Aug 2026· National Aerospace and Electronics Conference· pp. 72-77· 0 citations· 29 references
Abstract
Designing cyber-physical systems (CPS) that minimize vulnerabilities is difficult even with security engineering expertise. As a system becomes increasingly complex in terms of size, functionality, or usability, security analysis quickly becomes stale. Reasoning about vulnerability mitigation could be assisted with large language model (LLM) technology. This paper presents a methodology that progressively qualifies LLMs on the task of analyzing systems for attack paths and countermeasures, using Bloom’s Revised Taxonomy as a task-language refinement instrument: each successive rung is treated as a behavioral target to qualify prompt language. The methodology is applied to two open-weight 7–8 billion parameter LLMs deployable on 8GB VRAM hardware. The primary result is diagnostic: at the Understand rung the models default to an enterprise information technology (IT) framing of security terminology, requiring the prompt to carry the cyber-physical context explicitly rather than leaving it to the model’s training. Comparisons of the base task versus reasoning scaffolds such as Chain-of-Thought did not detect an improvement at this parameter scale; a structural analysis of the outputs offers a candidate explanation: models often emitted reasoning after the answer, where it cannot condition the result under autoregressive decoding. As a twomodel pilot, these results bound scope rather than establish generality; future work may re-use the methodology to specify task language within other domains or on LLMs with greater parameter counts.
Cyber ranges are complex environments comprising many interacting components and stakeholders with different security concerns. The Service-Oriented Cyber Range (SOR) is no exception, particularly when it comes to training scenarios targeting critical infrastructure. Security concerns are translated into security requi...
Michail Takaronis, Athanasia Kollarou, G. Kavallieratos et al.· 0 citations
This paper presents a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel, and outlines future research directions toward continuous, data-driven cybersecurit...
Alexander Fischer, Ramin Tavakoli Kolagari· Proceedings of the ACM/IEEE...· 0 citations
This paper formalizes the structure of prompt-injection artifacts, enabling defenders, red teamers, and cyber threat intelligence (CTI) teams to label, compare, and mutate attacks without relying on fragile string matching.
The proposed Large Language Model-Assisted Threat-Driven Testing System enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby s...
Praise Emeka Nze, A. Ademuwagun, Muktar Bello et al.· Journal of Cyber Security· 0 citations
D-RELLM is presented, a defensive reverse-engineering framework for black-box security assessment of deployed LLM applications that treats the deployed application as a socio-technical system whose risk depends on instruction hierarchy, retrieval trust, authorization, tool agency, output handling, monitoring, and opera...
Bhavesh B. Prajapati, Bhavya Shah· International journal of com...· 0 citations
The use of generative AI technologies in architectural threat modeling automation seems to be a promising alternative to ‘traditional’ formal approaches (e.g., attack-defense trees, domain-specific languages, knowledge graphs, etc.). The main advantage of Large Language Models (LLMs) is that they can work with system a...
Unknown authors· Journal of Superintelligence...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.