Skip to content
Open access

Bridging the Blind Spots: A Holistic Risk Model for Secure Deployment of Large Language Models

2026 · International journal of advanced engineering and management research · Vol 11, pp. 439-459 · 0 citations · 39 references

TL;DR

The model emphasizes the critical need for established governance before technical implementation and the importance of human-in-the-loop management for highrisk workflows, including the mitigation of probabilistic decisionmaking impacts such as bias, misinformation, and privacy violations.

Abstract

Academic research on securing Large Language Models (LLMs) in cybersecurity currently exists in silos. To address this fragmentation, this study develops the 'Holistic Deployment Risk Model' (HDRM) through a qualitative thematic synthesis of nine 'cornerstone' articles, selected through purposive sampling to ensure a representative cross-section of technical, ethical, and organizational perspectives, consolidating technical vulnerabilities, autonomous agentic risks, and adversarial misuse with organizational governance and human elements to identify critical 'blind spots'. The model clusters associated risks into five holistic, interdependent layers - Governance, Data and Privacy, Model Behavior, Operational Security, and Integrations and Infrastructure - while illustrating how vulnerabilities can propagate across these interdependent layers. To help demonstrate concrete applicability for regulatory readiness and real-world uses, components of the model are qualitatively mapped to current AI risk management frameworks: NIST AI RMF 1.0 and ISO/IEC 23894. While the model is currently theoretical and requires further investigation to confirm its efficacy, it offers organizations an actionable checklist to approach secure LLM deployment. It emphasizes the critical need for established governance before technical implementation and the importance of human-in-the-loop management for highrisk workflows. Ultimately, the work highlights key areas of 'ethical security' necessary to responsibly develop and manage AI systems, including the mitigation of probabilistic decisionmaking impacts such as bias, misinformation, and privacy violations.

Read PDF

Similar papers

#artificial intelligence Preprint Sep 2026

FUSE: An Evaluating Framework for Dangerous Capabilities of LLMs

Fragmented safety evaluation undermines the governance of dangerous AI capabilities. We present a modular framework that evaluates each model through three orthogonal pipelines---Knowledge ($K$), Defense ($D$), and Harm ($H$)---under a unified protocol, aggregating results into a standardized dangerous-capability profile $\phi$. Pluggable modules supply scenario seeds, knowledge banks, hazard queries, and judge rubrics, while the core evaluation engine remains unchanged across domains; the CB evaluation is complemented by a cyber pilot demonstrating protocol transfer. Instantiating the framework with a chemical-biological (CB) module, we evaluate 12 commercial LLMs from four families. Our first contribution is a horizontal comparison of dangerous capability across models and model families: the three dimensions expose sharply divergent profiles---models with comparable knowledge differ in refusal resilience, and strong defenders do not generate less harmful content when they do comply---while family-level patterns further separate Claude, DeepSeek, and GPT models. The second is a temporal analysis of capability evolution: tracking $K$, $D$, and $H$ against model release dates reveals that dangerous capability has not monotonically declined; newer models deepen knowledge while only partially improving defense, showing that scaling and alignment progress do not uniformly translate into safety. Reliability is established via cross-judge consistency (bootstrap $\rho>0.79$, 4 of 5 judges) and pipeline orthogonality ($K$--$D$--$H$ inter-correlations $\rho \in [0.32, 0.52]$).

Zheng-Yi Jin, Ru Zhang, Xiao Chen et al. · 0 citations
Dec 2025

MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity

Despite technical advancements, the human factor remains cybersecurity's most exploited vulnerability. Current research acknowledges this but remains fragmented, treating vulnerabilities as isolated, static traits. To address this, we introduce MORPHEUS, a holistic framework conceptualizing human-centric security as a dynamic, interconnected system. Grounded in the Cognition–Affect–Behavior (CAB) model and Attribution Theory, MORPHEUS consolidates 50 human factors influencing susceptibility to major cyberthreats (e.g., phishing, malware, password management, and misconfigurations). Beyond mere identification, the framework introduces a hierarchical Causal Pathway Architecture. Systematically mapping 302 empirical interactions (82.8% architecture-compliant), we reveal how cognitive, affective, and behavioral processes jointly shape security outcomes, distilling them into 12 recurring interaction mechanisms. MORPHEUS further links theory to practice through an inventory of 99 validated psychometric instruments for empirical assessment. We illustrate its applicability through in-depth operational scenarios for risk diagnosis and targeted interventions. Overall, MORPHEUS provides a comprehensive theoretical foundation for advancing human-centered cybersecurity.

Giuseppe Desolda, Francesco Greco, R. Lanzilotti et al. · 2 citations
Review Open access Aug 2026

Design and Validation Framework for Multi-Level Cybersecurity and Privacy Protection in Modern Digital Infrastructures

The increasing complexity of cyber threats, interconnected technologies, and data-intensive digital services has exposed limitations in security strategies that depend on isolated controls. This study develops a multi-level cybersecurity and privacy framework that integrates complementary controls across physical, network, endpoint, application, data, identity and access management, monitoring and incident response, and human and policy domains. The framework was developed through structured synthesis of the ten cybersecurity and privacy studies reviewed in the source manuscript and alignment with established cybersecurity guidance. The revised model treats monitoring and incident response as a cross-cutting capability and privacy and governance as cross-cutting concerns. It further introduces a measurable evaluation structure based on layer-specific security indicators and an overall Multi-Level Cybersecurity Resilience Index. The framework is mapped to NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, and Zero Trust principles. The resulting architecture provides a practical basis for coordinating preventive, detective, responsive, recovery, governance, and privacy controls. Because the source studies did not include primary empirical testing, the present manuscript does not claim empirical effectiveness; instead, it specifies a validation protocol using expert assessment and/or controlled simulation. This study contributes an integrated architectural model and a measurable evaluation approach for organizations seeking adaptive and resilient cybersecurity.

Kennedy Owino Jaramba, Samwel Oonge · 0 citations
Review Open access 2026

Large Language Models in Cybersecurity: A PRISMA-ScR-Guided Scoping Review of Threats, Defenses, and Emerging Applications

This study presents a PRISMA-ScR-guided scoping review to systematically map the current landscape of LLM applications in cybersecurity, addressing their roles as both threat enablers and defensive tools while identifying key governance challenges and future research directions.

Srinivas Jangirala, Vedika Gupta, Anandadeep Mandal · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.