Depending on yourself when you should: Mentoring LLM with RL agents to become the master in cybersecurity games

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yan, Yikuan, Zhang, Yaolun, Huang, Keman
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913284834197504
author Yan, Yikuan
Zhang, Yaolun
Huang, Keman
author_facet Yan, Yikuan
Zhang, Yaolun
Huang, Keman
contents Integrating LLM and reinforcement learning (RL) agent effectively to achieve complementary performance is critical in high stake tasks like cybersecurity operations. In this study, we introduce SecurityBot, a LLM agent mentored by pre-trained RL agents, to support cybersecurity operations. In particularly, the LLM agent is supported with a profile module to generated behavior guidelines, a memory module to accumulate local experiences, a reflection module to re-evaluate choices, and an action module to reduce action space. Additionally, it adopts the collaboration mechanism to take suggestions from pre-trained RL agents, including a cursor for dynamic suggestion taken, an aggregator for multiple mentors' suggestions ranking and a caller for proactive suggestion asking. Building on the CybORG experiment framework, our experiences show that SecurityBot demonstrates significant performance improvement compared with LLM or RL standalone, achieving the complementary performance in the cybersecurity games.
format Preprint
id arxiv_https___arxiv_org_abs_2403_17674
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Depending on yourself when you should: Mentoring LLM with RL agents to become the master in cybersecurity games
Yan, Yikuan
Zhang, Yaolun
Huang, Keman
Cryptography and Security
Artificial Intelligence
Multiagent Systems
Integrating LLM and reinforcement learning (RL) agent effectively to achieve complementary performance is critical in high stake tasks like cybersecurity operations. In this study, we introduce SecurityBot, a LLM agent mentored by pre-trained RL agents, to support cybersecurity operations. In particularly, the LLM agent is supported with a profile module to generated behavior guidelines, a memory module to accumulate local experiences, a reflection module to re-evaluate choices, and an action module to reduce action space. Additionally, it adopts the collaboration mechanism to take suggestions from pre-trained RL agents, including a cursor for dynamic suggestion taken, an aggregator for multiple mentors' suggestions ranking and a caller for proactive suggestion asking. Building on the CybORG experiment framework, our experiences show that SecurityBot demonstrates significant performance improvement compared with LLM or RL standalone, achieving the complementary performance in the cybersecurity games.
title Depending on yourself when you should: Mentoring LLM with RL agents to become the master in cybersecurity games
topic Cryptography and Security
Artificial Intelligence
Multiagent Systems
url https://arxiv.org/abs/2403.17674