面向工业互联网安全防护的安全大模型构建方法及应用
By constructing a large-scale security model for industrial internet security protection, and combining a retrieval-enhanced generation mechanism with a security-specific knowledge base, the problems of timeliness, illusion, and lack of specialized security knowledge in traditional LLM in the field of cybersecurity are solved, enabling efficient and accurate security situation analysis and attack tactics identification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TONGJI UNIV
- Filing Date
- 2025-05-06
- Publication Date
- 2026-07-17
AI Technical Summary
Traditional large-scale language models (LLMs) suffer from problems such as knowledge timeliness, illusion, and lack of specialized security knowledge in the field of cybersecurity. They are unable to adapt to the rapidly changing cybersecurity environment, and their retrieval and generation are disconnected, lacking professional fine-tuning strategies, which limits their reasoning capabilities.
The base model GLM-4 is used to build a knowledge retrieval module that connects to the MITRE ATT&CK knowledge base. Semantic embedding vectors are generated through the BGE-M3 model. A FAISS vector database is built for efficient storage and retrieval. A retrieval enhancement generation mechanism is initiated to dynamically introduce network security knowledge, optimize context generation, and verify the model in conjunction with the RAG mechanism.
It significantly reduces the model illusion problem, improves the accuracy and response speed of security content generation, and enhances the interpretability and identification capabilities of security situation analysis, especially in security situation analysis and network attack tactics identification in specialized security scenarios.
Smart Images

Figure CN120455066B_ABST