Skip to content
#small language model Open access

HERMES-OT: Hierarchical Embedded Reasoning Models for Predictive Cyber-Physical Defence in Industrial Control Systems

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)
Smart Grid Security and Resilience

Abstract

A small-language-model architecture for AI-driven detection, prediction and safe defence of operational technology. Operational technology (OT) and industrial control systems (ICS) increasingly connect information technology, industrial networks, programmable logic controllers (PLCs), SCADA, distributed control systems, robotics and physical processes. This convergence creates a cybersecurity environment in which compromise of a digital asset may propagate into physical consequences. The emergence of tool-using and autonomous large language model (LLM) agents introduces an additional dimension to this threat. Recent research has demonstrated that LLMs can generate attacks against PLC environments, and that autonomous agents can, under appropriate conditions, progress from PLC interaction toward sustained physical objectives. Existing AI cybersecurity approaches predominantly focus on alert classification, anomaly detection, vulnerability identification, malware analysis or natural-language security assistance. These capabilities do not fully address the central OT problem: determining how a cyber event propagates through industrial topology and ultimately affects a physical process. This paper proposes HERMES-OT, a cyber-physical defence architecture based on a hierarchy of compact, specialised language models rather than a single general-purpose LLM, combining industrial telemetry, asset topology, vulnerability intelligence, attack graphs, process-state information, engineering knowledge and digital-twin simulation. The architecture introduces a reasoning chain that runs observe, understand, correlate, predict, simulate, prescribe, validate, learn. Probabilistic reasoning is surrounded by deterministic constraints: a policy engine provides authority, a safety layer provides boundaries, and the human retains control where risk demands it. The central hypothesis is that specialised small language models, coordinated through structured graphs and deterministic safety mechanisms, can provide sufficiently reliable industrial security reasoning while reducing inference latency, computational requirements and exposure of sensitive industrial information. The paper also proposes the OT-HERMES benchmark, a cyber-physical evaluation framework measuring detection, asset reasoning, vulnerability correlation, attack-path prediction, physical-impact prediction, defensive prescription, safety and computational efficiency. The research question is: what is the smallest AI model, or combination of small models, that can reliably reason about cyber-physical risk in an industrial environment? Status: this is a research proposal. No experimental performance figures are claimed for HERMES-OT. The architecture and the eight contributions are proposed and the six hypotheses stated, but not experimentally validated. Implementation and controlled experiments are the next stage of the work, and are essential before the system is presented as empirically validated.

View source

Similar papers

#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#computer vision Review Open access May 2015

A survey study on major technical barriers affecting the decision to adopt cloud services

The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.

Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al. · 111 citations · ⚡8
#computer vision Open access Feb 2018

Lean Internal Startups for Software Product Innovation in Large Companies: Enablers and Inhibitors

This study investigates how Lean internal startup facilitates software product innovation in large companies and identifies its enablers and inhibitors, and shows the potential of the method-in-action framework to investigate the Lean startup approach in non-startup context.

Henry Edison, Nina M. Smørsgård, Xiaofeng Wang et al. · 78 citations · ⚡6
#computer vision Conference Sep 2010

Exploring the Sources of Waste in Kanban Software Development Projects

The application of agile software methods and more recently the integration of Lean practices contribute to the trend of continuous improvement in the software industry. One such area warranting proper empirical evidence is a project’s operational efficiency when using the Kanban method. This short paper takes a new angle and explores waste in the Kanban-driven software development project context. A preliminary research model is presented for helping the consequent replication of the study. The results from the empirical analysis suggest Kanban can be an effective method in visualizing and organizing the current work, but does not prevent waste from creeping in, although the overall project outcome may be successful.

Marko Ikonen, Petri Kettunen, Nilay V. Oza et al. · 67 citations · ⚡9

Related blog posts

MIT News · Artificial Intelligence Sep 14, 2026

New method enables AI for safety-critical situations

The “HardFlow” algorithm could help generative AI models produce high-quality outputs that obey strict requirements when “pretty close” doesn’t cut it.

GPT-Lab Sep 10, 2026

Responsible AI Must Consider Its Afterlife

AI may appear weightless, but every model depends on physical infrastructure. To understand responsible AI, we need to look beyond algorithms and consider the entire lifecycle of the hardware behind them. The post Responsible AI Must Consider Its Afterlife appeared first on GPT-Lab.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.