基于混合架构的SLM-LLM协同垃圾邮件检测方法An SLM-LLM collaborative spam detection method based on hybrid architecture
刘志豪,郭师光
摘要(Abstract):
针对人工智能生成内容(artificial intelligence generated content, AIGC)驱动下垃圾邮件从“规模化泛播”向“语义化对抗”演进的威胁,传统小参数语言模型(small language model, SLM)在应对语义去特征化攻击时存在认知盲区,而大语言模型(large language model,LLM)的直接应用则受限于高昂算力成本与判别偏见。对此,提出了一种基于混合架构的SLMLLM协同垃圾邮件检测方法。深入研究了SLM与LLM在中文垃圾邮件检测场景下的效能边界,剖析了通用LLM因安全对齐机制诱发的“礼貌偏见”及其漏报机理,并提出了结构化思维链(chain-of-thought, CoT)补偿策略。据此,利用置信度窗口机制实现流量的动态分流与专家级深度仲裁,设计并实现了一种SLM-LLM异步协同检测架构。实验结果表明,该架构在维持毫秒级平均响应时延的同时,将综合算力成本降低约84.78%,F1值提升至0.950 7,显著优于LoRA微调LLMs、蒸馏SLMs等单一模型方案,为AIGC时代的邮件安全治理提供了高效、低成本的技术范式。
关键词(KeyWords): 垃圾邮件检测;大语言模型;思维链推理;双模型混合架构;安全对齐偏见
基金项目(Foundation):
作者(Author): 刘志豪,郭师光
DOI: 10.16508/j.cnki.11-5866/n.2026.04.009
参考文献(References):
- [1]陈远志,陈飞跃,郎君.钓鱼邮件攻击态势和技术发展[J].信息安全与通信保密,2023(10):50-59.Chen Yuanzhi,Chen Feiyue,Lang Jun. Phishing email attack trends and technology development[J]. Information Security and Communications Privacy,2023(10):50-59.(in Chinese)
- [2]张弛,翁方宸,张玉清. ChatGPT在网络安全领域的应用、现状与趋势[J].信息安全研究,2023,9(6):500-509.Zhang Chi, Weng Fangchen, Zhang Yuqing. ChatGPT's applications,status and trends in the field of cyber security[J].Journal of Information Security Research,2023,9(6):500-509.(in Chinese)
- [3]张建,严珂,马祥.基于神经网络的复杂垃圾信息过滤算法分析[J].计算机应用,2022,42(3):770-777.Zhang Jian,Yan Ke,Ma Xiang. Analysis of complex spam filtering algorithm based on neural network[J]. Journal of Computer Applications,2022,42(3):770-777.(in Chinese)
- [4]Devlin J,Chang Mingwei,Lee K,et al. BERT:pre-training of deep bidirectional transformers for language understanding[C]//Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics:Human Language Technologies,Volume 1(Long and Short Papers).Stroudsburg:Association for Computational Linguistics,2019:4171-4186.
- [5]Liu Yinhan,Ott M,Goyal N,et al. RoBERTa:a robustly optimized BERT pretraining approach[PP/OL].(2019-07-26)[2025-12-15]. https://arxiv. org/abs/1907. 11692.
- [6]顾孟钧,冯文舟,陈中兵.不同长度下中文垃圾邮件分类模型的研究[J].工业信息安全,2022(7):28-35.Gu Mengjun,Feng Wenzhou,Chen Zhongbing. Performance and selection of Chinese spam classification model under different lengths[J]. Industry Information Security,2022(7):28-35.(in Chinese)
- [7]单晨棱,张新有,邢焕来,等.一种基于内容和ERNIE3. 0-CapsNet的中文垃圾邮件识别方法[J].信息安全研究,2024,10(3):233-240.Shan Chenleng,Zhang Xinyou,Xing Huanlai,et al. A Chinese spam detection method based on content and ERNIE3. 0-CapsNet[J]. Journal of Information Security Research,2024,10(3):233-240.(in Chinese)
- [8]周泽元,班秋成,曹刚.基于生成式对抗网络的网络钓鱼攻击识别方法[J].网络安全和信息化,2025(6):142-144.Zhou Zeyuan,Ban Qiucheng,Cao Gang. A phishing attack detection method based on generative adversarial networks[J].Security&Informatization,2025(6):142-144.(in Chinese)
- [9]金建栋,黄正,胡占宇,等.基于智能体工作流的高级钓鱼邮件检测方法[J].通信学报,2024,45(增刊2):59-68.Jin Jiandong, Huang Zheng, Hu Zhanyu, et al. PhishingAgent:an agentic workflow method for advanced phishing email detection[J]. Journal on Communications,2024,45(S2):59-68.(in Chinese)
- [10]Hu E J,Shen Yelong,Wallis P,et al. LoRA:low-rank adaptation of large language models[C]//ICLR 2022,2022:1-13.
- [11]Bai Jinze,Bai Shuai,Chu Yunfei,et al. Qwen technical report[PP/OL].(2023-09-28)[2025-12-20]https://arxiv. org/abs/2309. 16609.
- [12]李子川,季铎,周嵩.基于语言模型与低秩适配的钓鱼邮件高效检测方法[J].信息安全研究,2025,11(12):1117-1124.Li Zichuan,Ji Duo,Zhou Song. An efficient detection method of phishing email based on language model and LoRA[J]. Journal of Information Security Research,2025,11(12):1117-1124.(in Chinese)
- [13]闫驰,张贵强,郑礼.基于交叉注意力和原型学习的小样本钓鱼邮件检测[J].海军工程大学学报,2025,37(1):91-97.Yan Chi,Zhang Guiqiang,Zheng Li. Cross-attention and prototype learning for few-shot phishing mail detection[J].Journal of Naval University of Engineering,2025,37(1):91-97.(in Chinese)