thereby obtaining at least one adversarial sample corresponding to the adversarial scenario.

[0106] 205. Execute the at least one adversarial sample to collect the alarm logs during the execution of the at least one adversarial sample;

[0107] To test the aggressiveness of these adversarial samples, in the embodiments of the present application, after obtaining the adversarial samples, these adversarial samples can be executed, and during the adversarial process, the collection component is used to collect the alarm logs during the adversarial execution process of these adversarial samples.

[0108] 206. Input the alarm logs and the adversarial template into the large language model for comparative analysis to obtain the analysis result output by the large language model, where the analysis result includes the detected adversarial stage and the corresponding adversarial simulation technology category, and the undetected adversarial stage and the corresponding adversarial simulation technology category.

[0109] And to evaluate the aggressiveness of these adversarial samples, in the embodiments of the present application, the collected alarm logs and the adversarial template (the adversarial template includes the adversarial stage and the adversarial simulation technology category of each adversarial stage) can also be input into the large language model, so that the large language model performs comparison and analysis on the alarm logs and the adversarial model to obtain the analysis result output by the large language model, where the analysis structure includes the detected adversarial stage and the corresponding adversarial simulation technology category for the adversarial sample, and the undetected adversarial stage and the corresponding adversarial simulation technology category.

[0110] After obtaining the adversarial samples in the embodiments of the present application, the adversarial samples can also be executed to collect the alarm logs during the running process of the adversarial samples, and the large language model is used to compare the adversarial stage and the adversarial simulation technology category in the alarm logs and the adversarial template corresponding to the adversarial samples, thereby obtaining the test evaluation data for the adversarial samples.

[0111] Furthermore, the adversarial examples and test evaluation data in the embodiments of the present application can be directly applied to various security protection software or security models to verify their response capabilities to complex and variable attacks, and the detection capabilities of various security protection software or security models can be improved by using the adversarial dataset.

[0112] It can be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above steps do not mean the sequence of execution. The execution sequence of each step should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0113] The method for generating an adversarial dataset in the embodiments of the present application has been described in detail above. Next, the computer device in the embodiments of the present application will be described. Please refer to Figure 3 , the computer device in the embodiments of the present application includes:

[0114] The proxy component 301 is configured to input an adversarial requirement statement into the large language model 302 to obtain a function code in a preset format corresponding to the adversarial requirement statement output by the large language model 302;

[0115] The proxy component 301 is further configured to compile the function code in the preset format until a description file of the function code is generated;

[0116] The proxy component 301 is further configured to store the function code in the preset format and the description file of the function code in the code repository 303.

[0117] Preferably, the proxy component 301 is further configured to:

[0118] Input an adversarial scenario into the large language model 302 to obtain an adversarial template output by the large language model 302, where the adversarial template includes an adversarial stage and an adversarial simulation technology category in the adversarial scenario;

[0119] According to the adversarial stage and the adversarial simulation technology category in the adversarial scenario, at least one target function code for implementing the adversarial stage and the adversarial simulation technology category is searched from the code repository 303;

[0120] Generate a main function according to the identifier of the at least one target function code;

[0121] Compile the main function and the at least one target function code to obtain at least one adversarial example corresponding to the adversarial scenario.

[0122] Preferably, the proxy component 301 is further configured to:

[0123] Execute the at least one adversarial sample to collect the alarm logs during the execution of the at least one adversarial sample;

[0124] Input the alarm logs and the adversarial template into the large language model 302 for comparative analysis to obtain the analysis result output by the large language model 302, where the analysis result includes the detected adversarial stage and the corresponding adversarial simulation technology category, as well as the undetected adversarial stage and the corresponding adversarial simulation technology category.

[0125] Preferably, before inputting the adversarial requirement statement into the large language model, the proxy component 301 is further configured to:

[0126] Obtain at least one of the prompt information associated with the adversarial requirement statement and the prior open source code;

[0127] Input the adversarial requirement statement and at least one of the prompt information and the prior open source code into the large language model 302.

[0128] Preferably, the proxy component 301 is specifically configured to:

[0129] Compile the function code in the preset format;

[0130] If the compilation fails, obtain the error logs during the compilation process;

[0131] Input the error logs and the function code in the preset format into the large language model to obtain the function code in the preset format output again by the large language model;

[0132] Compile the function code in the preset format output again until a description file of the function code is generated.

[0133] Preferably, the description file includes a stage marker, a category marker, a path marker, and a dependency marker, where:

[0134] The stage marker is used to correspondingly describe the adversarial stage in the adversarial scenario;

[0135] The category marker is used to correspondingly describe the simulation technology category in the adversarial scenario;

[0136] The path marker is used to correspondingly describe the storage address of the function code;

[0137] The dependency marker is used to correspondingly describe other functions on which the function code depends.

[0138] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described proxy component, large language model, and code repository can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0139] An embodiment of this application also provides a computer program product, on which a computer program is stored. When the computer program is executed by a processor, it is used to implement each step described in the above method embodiments.

[0140] The computer device in the embodiments of the present invention has been described above from the perspective of modular functional entities. The computer device in the embodiments of the present invention will be described below from the perspective of hardware processing:

[0141] Please refer to Figure 4 , an embodiment of the computer device in the embodiments of the present invention includes:

[0142] It includes one or more central processing units (CPUs) 401 and a memory 405, and one or more application programs or data are stored in the memory 405.

