RAC-LLM: retrieval-augmented large-small model collaboration for cloud-assisted web asset risk assessment and homologous discovery
Cloud-assisted cyber-asset monitoring services must continuously assess web assets that rapidly change domains, content, and page structure, making new variants difficult to evaluate and trace. Large language models can interpret heterogeneous and ambiguous security evidence, but their decisions benefit from bounded and verifiable context. Lightweight modules can efficiently retrieve evidence and construct relations across large asset collections, but they cannot resolve every semantic ambiguity. We present RAC-LLM, a retrieval-augmented large-small model collaboration method for web asset risk assessment and homologous discovery. A compact encoder and BM25 retrieve bounded evidence from historical cases, security rules, and current neighbors. Four cloud-hosted specialist agents analyze URL, HTML, page content, and retrieved evidence, and a final judge integrates their structured outputs into an auditable risk decision. RAC-LLM further combines semantic, URL-token, profile-fingerprint, and suspicious-indicator similarities for homologous expansion, density clustering, and cluster-level warning. Experiments on a balanced PhreshPhish subset show consistent improvements across two large-model backends. With Mimo 2.5, RAC-LLM achieves F1 of 0.968 for risk classification, NDCG@20 of 0.764 for homologous retrieval, and F1 of 0.823 for cluster warning. The results demonstrate a practical cloud-assisted collaborative-intelligence pattern in which lightweight components construct bounded evidence and cross-asset relations, while large models perform evidence-grounded interpretation and decision synthesis. The cloud-call analysis further exposes an explicit quality–cost trade-off rather than assuming that stronger reasoning is computationally free.
Authors
- Li Yan (ORCID: https://orcid.org/0000-0002-9912-8738)
- Jing Guo
- Chao Zhou
- Zhimin Gu
- Haitao Jiang
Institutions
- Shanghai Electric (China) (CN)
Publication Details
- Journal
- Journal of Cloud Computing Advances Systems and Applications
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1186/s13677-026-00968-5
- Primary Topic
- Spam and Phishing Detection
- Type
- article
- Field-Weighted Citation Impact
- 0.00