Pith. sign in

REVIEW 3 major objections 6 minor 2 cited by

Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey

T0 review · 3 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash

Pith's one-line read This survey maps where large language models currently help defend cyberattacks and claims the biggest open gap is post-intrusion defense—lateral movement, data exfiltration, and post-exfiltration.

desk verdict Useful attack-lifecycle survey of LLM defenses, but the central gap claim contradicts its own lateral-movement section and the absent methodology makes 'systematic' a stretch. read the letter →

arxiv 2504.15622 v2 pith:QHVCDPLZ submitted 2025-04-22 cs.CR

classification cs.CR
keywords LargeLanguageModelsCybersecurityCyberattacklifecycleIntrusiondetectionAnomalyThreatIntelligenceVulnerabilityNext-generationnetworks
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This survey tries to establish where large language models fit in cyber defense by organizing the research literature around the stages an attacker passes through: reconnaissance, foothold establishment, lateral movement, data exfiltration, and post-exfiltration. It argues that LLMs are already demonstrably useful in the early and middle stages—detecting scans and phishing, spotting malware, finding and patching vulnerabilities, and automating cyber-threat intelligence—but that LLM-based defense research largely stops once an attacker is inside the network. The paper's central conclusion is that lateral movement, data exfiltration, and post-exfiltration mark a significant research gap, and it points to this gap as the place where future work is most needed. A sympathetic reader would care because the claim implies that defense research effort is systematically avoiding the stages where attacks actually do their damage.

What carries the argument

The organizing device is the five-phase cyber attack lifecycle (reconnaissance, foothold establishment, lateral movement, data exfiltration, post-exfiltration), used as a grid on which each surveyed LLM defense is placed. The grid does the argument's work: gaps become visible as phases with few or no entries, and the paper's headline conclusion—that post-intrusion phases are understudied—is read directly off the empty cells. The CTI lifecycle (requirements, collection, processing, analysis, dissemination, feedback) plays a supporting role, showing where LLMs already automate analyst work.

What would settle it

Run a systematic literature search with explicit inclusion criteria and coverage statistics across top security and AI venues for LLM-based defense in the data exfiltration and post-exfiltration phases. If such a search surfaces a substantial corpus of papers the survey omitted, the claimed gap shrinks; if it confirms near-zero results, the gap holds. A cheaper check: the paper reviews lateral-movement detection systems in Section V.C yet declares lateral movement understudied in Section V.D—determining whether those cited lateral-movement works actually target post-intrusion behavior would decide whether the inconsistency is semantic or substantive.

Watch

Extended reading notes

Core claim

The paper's central claim is that a systematic, attacker-lifecycle view of LLM-based defense reveals a consistent pattern: LLM research clusters in the reconnaissance and foothold establishment phases, with meaningful but thinner work on lateral movement detection, while data exfiltration and post-exfiltration are largely untouched. It also claims that LLMs can carry out the labor-intensive parts of cyber threat intelligence—collection, processing, and analysis—and that deployment strategies for resource-limited next-generation networks are emerging but immature. The paper further asserts that LLM-based defenses bring their own internal and external risks, including prompt injection, data poisoning, and hallucination-driven misinformation, which must be mitigated before such defenses are reliable. Taken together, these claims position the lifecycle as the right lens for planning LLM security research and identify post-intrusion defense as the field's open frontier.

Load-bearing premise

The central gap claim presupposes that the surveyed corpus represents the full body of LLM defense research; the paper gives no search protocol, inclusion criteria, or coverage statistics, so a larger or differently selected corpus could change which phases appear understudied.

Editorial extensions

If this is right

  • LLM-based defense research should shift toward the post-intrusion stages, where the survey finds almost no LLM-based methods for lateral movement, data exfiltration, or post-exfiltration.
  • Practitioners deploying LLM-based IDS, honeypots, or EDR should plan for prompt injection and data-poisoning attacks aimed at the defensive model itself, since these are among the risks the survey catalogs.
  • Automating CTI collection and analysis with LLMs is feasible today, but hallucination and delayed inference remain barriers to real-time defensive use.
  • Deploying LLM security tools in next-generation networks (IoT, 6G, satellite-aerial-ground integrated networks) requires model compression, split learning, or federated approaches because of resource limits.
  • Because most evaluated systems rely on black-box LLMs, measured success rates may be inflated by pre-training data overlap, so open datasets and transparent models are a stated priority.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the post-intrusion gap is real, one testable direction is to adapt pre-intrusion LLM detectors—for example, log anomaly detectors and traffic analyzers—to outbound flows and post-compromise behavior, then benchmark them on exfiltration datasets.
  • The lifecycle grid could be extended to insider threats or supply-chain compromise, which would likely reveal the same empty post-intrusion cells and give the gap claim wider scope.
  • The survey's own evidence suggests the boundary between 'lateral movement' and 'post-intrusion' is where the corpus thins; a finer-grained taxonomy that separates detection of lateral movement from response and recovery might make the gap more or less severe depending on where the line is drawn.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 6 minor

