Aug 2026· Applied Sciences· 0 citations· 22 references
TL;DR
This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate.
Abstract
The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate. Following a Design Science Research approach, the framework was evaluated through expert assessment involving twelve cybersecurity practitioners with experience in industrial and Security Operations Centre (SOC) environments and complemented by a proof-of-concept artefact instantiation based on the APT41 DUST campaign. The prototype integrated five heterogeneous CTI evidence sources and executed the automated analytical workflow in approximately 25 s (25.29 s) while illustrating evidence-grounded retrieval, specialized agent orchestration, and human-supervised intelligence generation. Practitioner feedback indicated that AI-assisted contextual intelligence and agent-based reasoning were perceived as valuable, while successful adoption depends primarily on governance, explainability, trust, and alignment with existing operational workflows rather than algorithmic sophistication alone. The study contributes a design-science artefact that combines retrieval-augmented intelligence, modular AI agents, and human oversight, providing practical design guidance for trustworthy AI-assisted CTI deployment in safety-critical Industry 4.0 environments.
The research provides a theoretically informed conceptual framework for cybersecurity architects, offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational claims.
Nitin Bodade· International Journal of Inn...· 0 citations
Industry 5.0 places autonomous agents inside its human–agent collaborative loop, resting its human-centricity pillar on an assumption of trustworthy collaboration that has not been examined critically. Agentic artificial intelligence has moved from research demonstration to industrial deployment within months, introducing a threat class this setting has not yet addressed. This article bridges three literatures developed in isolation, Industry 5.0 cybersecurity, agentic AI security, and Industry 5.0’s own foundational scholarship, proposing a six-category threat taxonomy and a paired forensic readiness framework, formalised as a five-level maturity model and grounded in real 2024–2026 incidents rather than hypothetical scenarios. Both contributions are evaluated through two complementary methods. An exploratory elicitation exercise, modelled on Delphi methodology and using six independent large language models as blind panellists across two rounds, converges on a specific structural critique that is incorporated into the taxonomy’s final design. A retrospective coding exercise then applies that taxonomy to fourteen publicly documented incidents, finding that half require multi-category classification and that two categories remain unexercised in the current public record, evidence that physically embodied industrial deployment has outpaced the documented incident base rather than a gap in the taxonomy itself. This urgency is reinforced by emerging EU and UK regulation imposing 24- and 72-h incident reporting obligations that, on current evidence, most industrial organisations are not positioned to meet. The article closes with a research agenda addressing liability, evidentiary standards, and the readiness-sustainability trade-off.
Maurice E. Dawson, Ahmed Ben Ayed, Samson Quaye· Information· 0 citations
A Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning is proposed.
Iván Ortiz-Garcés, Roberto O. Andrade· Future Internet· 0 citations
A comprehensive review of XAI techniques in industrial cybersecurity, focusing on industrial SOC environments and operational security workflows, and identifies open research directions and opportunities for developing trustworthy, operationally viable, and domain-specific XAI-enabled cybersecurity solutions for industrial environments.
Amr S. Mohamed, Charlotte Fritz, A. M. Saber et al.· 0 citations
Industrial operations increasingly face high-stakes decisions that involve people, data streams, simulations, and control systems. Urgent sessions often require external expertise, retrieval of documents and live telemetry, running what-if simulations, and verifying safety constraints. These scenarios highlight the need for secure interoperability, explainable decision support, and human-in-the-loop control. This paper presents a proposal of a technology-agnostic reference architecture that builds on Industry 4.0 frameworks by incorporating the human-centric, resilient, and sustainable principles of Industry 5.0. Its intelligent layer enables the new approach to human involvement in the process, facilitating meaningful human–machine collaboration. The proposed research provides a practical and conceptual framework for systems engineers, industrial software architects, and operations managers seeking to transition legacy operational plants into human-aligned ecosystems. Its feasibility is evaluated through a simulation-based underground mining testbed, where heterogeneous data sources and communication protocols are integrated into a common operational environment. The proof of concept shows how telemetry, data storage, machine learning models, and operator feedback can be combined to support auditable, explainable, and human-contestable industrial decisions, demonstrating the classification accuracy, remaining useful life forecasting capabilities, and enhanced recommendation precision enabled by iterative operator feedback loops.
Luis Ferreira, E. Gonçalves, G. Putnik et al.· Sustainability· 0 citations
This paper investigates a secure-by-design engineering process focusing on the initial architectural design and examines the role that AI-powered agents can play in supporting it, as well as the conditions required for their effective and reliable use.
C. Ponsard, Jean-François Daune· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.