arXiv:cs.AI· Lin Cui, Vincenzo Scotti, Raffaela Mirandola·· 5 小时前AI 评分33
CVE2AP:用大语言模型从 CVE 描述自动生成 PDDL 攻击路径
CVE2AP: Automated Generation of PDDL-Encoded Attack Paths via Large Language Models
AI 导读
CVE2AP 是一种基于 LLM 的方法,可从自然语言 CVE 描述自动生成 PDDL 编码的攻击路径,通过结构化提示与规划器报错反馈迭代修正生成结果。在多个 LLM 与生成配置的系统评测中,该方法最高达到 86.9% 语法正确率、78.6% 可解性和 93.1% 语义正确率(LLM-as-expert 评估),其中 GPT-5.5 在质量与成本间取得最佳平衡,错误反馈带来最稳定的质量提升。
正文
Abstract:Attack Path (AP) modeling is fundamental to cybersecurity analysis, where the Planning Domain Definition Language (PDDL) has been widely adopted to encode APs into formal and machine-verifiable representations for automated reasoning about vulnerability exploitation, attack progression, and their potential impacts. However, existing AP modeling approaches largely rely on expert-driven manual construction, limiting their scalability and ability to keep pace with rapidly evolving cyber threats. Large language models (LLMs) are promising candidates, as their extensive pre-trained knowledge and reasoning capabilities enable them to interpret and transform threat intelligence into formal representations. In this paper, we propose \textbf{CVE2AP}, an LLM-based approach for automatically generating PDDL-encoded attack paths from natural language CVE (Common Vulnerability Exposure) descriptions. CVE2AP leverages structured prompting and incorporates an error-feedback mechanism that iteratively refines the generated paths using planner-reported syntactic and solvability errors. We conduct a systematic empirical evaluation across multiple LLMs and generation configurations, assessing generation quality across syntactic, solvability and semantic dimensions, together with token consumption and generation time. The results demonstrate that CVE2AP effectively generates high-quality PDDL-encoded attack paths, achieving up to 86.9\% syntax correctness, 78.6\% solvability, and 93.1\% semantic correctness under LLM-as-expert evaluation, while \texttt{GPT-5.5} offers the best quality-cost trade-off and error feedback yields the most consistent quality improvement.
| Subjects: | Artificial Intelligence (cs.AI) |
| Cite as: | arXiv:2610.03383 [cs.AI] |
| (or arXiv:2610.03383v1 [cs.AI] for this version) | |
| https://doi.org/10.48550/arXiv.2610.03383 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Lin Cui [view email]
[v1]
Fri, 2 Oct 2026 14:35:44 UTC (1,183 KB)
来源:arXiv:cs.AI · arxiv.org