Summary. This survey reviews applications of Large Language Models in cybersecurity, organizing the defense literature around a five-phase attack lifecycle (reconnaissance, foothold establishment, lateral movement, data exfiltration, post-exfiltration), the Cyber Threat Intelligence lifecycle, deployment in traditional and next-generation networks, and risks posed to and by LLMs. It claims as central contributions a systematic mapping of LLM defense work across the attack lifecycle and the identification of a significant research gap in post-intrusion defenses. The treatment is descriptive: each phase's subsection summarizes selected primary papers in thematic tables, and the later chapters catalog CTI tasks, network deployment scenarios, and LLM-specific security risks.

Significance. If its claims were fully supported, the survey would be a useful map for researchers planning LLM-based defense work, especially because it organizes material by attack lifecycle phase and CTI lifecycle stage, and because it explicitly covers deployment in next-generation networks and LLM-inherent risks such as prompt injection and hallucination. The paper is not a derivation or an empirical study; there are no machine-checked proofs or fitted parameters to assess. Its value lies in corpus organization and in the research-gap statement, and both are currently undermined by an internal contradiction and by the absence of a reproducible search methodology. The potential significance is real, but the manuscript in its present form does not yet support the advertised contribution.

major comments (3)
  1. [V.D, with V.C and Table V] The central gap claim is internally inconsistent. Section V.D states that 'a significant research gap exists in the application of LLM-based defense methods to post-intrusion scenarios, including lateral movement, data exfiltration, and post-exfiltration phases,' yet Section V.C, titled 'The Defensive Role of LLM in the Lateral Movement Phase,' reviews six LLM-based lateral-movement detection systems, namely IDS-Agent [70], IoV-BERT-IDS [71], HilBERT [72], LogPrompt [73], and an LLM-based EDR approach [74]. Since Section IV defines lateral movement as a phase that occurs after the attacker has established a foothold, lateral movement is a post-intrusion phase under the paper's own attack model. The same contradiction is visible in Table II, where 'Our survey' marks coverage of defense against lateral movement. The gap statement must be revised to exclude lateral movement, or it must explain why the systems in Section V.C are considered insufficient to count as coverage.
  2. [II.C and V.D] The research-gap conclusion is not verifiable from the manuscript because no systematic search protocol is documented. The paper does not report the databases queried, search strings, inclusion or exclusion criteria, screening procedure, or the number of papers retrieved and excluded. Since the central claim rests on the absence of LLM-based defense papers in particular lifecycle phases, the reader cannot tell whether the alleged gap reflects the actual literature or the chosen corpus. I recommend adding a methodology subsection that specifies the search and selection process and reports phase-wise counts of included works, so that the gap statement can be checked and reproduced.
  3. [II.B.2] A paragraph is duplicated nearly verbatim within the related-work subsection. The text beginning 'Both Ref. [15] and Ref. [16] provide systematic summaries and organization of current research on the application of LLMs in cybersecurity' appears twice, with the second copy again covering the same descriptions of Ref. [17], Ref. [3], and Ref. [18]. This is a clear editorial defect that needs correction, and the duplication makes the surrounding discussion of Motlagh et al. and Chen et al. appear twice in inconsistent verb forms.
minor comments (6)
  1. [II.A] The phrase 'ransformer architecture' should read 'transformer architecture'.
  2. [Table II caption] The caption spells 'EXPLORED' as 'RXPLORED' twice; the symbols '●' and '○' should also be defined with the correct spelling.
  3. [III] The text contains 'prompt ngineering' and the phrase 'the specialized and complex character of cybersecurity tasks challenges the applicability of LLM'; both need grammatical and typographical correction.
  4. [V.A.1] The phrase 'a true negativity rate of 0.9' should be 'a true negative rate of 0.9' or 'specificity of 0.9'.
  5. [V.D] The subsection declares data exfiltration and post-exfiltration to be understudied but cites no literature search confirming that no relevant work exists; even after the contradiction over lateral movement is fixed, the authors should soften the claim to 'we found few works' unless they can provide transparent corpus statistics.
  6. [II.B.2] The phrase 'the the National Institute of Standards and Technology' contains a duplicated article in both copies of the duplicated paragraph.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: this is a literature survey whose claims are external summaries, not derivations from fitted inputs.

