2026· International journal of advanced engineering and management research· Vol 11, pp. 439-459· 0 citations· 39 references
TL;DR
The model emphasizes the critical need for established governance before technical implementation and the importance of human-in-the-loop management for highrisk workflows, including the mitigation of probabilistic decisionmaking impacts such as bias, misinformation, and privacy violations.
Abstract
Academic research on securing Large Language Models (LLMs) in cybersecurity currently
exists in silos. To address this fragmentation, this study develops the 'Holistic Deployment Risk
Model' (HDRM) through a qualitative thematic synthesis of nine 'cornerstone' articles, selected
through purposive sampling to ensure a representative cross-section of technical, ethical, and
organizational perspectives, consolidating technical vulnerabilities, autonomous agentic risks,
and adversarial misuse with organizational governance and human elements to identify critical
'blind spots'. The model clusters associated risks into five holistic, interdependent layers -
Governance, Data and Privacy, Model Behavior, Operational Security, and Integrations and
Infrastructure - while illustrating how vulnerabilities can propagate across these interdependent
layers. To help demonstrate concrete applicability for regulatory readiness and real-world uses,
components of the model are qualitatively mapped to current AI risk management frameworks:
NIST AI RMF 1.0 and ISO/IEC 23894. While the model is currently theoretical and requires
further investigation to confirm its efficacy, it offers organizations an actionable checklist to
approach secure LLM deployment. It emphasizes the critical need for established governance
before technical implementation and the importance of human-in-the-loop management for highrisk workflows. Ultimately, the work highlights key areas of 'ethical security' necessary to
responsibly develop and manage AI systems, including the mitigation of probabilistic decisionmaking impacts such as bias, misinformation, and privacy violations.
Fragmented safety evaluation undermines the governance of dangerous AI capabilities. We present a modular framework that evaluates each model through three orthogonal pipelines---Knowledge ($K$), Defense ($D$), and Harm ($H$)---under a unified protocol, aggregating results into a standardized dangerous-capability profile $\phi$. Pluggable modules supply scenario seeds, knowledge banks, hazard queries, and judge rubrics, while the core evaluation engine remains unchanged across domains; the CB evaluation is complemented by a cyber pilot demonstrating protocol transfer. Instantiating the framework with a chemical-biological (CB) module, we evaluate 12 commercial LLMs from four families. Our first contribution is a horizontal comparison of dangerous capability across models and model families: the three dimensions expose sharply divergent profiles---models with comparable knowledge differ in refusal resilience, and strong defenders do not generate less harmful content when they do comply---while family-level patterns further separate Claude, DeepSeek, and GPT models. The second is a temporal analysis of capability evolution: tracking $K$, $D$, and $H$ against model release dates reveals that dangerous capability has not monotonically declined; newer models deepen knowledge while only partially improving defense, showing that scaling and alignment progress do not uniformly translate into safety. Reliability is established via cross-judge consistency (bootstrap $\rho>0.79$, 4 of 5 judges) and pipeline orthogonality ($K$--$D$--$H$ inter-correlations $\rho \in [0.32, 0.52]$).
Zheng-Yi Jin, Ru Zhang, Xiao Chen et al.· 0 citations
Despite technical advancements, the human factor remains cybersecurity's most exploited vulnerability. Current research acknowledges this but remains fragmented, treating vulnerabilities as isolated, static traits. To address this, we introduce MORPHEUS, a holistic framework conceptualizing human-centric security as a dynamic, interconnected system. Grounded in the Cognition–Affect–Behavior (CAB) model and Attribution Theory, MORPHEUS consolidates 50 human factors influencing susceptibility to major cyberthreats (e.g., phishing, malware, password management, and misconfigurations). Beyond mere identification, the framework introduces a hierarchical Causal Pathway Architecture. Systematically mapping 302 empirical interactions (82.8% architecture-compliant), we reveal how cognitive, affective, and behavioral processes jointly shape security outcomes, distilling them into 12 recurring interaction mechanisms. MORPHEUS further links theory to practice through an inventory of 99 validated psychometric instruments for empirical assessment. We illustrate its applicability through in-depth operational scenarios for risk diagnosis and targeted interventions. Overall, MORPHEUS provides a comprehensive theoretical foundation for advancing human-centered cybersecurity.
Giuseppe Desolda, Francesco Greco, R. Lanzilotti et al.· ACM Transactions on Computer...· 2 citations
The findings show that LLMs can approximate structured cybersecurity reasoning under controlled representations, but do not apply it robustly, which has important implications for the design and evaluation of AI-assisted security decision-support systems.
The increasing complexity of cyber threats, interconnected technologies, and data-intensive digital services has exposed limitations in security strategies that depend on isolated controls. This study develops a multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains. The framework was developed through structured synthesis of the ten cybersecurity and privacy studies reviewed in the source manuscript and alignment with established cybersecurity guidance. The revised model treats monitoring and incident response as a cross-cutting capability and privacy and governance as cross-cutting concerns. It further introduces a measurable evaluation structure based on layer-specific security indicators and an overall Multi-Level Cybersecurity Resilience Index. The framework is mapped to NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and Zero Trust principles. The resulting architecture provides a practical basis for coordinating preventive, detective, responsive, recovery, governance, and privacy controls. Because the source studies did not include primary empirical testing, the present manuscript does not claim empirical effectiveness; instead, it specifies a validation protocol using expert assessment and/or controlled simulation. This study contributes an integrated architectural model and a measurable evaluation approach for organizations seeking adaptive and resilient cybersecurity.
This study presents a PRISMA-ScR-guided scoping review to systematically map the current landscape of LLM applications in cybersecurity, addressing their roles as both threat enablers and defensive tools while identifying key governance challenges and future research directions.