Skip to content
Conference

Experimental Prompt Engineering Using Structured Language Refinement for Attack Path Analysis

Aug 2026 · National Aerospace and Electronics Conference · pp. 72-77 · 0 citations · 29 references

Abstract

Designing cyber-physical systems (CPS) that minimize vulnerabilities is difficult even with security engineering expertise. As a system becomes increasingly complex in terms of size, functionality, or usability, security analysis quickly becomes stale. Reasoning about vulnerability mitigation could be assisted with large language model (LLM) technology. This paper presents a methodology that progressively qualifies LLMs on the task of analyzing systems for attack paths and countermeasures, using Bloom’s Revised Taxonomy as a task-language refinement instrument: each successive rung is treated as a behavioral target to qualify prompt language. The methodology is applied to two open-weight 7–8 billion parameter LLMs deployable on 8GB VRAM hardware. The primary result is diagnostic: at the Understand rung the models default to an enterprise information technology (IT) framing of security terminology, requiring the prompt to carry the cyber-physical context explicitly rather than leaving it to the model’s training. Comparisons of the base task versus reasoning scaffolds such as Chain-of-Thought did not detect an improvement at this parameter scale; a structural analysis of the outputs offers a candidate explanation: models often emitted reasoning after the answer, where it cannot condition the result under autoregressive decoding. As a twomodel pilot, these results bound scope rather than establish generality; future work may re-use the methodology to specify task language within other domains or on LLMs with greater parameter counts.

View source

Similar papers

Review Sep 2026

Using LLMs to Elicit Security Requirements for Service-Oriented Cyber Ranges

Cyber ranges are complex environments comprising many interacting components and stakeholders with different security concerns. The Service-Oriented Cyber Range (SOR) is no exception, particularly when it comes to training scenarios targeting critical infrastructure. Security concerns are translated into security requi...

Michail Takaronis, Athanasia Kollarou, G. Kavallieratos et al. · 0 citations
Book Open access Oct 2026

Metamodel-Based Generation of Security Models from Structured Cyber Threat Intelligence

This paper presents a prototype approach that transforms publicly available attack knowledge from sources such as MITRE ATT&CK and MITRE EMB3D into instances of the Security Abstraction Model (SAM), a domain-specific security metamodel, and outlines future research directions toward continuous, data-driven cybersecurit...

Alexander Fischer, Ramin Tavakoli Kolagari · 0 citations
Preprint Aug 2026

The Anatomy of a Prompt Injection: A Component Model for Structured Analysis

This paper formalizes the structure of prompt-injection artifacts, enabling defenders, red teamers, and cyber threat intelligence (CTI) teams to label, compare, and mutate attacks without relying on fragile string matching.

Jeremy McHugh · 0 citations
Review Open access 2026

Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness

The proposed Large Language Model-Assisted Threat-Driven Testing System enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby s...

Praise Emeka Nze, A. Ademuwagun, Muktar Bello et al. · 0 citations
Review Open access Aug 2026

Defensive Reverse Engineering of LLM Applications: A Black-Box Framework for Security Risk Scoring and Mitigation

D-RELLM is presented, a defensive reverse-engineering framework for black-box security assessment of deployed LLM applications that treats the deployed application as a socio-technical system whose risk depends on instruction hierarchy, retrieval trust, authorization, tool agency, output handling, monitoring, and opera...

Bhavesh B. Prajapati, Bhavya Shah · 0 citations
Open access Sep 2026

A Case Study on Using Local LLMs for Automated Cybersecurity Analysis

The use of generative AI technologies in architectural threat modeling automation seems to be a promising alternative to ‘traditional’ formal approaches (e.g., attack-defense trees, domain-specific languages, knowledge graphs, etc.). The main advantage of Large Language Models (LLMs) is that they can work with system a...

Unknown authors · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.