full rationale

This paper is a systematic survey, not a derivation. Its central outputs are (a) a taxonomy of LLM defensive roles across the cyber attack lifecycle, (b) a research-gap statement for post-intrusion scenarios, and (c) summaries of external works. None of these are produced from equations or fitted parameters, so the primary circularity patterns (self-definitional equivalence, fitted input called prediction, etc.) do not apply. The paper does cite works by its own authors (e.g., [75], [98], [102]), but these citations support background claims about networking scenarios and are not load-bearing for the survey's central defensive-role analysis. The research-gap claim in Section V.D is not circular; it is an empirical judgment about the surveyed corpus. However, it is internally inconsistent as written: Section V.C and Table V review LLM-based lateral-movement defenses (e.g., IDS-Agent [70], IoV-BERT-IDS [71], HilBERT [72], LogPrompt [73], and an LLM-based EDR approach [74]), and Table II marks 'Our survey' as covering defense against lateral movement. That contradiction undermines the accuracy of the gap claim and is a correctness/consistency issue, but it is not a case where a predicted result reduces to its input by construction. The absence of a search protocol further limits falsifiability, but again this bears on rigor, not circularity. Accordingly the appropriate circularity score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The survey relies on externally defined lifecycle taxonomies for attacks, CTI, and reconnaissance classification. These are standard domain models from the cited literature, not new inventions. No free parameters or invented entities are present.

assumptions (3)
  • domain assumption The external cyber attack lifecycle can be divided into five phases: reconnaissance, foothold establishment, lateral movement, data exfiltration, and post-exfiltration.
    Adopted from Ref [28] (Alshamrani et al. APT survey) in Section IV. The entire survey's organization and gap analysis depend on this phase model being a valid and complete representation of attacks.
  • domain assumption The CTI lifecycle has six phases (requirements, collection, processing, analysis, dissemination, feedback) and LLM applications concentrate in collection, processing, and analysis.
    Adopted from Nova [81] in Section VI. Used to scope which CTI tasks are reviewed.
  • domain assumption Reconnaissance attacks can be classified into third-party source-based, human-based, and system-based types.
    Adopted from Roy et al. [32] in Section V.A. Used to organize the reconnaissance literature into tables.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey." pith.science (2026). https://pith.science/paper/QHVCDPLZ

@misc{pith2026250415622,
  author       = {Pith},
  title        = {Pith review of: Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/QHVCDPLZ}},
  note         = {Machine review of arXiv:2504.15622}
}
read the original abstract

With the rapid development of technology and the acceleration of digitalisation, the frequency and complexity of cyber security threats are increasing. Traditional cybersecurity approaches, often based on static rules and predefined scenarios, are struggling to adapt to the rapidly evolving nature of modern cyberattacks. There is an urgent need for more adaptive and intelligent defence strategies. The emergence of Large Language Model (LLM) provides an innovative solution to cope with the increasingly severe cyber threats, and its potential in analysing complex attack patterns, predicting threats and assisting real-time response has attracted a lot of attention in the field of cybersecurity, and exploring how to effectively use LLM to defend against cyberattacks has become a hot topic in the current research field. This survey examines the applications of LLM from the perspective of the cyber attack lifecycle, focusing on the three phases of defense reconnaissance, foothold establishment, and lateral movement, and it analyzes the potential of LLMs in Cyber Threat Intelligence (CTI) tasks. Meanwhile, we investigate how LLM-based security solutions are deployed and applied in different network scenarios. It also summarizes the internal and external risk issues faced by LLM during its application. Finally, this survey also points out the facing risk issues and possible future research directions in this domain.

Figures

Figures reproduced from arXiv: 2504.15622 by the authors.

Figure 1
Figure 1. Section II introduces the foundations of the LLM and [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 1
Figure 1. The overall organizational structure of this survey. [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. Network attack model. In this paper, we divide the life cycle of an external cyber attack into five phases: reconnaissance, foothold establishment, lateral movement, data exfiltration, and post-exfiltration [28], as shown in [PITH_FULL_IMAGE:figures/full_fig_p006_2.png] view at source ↗
Figures from the paper (1 more)
Figure 3
Figure 3. Figure 3: Lifecycle of CTI. in a cyber attack become proactive [80]. Due to its important role in cyber defence, we also investigated the application of LLM in this defensive action. Nova [81] divided the CTI lifecycle into six phases: CTI requirements, CTI collection, CTI proce…

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Rectified Schr\"odinger Bridge Matching for Few-Step Visual Navigation

    cs.RO 2026-04 unverdicted novelty 7.0 of 10

    RSBM exploits velocity field invariance across regularization levels to achieve over 94% cosine similarity and 92% success in visual navigation using only 3 integration steps.

  2. Agentic SABRE: An Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection

    cs.AI 2026-07 conditional novelty 5.0 of 10

    An uncertainty-aware multi-agent framework fuses semantic and behavioural ransomware signals via risk and uncertainty thresholds, reducing false escalations at equal recall while preserving calibrated triage.

