Back to feed
Review Open access

LLM-Driven Security and Resilience in 6G Mission-Critical Communication Networks

2026 · IEEE Open Journal of the Communications Society · Vol 7, pp. 8963-8984 · 1 citation · 61 references

Abstract

The large language models (LLMs) are beginning to provide tangible changes to the practice of network security: better threat detection; tighter enforcement of policy; and faster incident response. This survey provides a practitioner’s perspective on the use of LLMs in each of the key areas of network security, with a focus on 6G-enabled mission-critical communication systems, including public safety networks, emergency response coordination, and resilient infrastructure supporting URLLC, non-terrestrial networks (NTN), and edge deployments; these include traffic analysis, anomaly detection, threat intelligence, intrusion detection, vulnerability management, access control, compliance auditing, and security training. The survey documents specific improvements provided by LLMs with respect to context-aware classification, parsing of logs at a fine level of granularity, translating high-level policies to executable rules, and scripting of realistic threat scenarios to test against. We show how the combination of prompt engineering, multimodal embeddings, federated learning, and retrieval-augmented generation (RAG) can be used to expand the capabilities of the Security Operations Center (SOC), and automated defense. We also identify some of the risks associated with the use of LLMs, which include hallucination in output, leakage of sensitive information, and creation of new attack vectors through integration with the model; we also note some of the safeguards that have begun to emerge. We further analyze concrete public safety and emergency response scenarios - including LLM-assisted disaster-zone threat detection and emergency communication prioritization under adversarial overload - examining the specific vulnerabilities introduced by NTN-enabled 6G architectures and the stringent latency requirements of URLLC deployments. In conclusion, we provide working baseline levels of capability with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and map out specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions.

Read PDF