GraphGuard: Graph-Constrained Neuro-Symbolic Synthesis of Network Defense Configurations
Abstract
Translating high-level intents into executable configurations is essential for modern network defense. Existing Large Language Model (LLM)- and Retrieval-Augmented Generation-based methods still rely heavily on unconstrained LLM reasoning to assemble configuration fields and instantiate runtime parameters, making reliable configuration synthesis difficult. This difficulty stems from fragmented configuration knowledge across heterogeneous devices, interdependent configuration choices tied to dynamic network contexts, and generated configurations that may violate deterministic constraints or deployment requirements. To address these issues, we propose GraphGuard, a graph-constrained neuro-symbolic framework that translates high-level defense intents into verified configurations for heterogeneous devices. GraphGuard organizes configuration knowledge into a unified typed five-slot space, uses graph-constrained joint synthesis to compose compatible configuration components, and deterministically instantiates runtime-dependent parameters under explicit operational constraints. A structured verifier then guides bounded repair through graph-defined legal edits, while a backend-independent Intermediate Representation (IR) enables device-specific compilation. Experiments in heterogeneous DDoS mitigation environments show that GraphGuard achieves 93.45% Joint Exact Match and 75.41% Safe Synthesis Success, with a 1.50% unsafe acceptance rate on infeasible instances, while maintaining practical end-to-end synthesis latency.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.