Reference graph

Works this paper leans on

130 extracted references · 53 canonical work pages · cited by 2 Pith papers

  1. [70]

    IDS-agent: An LLM agent for explainable intrusion detection in iot networks,

    Y . Li, Z. Xiang, N. D. Bastian, D. Song, and B. Li, “IDS-agent: An LLM agent for explainable intrusion detection in iot networks,” in NeurIPS 2024 Workshop on Open-World Agents , 2024

  2. [71]

    Iov-bert-ids: Hybrid network intrusion detection system in iov using large language models,

    M. Fu, P. Wang, M. Liu, Z. Zhang, and X. Zhou, “Iov-bert-ids: Hybrid network intrusion detection system in iov using large language models,” IEEE Transactions on Vehicular Technology, vol. 74, no. 2, pp. 1909– 1921, 2025

  3. [72]

    Improving log-based anomaly detection by pre-training hierarchical transformers,

    S. Huang, Y . Liu, C. Fung, H. Wang, H. Yang, and Z. Luan, “Improving log-based anomaly detection by pre-training hierarchical transformers,” IEEE Transactions on Computers, vol. 72, no. 9, pp. 2656–2667, 2023

  4. [73]

    Logprompt: A log-based anomaly detection framework using prompts,

    T. Zhang, X. Huang, W. Zhao, S. Bian, and P. Du, “Logprompt: A log-based anomaly detection framework using prompts,” in 2023 International Joint Conference on Neural Networks (IJCNN) , 2023, pp. 1–8

  5. [74]

    Towards Automatic Hands-on-Keyboard Attack Detection Using LLMs in EDR Solutions

    A. Portnoy, E. Azikri, and S. Kels, “Towards automatic hands-on- keyboard attack detection using llms in edr solutions,” arXiv preprint arXiv:2408.01993, 2024

  6. [15]

    When LLMs meet cybersecurity: a systematic literature review,

    J. Zhang, H. Bu, H. Wen, Y . Liu, H. Fei, R. Xi, L. Li, Y . Yang, H. Zhu, and D. Meng, “When LLMs meet cybersecurity: a systematic literature review,” Cybersecurity, vol. 8, no. 1, p. 55, Feb. 2025

  7. [16]

    Large language models meet next-generation networking technologies: A review,

    C.-N. Hang, P.-D. Yu, R. Morabito, and C.-W. Tan, “Large language models meet next-generation networking technologies: A review,” Future Internet, vol. 16, no. 10, 2024

  8. [17]

    Large language models in cybersecurity: State-of-the-art,

    F. N. Motlagh, M. Hajizadeh, M. Majd, P. Najafi, F. Cheng, and C. Meinel, “Large language models in cybersecurity: State-of-the-art,” arXiv preprint arXiv:2402.00891, 2024

  9. [3]

    A survey of large language models for cyber threat detection,

    Y . Chen, M. Cui, D. Wang, Y . Cao, P. Yang, B. Jiang, Z. Lu, and B. Liu, “A survey of large language models for cyber threat detection,” Computers & Security , vol. 145, p. 104016, 2024

  10. [18]

    A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,

    Y . Yao, J. Duan, K. Xu, Y . Cai, Z. Sun, and Y . Zhang, “A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,” High-Confidence Computing , vol. 4, no. 2, p. 100211, 2024

Show all 130 references
  1. [1]

    How machine learning changes the nature of cyberattacks on iot networks: A survey,

    E. Bout, V . Loscri, and A. Gallais, “How machine learning changes the nature of cyberattacks on iot networks: A survey,” IEEE Commu- nications Surveys & Tutorials , vol. 24, no. 1, pp. 248–279, 2022

  2. [2]

    Robust and resilient distributed optimal frequency control for microgrids against cyber attacks,

    Y . Liu, Y . Li, Y . Wang, X. Zhang, H. B. Gooi, and H. Xin, “Robust and resilient distributed optimal frequency control for microgrids against cyber attacks,” IEEE Transactions on Industrial Informatics , vol. 18, no. 1, pp. 375–386, 2022

  3. [4]

    Generative ai based secure wireless sensing for isac networks,

    J. Wang, H. Du, Y . Liu, G. Sun, D. Niyato, S. Mao, D. I. Kim, and X. Shen, “Generative ai based secure wireless sensing for isac networks,” arXiv preprint arXiv:2408.11398, 2024

  4. [5]

    A novel cyberattack-resilient frequency control method for interconnected power systems using smo-based attack estimation,

    A. D. Syrmakesis, H. H. Alhelou, and N. D. Hatziargyriou, “A novel cyberattack-resilient frequency control method for interconnected power systems using smo-based attack estimation,” IEEE Transactions on Power Systems, vol. 39, no. 4, pp. 5672–5686, 2024

  5. [6]

    A novel iot network intrusion detection approach based on adaptive particle swarm optimization convolutional neural network,

