| Item type |
Journal(1) |
| 公開日 |
2026-08-15 |
| タイトル |
|
|
言語 |
ja |
|
タイトル |
RAGを用いたサイバーセキュリティ演習シナリオ生成フレームワークの提案 |
| タイトル |
|
|
言語 |
en |
|
タイトル |
A RAG-based Framework for Generating Cybersecurity Training Scenarios |
| 言語 |
|
|
言語 |
jpn |
| キーワード |
|
|
主題Scheme |
Other |
|
主題 |
[一般論文(推薦論文, 特選論文)] 大規模言語モデル,RAG,ゲーム学習,サイバーセキュリティ教育 |
| 資源タイプ |
|
|
資源タイプ識別子 |
http://purl.org/coar/resource_type/c_6501 |
|
資源タイプ |
journal article |
| ID登録 |
|
|
ID登録 |
10.20729/0002011021 |
|
ID登録タイプ |
JaLC |
| 著者所属 |
|
|
|
中央大学ELSIセンター |
| 著者所属 |
|
|
|
電気通信大学大学院情報理工学研究科 |
| 著者所属 |
|
|
|
中央大学ELSIセンター |
| 著者所属(英) |
|
|
|
en |
|
|
ELSI Center, Chuo University |
| 著者所属(英) |
|
|
|
en |
|
|
Graduate School of Informatics and Engineering Department of Informatics, The University of Electro-Communications |
| 著者所属(英) |
|
|
|
en |
|
|
ELSI Center, Chuo University |
| 著者名 |
津田,敦哉
清,雄一
松崎,和賢
|
| 著者名(英) |
Atsuya Tsuda
Yuichi Sei
Kazutaka Matsuzaki
|
| 論文抄録 |
|
|
内容記述タイプ |
Other |
|
内容記述 |
本論文では,LLM(大規模言語モデル)およびRAG(Retrieval-Augmented Generation)を用いた,サイバーセキュリティ初学者向けのインシデント対応演習シナリオ生成手法の開発について述べる.日本国内におけるセキュリティ人材の不足は深刻な状況にあり,人材育成は喫緊の課題である.筆者らはこれまで,初学者に対するデジタルゲームを用いた教育プログラムの開発・提供に取り組んできたが,ゲームのインタラクティブ性が低いことが課題となっていた.また,セキュリティに関連して,技術・法律等の多角的な内容や,組織ごとにカスタマイズされた内容を含む訓練を,対話的かつ低コストで提供可能とする手法は知る限りない.そこで本研究では,LLMおよびRAGを組み合わせた動的かつ適応的な演習シナリオ生成フレームワークを提案する.具体的には,RAGの要素技術を組み合わせて,大局的な文脈理解と局所的な情報取得を両立するハイブリッド・インデクシング機構と,参照ドキュメントや出力等の品質管理機構を備えるシナリオ生成システムを構築し,専門性と一貫性の両方を満たすシナリオの自動生成を試みた.シナリオ生成実験を行い,性能面の測定や品質面でのユーザ評価等を実施した結果,提案手法は,LLMのみを用いるベースラインと同程度の処理性能を維持しつつ,より有用で具体性の高いシナリオを生成できる可能性が示唆された. |
| 論文抄録(英) |
|
|
内容記述タイプ |
Other |
|
内容記述 |
This paper presents a method for generating incident response training scenarios for cybersecurity beginners, using Large Language Models (LLMs) and Retrieval-Augmented Generation (RAG). Japan faces a serious shortage of cybersecurity professionals, highlighting the need for workforce development. The authors have developed educational programs using digital games. However, a major challenge in our previous work has been their low interactivity. To our knowledge, no existing method enables the interactive and low-cost provision of cybersecurity training that covers multifaceted technical and legal aspects while allowing customization to specific organizational needs. To address these challenges, this study proposes a dynamic and adaptive scenario generation framework that combines LLMs and RAG. Specifically, we constructed a scenario generation system equipped with a hybrid indexing mechanism that balances global contextual understanding and local information retrieval, as well as quality management functions for source documents and generated outputs, with the aim of generating scenarios that demonstrate both domain expertise and consistency. We conducted scenario generation experiments to measure processing performance and to obtain user evaluations of scenario quality. The results suggest that the proposed method has the potential to generate more useful and more concrete scenarios while maintaining processing performance comparable to that of an LLM-only baseline. |
| 書誌レコードID |
|
|
収録物識別子タイプ |
NCID |
|
収録物識別子 |
AN00116647 |
| 書誌情報 |
情報処理学会論文誌
巻 67,
号 8,
p. 1251-1261,
発行日 2026-08-15
|
| ISSN |
|
|
収録物識別子タイプ |
ISSN |
|
収録物識別子 |
1882-7764 |
| 公開者 |
|
|
言語 |
ja |
|
出版者 |
情報処理学会 |