acceptodds
Under review as a conference paper at ICLR 2027

GraphGuard: Graph-Constrained Neuro-Symbolic Synthesis of Network Defense Configurations

Abstract

Translating high-level intents into executable configurations is essential for modern network defense. Existing Large Language Model (LLM)- and Retrieval-Augmented Generation-based methods still rely heavily on unconstrained LLM reasoning to assemble configuration fields and instantiate runtime parameters, making reliable configuration synthesis difficult. This difficulty stems from fragmented configuration knowledge across heterogeneous devices, interdependent configuration choices tied to dynamic network contexts, and generated configurations that may violate deterministic constraints or deployment requirements. To address these issues, we propose GraphGuard, a graph-constrained neuro-symbolic framework that translates high-level defense intents into verified configurations for heterogeneous devices. GraphGuard organizes configuration knowledge into a unified typed five-slot space, uses graph-constrained joint synthesis to compose compatible configuration components, and deterministically instantiates runtime-dependent parameters under explicit operational constraints. A structured verifier then guides bounded repair through graph-defined legal edits, while a backend-independent Intermediate Representation (IR) enables device-specific compilation. Experiments in heterogeneous DDoS mitigation environments show that GraphGuard achieves 93.45% Joint Exact Match and 75.41% Safe Synthesis Success, with a 1.50% unsafe acceptance rate on infeasible instances, while maintaining practical end-to-end synthesis latency.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.