    X. Kan, Y . Fan, Z. Fang, L. Cao, N. N. Xiong, D. Yang, and X. Li, “A novel iot network intrusion detection approach based on adaptive particle swarm optimization convolutional neural network,”Information Sciences, vol. 568, pp. 147–162, 2021

  6. [7]

    Secure intelligent fuzzy blockchain framework: Ef- fective threat detection in iot networks,

    A. Yazdinejad, A. Dehghantanha, R. M. Parizi, G. Srivastava, and H. Karimipour, “Secure intelligent fuzzy blockchain framework: Ef- fective threat detection in iot networks,” Computers in Industry , vol. 144, p. 103801, 2023

  7. [8]

    Redun- dancy planning for cost efficient resilience to cyber attacks,

    J. Soikkeli, G. Casale, L. Mu ˜noz-Gonz´alez, and E. C. Lupu, “Redun- dancy planning for cost efficient resilience to cyber attacks,” IEEE Transactions on Dependable and Secure Computing , vol. 20, no. 2, pp. 1154–1168, 2023

  8. [9]

    The role of national cybersecurity strategies on the improvement of cybersecurity education,

    S. AlDaajeh, H. Saleous, S. Alrabaee, E. Barka, F. Breitinger, and K.- K. Raymond Choo, “The role of national cybersecurity strategies on the improvement of cybersecurity education,” Computers & Security , vol. 119, p. 102754, 2022

  9. [10]

    Large lan- guage models for cyber resilience: A comprehensive review, challenges, and future perspectives,

    W. Ding, M. Abdel-Basset, A. M. Ali, and N. Moustafa, “Large lan- guage models for cyber resilience: A comprehensive review, challenges, and future perspectives,” Applied Soft Computing, vol. 170, p. 112663, 2025

  10. [11]

    Trusting artificial intel- ligence in cybersecurity is a double-edged sword,

    M. Taddeo, T. McCutcheon, and L. Floridi, “Trusting artificial intel- ligence in cybersecurity is a double-edged sword,” Nature Machine Intelligence, vol. 1, no. 12, pp. 557–560, 2019

  11. [12]

    Transformers and large language models for efficient intrusion detection systems: A comprehensive survey,

    H. Kheddar, “Transformers and large language models for efficient intrusion detection systems: A comprehensive survey,” arXiv preprint arXiv:2408.07583, 2025

  12. [13]

    Llms in software security: A survey of vulnerability detection techniques and insights,

    Z. Sheng, Z. Chen, S. Gu, H. Huang, G. Gu, and J. Huang, “Llms in software security: A survey of vulnerability detection techniques and insights,” arXiv preprint arXiv:2502.07049, 2025

  13. [14]

    Large language model for vulnerability detection and repair: Literature review and the road ahead,

    X. Zhou, S. Cao, X. Sun, and D. Lo, “Large language model for vulnerability detection and repair: Literature review and the road ahead,” ACM Trans. Softw. Eng. Methodol. , Dec. 2024, just Accepted

  14. [19]

    Lawllm: Law large language model for the us legal system,

    D. Shu, H. Zhao, X. Liu, D. Demeter, M. Du, and Y . Zhang, “Lawllm: Law large language model for the us legal system,” in Proceedings of the 33rd ACM International Conference on Information and Knowledge Management, ser. CIKM ’24. New York, NY , USA: Association for Computing ...

  15. [20]

    Llm-based agentic systems in medicine and healthcare,

    J. Qiu, K. Lam, G. Li, A. Acharya, T. Y . Wong, A. Darzi, W. Yuan, and E. J. Topol, “Llm-based agentic systems in medicine and healthcare,” Nature Machine Intelligence , vol. 6, no. 12, pp. 1418–1420, 12 2024

  16. [21]

    Ai for education (ai4edu): Advancing personalized education with llm and adaptive learning,

    Q. Wen, J. Liang, C. Sierra, R. Luckin, R. Tong, Z. Liu, P. Cui, and J. Tang, “Ai for education (ai4edu): Advancing personalized education with llm and adaptive learning,” ser. KDD ’24. New York, NY , USA: Association for Computing Machinery, 2024, p. 6743–6744

  17. [22]

    Secqa: A concise question-answering dataset for evalu- ating large language models in computer security,

    Z. Liu, “Secqa: A concise question-answering dataset for evalu- ating large language models in computer security,” arXiv preprint arXiv:2312.15838, 2023

  18. [23]

    Cybermetric: A benchmark dataset based on retrieval-augmented gen- eration for evaluating llms in cybersecurity knowledge,

    N. Tihanyi, M. A. Ferrag, R. Jain, T. Bisztray, and M. Debbah, “Cybermetric: A benchmark dataset based on retrieval-augmented gen- eration for evaluating llms in cybersecurity knowledge,” in 2024 IEEE International Conference on Cyber Security and Resilience (CSR) , 2024, pp. 296–302

  19. [24]