[0143] Among them, the memory 405 can be volatile storage or persistent storage. The program stored in the memory 405 can include one or more modules, and each module can include a series of instruction operations on the server. Further, the central processor 401 can be set to communicate with the memory 405 and execute a series of instruction operations in the memory 405 on the computer device.

[0144] The computer device may further include one or more power supplies 402, one or more wired or wireless network interfaces 403, one or more input / output interfaces 404, and / or one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.

[0145] The central processor 401 can execute each step in the above method embodiments.

[0146] It can be understood that when the processor in the computer device described above executes the computer program, it can also implement the functions of each unit in the corresponding device embodiments described above, which will not be elaborated here. Exemplarily, the computer program can be divided into one or more modules / units, and the one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the computer device. For example, the computer program can be divided into the respective units in the above computer device, and each unit can implement the specific functions as described in the corresponding computer device above.

[0147] The computer device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device may include but is not limited to a processor and a memory. Those skilled in the art can understand that the processor and the memory are only examples of the computer device and do not constitute a limitation on the computer device. It may include more or fewer components, or combine certain components, or different components. For example, the computer device may further include input / output devices, network access devices, a bus, etc.

[0148] The processor can be a central processing unit (CPU), or can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The processor is the control center of the computer device, and connects various parts of the entire computer device through various interfaces and lines.

[0149] The memory can be used to store the computer programs and / or modules. By running or executing the computer programs and / or modules stored in the memory, and invoking the data stored in the memory, the processor realizes various functions of the computer device. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices.

[0150] The present invention also provides a computer-readable storage medium for realizing the functions of a computer device, on which a computer program is stored. When the computer program is executed by a processor, the processor can realize each step in the above method embodiments.

[0151] It can be understood that if the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a corresponding computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above corresponding method embodiments of the present invention, it can also be completed by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be realized. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0152] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.

[0153] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0154] In addition, each functional unit in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0155] As mentioned above, the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of various embodiments of the present invention.

Claims

1. A method for generating an adversarial dataset, characterized in that, Comprising: Inputting the adversarial requirement statement into a large language model to obtain the functional function code in a preset format corresponding to the adversarial requirement statement output by the large language model; Compiling the functional function code in the preset format until a description file of the functional function code is generated; Storing the functional function code in the preset format and the description file of the functional function code in a code repository.

2. The method according to claim 1, wherein The method further comprises: Inputting the adversarial scenario into the large language model to obtain an adversarial template output by the large language model, wherein the adversarial template includes the adversarial phase and the adversarial simulation technology category in the adversarial scenario; According to the adversarial phase and the adversarial simulation technology category in the adversarial scenario, searching in the code repository for at least one target functional function code for implementing the adversarial phase and the adversarial simulation technology category; Generating a main function according to the identifier of the at least one target functional function code; Compiling the main function and the at least one target functional function code to obtain at least one adversarial sample corresponding to the adversarial scenario.

3. The method according to claim 2, wherein The method further comprises: Executing the at least one adversarial sample to collect the alarm logs during the execution of the at least one adversarial sample; Inputting the alarm logs and the adversarial template into the large language model for comparative analysis to obtain an analysis result output by the large language model, wherein the analysis result includes the detected adversarial phase and the corresponding adversarial simulation technology category, and the undetected adversarial phase and the corresponding adversarial simulation technology category.

4. The method according to claim 1, wherein Before inputting the adversarial requirement statement into the large language model, the method further comprises: Obtaining at least one of the prompt information associated with the adversarial requirement statement and the prior open source code; The inputting the adversarial requirement statement into the large language model includes: Inputting the adversarial requirement statement and at least one of the prompt information and the prior open source code into the large language model.

5. The method according to claim 1, wherein Compiling the functional function code in the preset format until a description file of the functional function code is generated, including: Compiling the functional function code in the preset format; If the compilation fails, obtaining the error log during the compilation; Inputting the error log and the functional function code in the preset format into the large language model to obtain the functional function code in the preset format output again by the large language model; Compiling the functional function code output again until a description file of the functional function code is generated.

6. The method according to claim 1, characterized in that, The description file includes a phase tag, a category tag, a path tag, and a dependency tag, wherein: The phase tag is used to correspondingly describe the adversarial phase in the adversarial scenario; The category tag is used to correspondingly describe the simulation technology category in the adversarial scenario; The path tag is used to correspondingly describe the storage address of the functional function code; The dependency tag is used to correspondingly describe other functions on which the functional function code depends.

7. A computer device, characterized in that, Comprising: A proxy component for inputting an adversarial requirement statement into a large language model to obtain a function code in a preset format corresponding to the adversarial requirement statement output by the large language model; The proxy component is further configured to compile the function code in the preset format until a description file of the function code is generated; The proxy component is further configured to store the function code in the preset format and the description file of the function code in a code repository.

8. A computer device, comprising a processor and a memory, characterized in that When the processor executes the computer program stored in the memory, it is configured to implement the method for generating an adversarial dataset according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it is configured to implement the method for generating an adversarial dataset according to any one of claims 1 to 6.

10. A computer program product having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it is configured to implement the method for generating an adversarial dataset according to any one of claims 1 to 6.