面向工业互联网安全防护的安全大模型构建方法及应用

By constructing a large-scale security model for industrial internet security protection, and combining a retrieval-enhanced generation mechanism with a security-specific knowledge base, the problems of timeliness, illusion, and lack of specialized security knowledge in traditional LLM in the field of cybersecurity are solved, enabling efficient and accurate security situation analysis and attack tactics identification.

CN120455066BActive Publication Date: 2026-07-17TONGJI UNIV +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TONGJI UNIV
Filing Date
2025-05-06
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Traditional large-scale language models (LLMs) suffer from problems such as knowledge timeliness, illusion, and lack of specialized security knowledge in the field of cybersecurity. They are unable to adapt to the rapidly changing cybersecurity environment, and their retrieval and generation are disconnected, lacking professional fine-tuning strategies, which limits their reasoning capabilities.

Method used

The base model GLM-4 is used to build a knowledge retrieval module that connects to the MITRE ATT&CK knowledge base. Semantic embedding vectors are generated through the BGE-M3 model. A FAISS vector database is built for efficient storage and retrieval. A retrieval enhancement generation mechanism is initiated to dynamically introduce network security knowledge, optimize context generation, and verify the model in conjunction with the RAG mechanism.

Benefits of technology

It significantly reduces the model illusion problem, improves the accuracy and response speed of security content generation, and enhances the interpretability and identification capabilities of security situation analysis, especially in security situation analysis and network attack tactics identification in specialized security scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455066B_ABST
    Figure CN120455066B_ABST
Patent Text Reader

Abstract

本申请涉及大语言模型与网络安全技术领域,特别涉及一种面向工业互联网安全防护的安全大模型构建方法及应用,该方法包括以下步骤:加载基座大模型GLM‑4,并构建知识检索模块,接入MITRE ATT&CK知识库;对MITRE ATT&CK知识库内的安全知识进行知识特征嵌入向量化;搭建向量数据库存储与检索模块;启动检索增强生成机制,加载测试数据集mitre‑ttp‑mapping;分别构建本地模型和对比模型,开展模型对比实验;评估所构建的安全大模型在网络安全态势分析任务中的表现,评估应用检索增强生成(RAG)机制后模型的改进效果,输出基于RAG的安全大模型方案。本申请适用于企业、工业、移动等多场景下的安全态势评估,并能够提升安全内容生成的准确性和可解释性。
Need to check novelty before this filing date? Find Prior Art