    Cyberbench: A multi-task benchmark for evaluating large language models in cybersecurity,

    Z. Liu, J. Shi, and J. F. Buford, “Cyberbench: A multi-task benchmark for evaluating large language models in cybersecurity,” AAAI-24 Workshop on Artificial Intelligence for Cyber Security (AICS), 2024

  20. [25]

    Secure: Benchmarking large language models for cybersecurity,

    D. Bhusal, M. T. Alam, L. Nguyen, A. Mahara, Z. Lightcap, R. Frazier, R. Fieblinger, G. L. Torales, B. A. Blakely, and N. Rastogi, “Secure: Benchmarking large language models for cybersecurity,” arXiv preprint arXiv:2405.20441, 2024

  21. [26]

    Hackmentor: Fine-tuning large language models for cybersecurity,

    J. Zhang, H. Wen, L. Deng, M. Xin, Z. Li, L. Li, H. Zhu, and L. Sun, “Hackmentor: Fine-tuning large language models for cybersecurity,” in 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) , 2023, pp. 452–461

  22. [27]

    Time for action: Automated analysis of cyber threat intelligence in the wild,

    G. Siracusano, D. Sanvito, R. Gonzalez, M. Srinivasan, S. Kamatchi, W. Takahashi, M. Kawakita, T. Kakumaru, and R. Bifulco, “Time for action: Automated analysis of cyber threat intelligence in the wild,” arXiv preprint arXiv:2307.10214, 2023

  23. [28]

    A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,

    A. Alshamrani, S. Myneni, A. Chowdhary, and D. Huang, “A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,” IEEE Communications Surveys & Tutorials , vol. 21, no. 2, pp. 1851–1877, 2019

  24. [29]

    Domain and website attribution beyond whois,

    S. Sebasti ´an, R.-G. Diugan, J. Caballero, I. Sanchez-Rola, and L. Bilge, “Domain and website attribution beyond whois,” in Proceedings of the 39th Annual Computer Security Applications Conference , ser. ACSAC ’23. New York, NY , USA: Association for Computing Machinery, 2023...

  25. [30]

    Automation of recon process for ethical hackers,

    V . R. Saraswathi, I. S. Ahmed, S. M. Reddy, S. Akshay, V . M. Reddy, and S. M. Reddy, “Automation of recon process for ethical hackers,” in 2022 International Conference for Advancement in Technology (ICONAT), 2022, pp. 1–6

  26. [31]

    An enhanced social engineering optimizer for solving an energy-efficient disassembly line balancing problem based on bucket brigades and cloud theory,

    G. Tian, C. Zhang, A. M. Fathollahi-Fard, Z. Li, C. Zhang, and Z. Jiang, “An enhanced social engineering optimizer for solving an energy-efficient disassembly line balancing problem based on bucket brigades and cloud theory,” IEEE Transactions on Industrial Informat- ics, vol....

  27. [32]

    Survey and taxonomy of adversarial reconnaissance techniques,

    S. Roy, N. Sharmin, J. C. Acosta, C. Kiekintveld, and A. Laszka, “Survey and taxonomy of adversarial reconnaissance techniques,” ACM Comput. Surv., vol. 55, no. 6, Dec. 2022

  28. [33]

    A hybrid cyber defense mechanism to mitigate the persistent scan and foothold attack,

    S. Wang, Q. Pei, Y . Zhang, X. Liu, and G. Tang, “A hybrid cyber defense mechanism to mitigate the persistent scan and foothold attack,” Security and Communication Networks , vol. 2020, no. 1, p. 8882200, 2020

  29. [34]

    Catching phishers by their bait: Investigating the dutch phishing landscape through phishing kit detection,

    H. Bijmans, T. Booij, A. Schwedersky, A. Nedgabat, and R. van Wegberg, “Catching phishers by their bait: Investigating the dutch phishing landscape through phishing kit detection,” in 30th USENIX Security Symposium (USENIX Security 21) . USENIX Association, Aug. 2021, pp. 3757–3774

  30. [35]

    An attack exploiting cyber-arm industry,

    J. Gan, C. Luo, W. Shi, Y . Liu, X. Liu, and Z. Tian, “An attack exploiting cyber-arm industry,” IEEE Transactions on Dependable and Secure Computing, vol. 22, no. 2, pp. 1686–1702, 2025

  31. [36]

    Sbi model for the detection of advanced persistent threat based on strange behavior of using credential dumping technique,

    N. Mohamed and B. Belaton, “Sbi model for the detection of advanced persistent threat based on strange behavior of using credential dumping technique,” IEEE Access, vol. 9, pp. 42 919–42 932, 2021. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, VOL. XX, NO. XX, XXXX XXXX 17

  32. [37]

    Hidden markov model and cyber deception for the prevention of adversarial lateral movement,

