English  |  正體中文  |  简体中文  |  全文筆數/總筆數 : 83776/83776 (100%)
造訪人次 : 58596379      線上人數 : 2479
RC Version 7.0 © Powered By DSPACE, MIT. Enhanced by NTU Library IR team.
搜尋範圍 查詢小技巧:
  • 您可在西文檢索詞彙前後加上"雙引號",以獲取較精準的檢索結果
  • 若欲以作者姓名搜尋,建議至進階搜尋限定作者欄位,可獲得較完整資料
  • 進階搜尋


    請使用永久網址來引用或連結此文件: https://ir.lib.ncu.edu.tw/handle/987654321/98215


    題名: DLEX:強化跨站腳本攻擊載荷偵測之大型語言模型回饋框架;DLEX: A Feedback driven LLM Framework for Evolving XSS detection Models
    作者: 鄭宇翔;Cheng, Yu-Hsiang
    貢獻者: 資訊工程學系
    關鍵詞: 跨站網頁腳本;大型語言模型;對抗生成樣本;Large Language Models;Cross-site Scripting;Adversarial Payload Generation
    日期: 2025-07-07
    上傳時間: 2025-10-17 12:30:12 (UTC+8)
    出版者: 國立中央大學
    摘要: 在網路安全領域中,跨站腳本攻擊依然是最常見且危害性極高的漏洞之一。對於該攻擊,已有不少基於深度學習的跨站腳本載荷偵測模型被提出,但面對新型態或變異型的惡意載荷仍容易失效,導致防禦系統產生誤判或漏報。
    為了解決此問題,本研究提出一個以大型語言模型為基礎的自我學習架構,利用大型語言模型具備語義理解能力、低建置成本、快速部署等優勢,相較於傳統的強化學習方式能更有效率地生成語意多樣且具滲透性的攻擊樣本,能自動生成具滲透能力的對抗型跨站腳本載荷,並作為深度學習模型的訓練資料,以持續強化其偵測能力。
    本架構結合大型語言模型、對抗樣本設計與自動回饋機制,使偵測模型能在實驗環境中不斷對抗與學習新型攻擊,進而提升其穩健性與泛化能力。實驗結果顯示,透過本方法訓練後的模型,能有效提升對變異型載荷的偵測準確度,展現出此方法在主動防禦設計上的潛力。
    ;Cross-site scripting (XSS) remains one of the most prevalent and dangerous web security threats. Although many deep learning-based models have been proposed for detecting XSS attacks, they often fail to detect novel or obfuscated payloads, resulting in false negatives and system vulnerabilities.

    To solve this problem, this research proposes a self-learning framework using large language models (LLMs). The framework can automatically create XSS attack payloads that are able to get past common security filters. By leveraging the semantic understanding, low training cost, and rapid deployment capabilities of LLMs, this framework outperforms traditional RL-based approaches in efficiently generating diverse and hard-to-detect attack samples. These generated payloads are then used to improve the robustness of deep learning-based detection models.

    The proposed framework combines LLM, adversarial sample creation, and feedback loop to simulate a continuous attack-defense situation. This allows the detection model to learn from new attack samples and improve its ability to handle different types of attacks. Test results show that the model trained with LLM-generated attack payloads improves its robustness for evasive attacks. This work shows that using LLMs with self-learning systems can help build more active and effective cybersecurity solutions.
    顯示於類別:[資訊工程研究所] 博碩士論文

    文件中的檔案:

    檔案 描述 大小格式瀏覽次數
    index.html0KbHTML3檢視/開啟


    在NCUIR中所有的資料項目都受到原著作權保護.

    社群 sharing

    ::: Copyright National Central University. | 國立中央大學圖書館版權所有 | 收藏本站 | 設為首頁 | 最佳瀏覽畫面: 1024*768 | 建站日期:8-24-2009 :::
    DSpace Software Copyright © 2002-2004  MIT &  Hewlett-Packard  /   Enhanced by   NTU Library IR team Copyright ©   - 隱私權政策聲明