    M. A. R. A. Amin, S. Shetty, L. Njilla, D. K. Tosh, and C. Kamhoua, “Hidden markov model and cyber deception for the prevention of adversarial lateral movement,” IEEE Access, vol. 9, pp. 49 662–49 682, 2021

  33. [38]

    Advanced persistent threats (apt): evolution, anatomy, attribution and countermea- sures,

    A. Sharma, B. B. Gupta, A. K. Singh, and V . Saraswat, “Advanced persistent threats (apt): evolution, anatomy, attribution and countermea- sures,” Journal of Ambient Intelligence and Humanized Computing , vol. 14, no. 7, pp. 9355–9381, 2023

  34. [39]

    How to disturb network reconnaissance: A moving target defense approach based on deep reinforcement learning,

    T. Zhang, C. Xu, J. Shen, X. Kuang, and L. A. Grieco, “How to disturb network reconnaissance: A moving target defense approach based on deep reinforcement learning,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 5735–5748, 2023

  35. [40]

    Pllm- cs: Pre-trained large language model (llm) for cyber threat detection in satellite networks,

    M. Hassanin, M. Keshk, S. Salim, M. Alsubaie, and D. Sharma, “Pllm- cs: Pre-trained large language model (llm) for cyber threat detection in satellite networks,” Ad Hoc Networks , vol. 166, p. 103645, 2025

  36. [41]

    Audit-llm: Multi-agent collaboration for log-based insider threat detection,

    C. Song, L. Ma, J. Zheng, J. Liao, H. Kuang, and L. Yang, “Audit-llm: Multi-agent collaboration for log-based insider threat detection,” arXiv preprint arXiv:2408.08902, 2024

  37. [42]

    Llm in the shell: Generative honeypots,

    M. Sladi ´c, V . Valeros, C. Catania, and S. Garcia, “Llm in the shell: Generative honeypots,” in2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) , 2024, pp. 430–435

  38. [43]

    Prompting large language models for malicious webpage detection,

    L. Li and B. Gong, “Prompting large language models for malicious webpage detection,” in 2023 IEEE 4th International Conference on Pattern Recognition and Machine Learning (PRML) , 2023, pp. 393– 400

  39. [44]

    Chatspamdetector: Leveraging large language models for effective phishing email detec- tion,

    T. Koide, N. Fukushi, H. Nakano, and D. Chiba, “Chatspamdetector: Leveraging large language models for effective phishing email detec- tion,” arXiv preprint arXiv:2402.18093, 2024

  40. [45]

    Large language models for code analysis: Do llms really do their job?

    C. Fang, N. Miao, S. Srivastav, J. Liu, R. Zhang, R. Fang, Asmita, R. Tsang, N. Nazari, H. Wang, and H. Homayoun, “Large language models for code analysis: Do llms really do their job?” in 33rd USENIX Security Symposium (USENIX Security 24) . Philadelphia, PA: USENIX Associati...

  41. [46]

    Towards novel malicious packet recognition: A few-shot learning approach,

    K. Stein, A. A. Mahyari, G. Francia, and E. El-Sheikh, “Towards novel malicious packet recognition: A few-shot learning approach,” in MILCOM 2024 - 2024 IEEE Military Communications Conference (MILCOM), 2024, pp. 847–852

  42. [47]

    Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,

    Z. Yu, M. Wen, X. Guo, and H. Jin, “Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,” in Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, ser. ISSTA 2024. New York, NY , USA: Association for Computin...

  43. [48]

    Exploring large language model-powered pedagogical approaches to cybersecurity education,

    C. Chhetri, “Exploring large language model-powered pedagogical approaches to cybersecurity education,” in Proceedings of the 25th Annual Conference on Information Technology Education, ser. SIGITE ’24. New York, NY , USA: Association for Computing Machinery, 2024, p. 163–166

  44. [49]

    Llm-driven sat impact on phishing defense: A cross-sectional analysis,

    H. ˙IS ¸, “Llm-driven sat impact on phishing defense: A cross-sectional analysis,” in 2024 12th International Symposium on Digital Forensics and Security (ISDFS) , 2024, pp. 1–5

  45. [50]

    Probabilistic models for evaluating network edge’s resistance against scan and foothold attack,

    S. Wang, Q. Pei, Y . Xiao, F. Shao, S. Yuan, J. Chu, and R. Liao, “Probabilistic models for evaluating network edge’s resistance against scan and foothold attack,” IET Communications , vol. 18, no. 20, pp. 1983–1995, 2024

  46. [51]

    Grace: Empowering llm-based software vulnerability detection with graph structure and in- context learning,

    G. Lu, X. Ju, X. Chen, W. Pei, and Z. Cai, “Grace: Empowering llm-based software vulnerability detection with graph structure and in- context learning,” Journal of Systems and Software, vol. 212, p. 112031, 2024

  47. [52]

    Security vulnerability detection with multitask self-instructed fine-tuning of large language models,

    A. Z. H. Yang, H. Tian, H. Ye, R. Martins, and C. L. Goues, “Security vulnerability detection with multitask self-instructed fine-tuning of large language models,” arXiv preprint arXiv:2406.05892, 2024

  48. [53]

    Vtt- llm: Advancing vulnerability-to-tactic-and-technique mapping through fine-tuning of large language model,

    C. Zhang, L. Wang, D. Fan, J. Zhu, T. Zhou, L. Zeng, and Z. Li, “Vtt- llm: Advancing vulnerability-to-tactic-and-technique mapping through fine-tuning of large language model,” Mathematics, vol. 12, no. 9, p. 1286, 2024

  49. [54]

    Apply transfer learning to cy- bersecurity: Predicting exploitability of vulnerabilities by description,

    J. Yin, M. Tang, J. Cao, and H. Wang, “Apply transfer learning to cy- bersecurity: Predicting exploitability of vulnerabilities by description,” Knowledge-Based Systems, vol. 210, p. 106529, 2020

  50. [55]

    Fellmvp: An ensemble llm framework for classifying smart contract vulnerabilities,

    Y . Luo, W. Xu, K. Andersson, M. S. Hossain, and D. Xu, “Fellmvp: An ensemble llm framework for classifying smart contract vulnerabilities,” in 2024 IEEE International Conference on Blockchain (Blockchain) , 2024, pp. 89–96

  51. [56]

    Con- tracttinker: Llm-empowered vulnerability repair for real-world smart contracts,

    C. Wang, J. Zhang, J. Gao, L. Xia, Z. Guan, and Z. Chen, “Con- tracttinker: Llm-empowered vulnerability repair for real-world smart contracts,” in Proceedings of the 39th IEEE/ACM International Con- ference on Automated Software Engineering, ser. ASE ’24. New York, NY , USA: A...

  52. [57]

    Zeroleak: Automated side-channel patching in source code using llms,

    M. C. Tol and B. Sunar, “Zeroleak: Automated side-channel patching in source code using llms,” in Computer Security – ESORICS 2024 , J. Garcia-Alfaro, R. Kozik, M. Chora ´s, and S. Katsikas, Eds. Cham: Springer Nature Switzerland, 2024, pp. 290–310

  53. [58]

    Automating zero- shot patch porting for hard forks,

    S. Pan, Y . Wang, Z. Liu, X. Hu, X. Xia, and S. Li, “Automating zero- shot patch porting for hard forks,” in Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis , ser. ISSTA 2024. New York, NY , USA: Association for Computing Machinery,...

  54. [59]

    Leveraging large language model for automatic patch correctness assessment,

    X. Zhou, B. Xu, K. Kim, D. Han, H. H. Nguyen, T. Le-Cong, J. He, B. Le, and D. Lo, “Leveraging large language model for automatic patch correctness assessment,” IEEE Transactions on Software Engi- neering, vol. 50, no. 11, pp. 2865–2883, 2024

  55. [60]

    Getting pwn’d by ai: Penetration testing with large language models,

    A. Happe and J. Cito, “Getting pwn’d by ai: Penetration testing with large language models,” in Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , ser. ESEC/FSE 2023. New York, NY , USA: Associa...

  56. [61]

    Multitask-based evaluation of open- source llm on software vulnerability,

    X. Yin, C. Ni, and S. Wang, “Multitask-based evaluation of open- source llm on software vulnerability,” IEEE Transactions on Software Engineering, vol. 50, no. 11, pp. 3071–3087, 2024

  57. [62]

    An empirical study of automated vulnerability localization with large language models,

    J. Zhang, C. Wang, A. Li, W. Sun, C. Zhang, W. Ma, and Y . Liu, “An empirical study of automated vulnerability localization with large language models,” arXiv preprint arXiv:2404.00287, 2024

  58. [63]

    Microwalk: A framework for finding side channels in binaries,

    J. Wichelmann, A. Moghimi, T. Eisenbarth, and B. Sunar, “Microwalk: A framework for finding side channels in binaries,” in Proceedings of the 34th Annual Computer Security Applications Conference , ser. ACSAC ’18. New York, NY , USA: Association for Computing Machinery, 2018, ...

  59. [64]

    Diversevul: A new vulnerable source code dataset for deep learning based vulner- ability detection,

    Y . Chen, Z. Ding, L. Alowain, X. Chen, and D. Wagner, “Diversevul: A new vulnerable source code dataset for deep learning based vulner- ability detection,” in Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses , ser. RAID ’23. New ...

  60. [65]

    Outside the comfort zone: Analysing llm capabilities in software vulnerability detection,

    Y . Guo, C. Patsakis, Q. Hu, Q. Tang, and F. Casino, “Outside the comfort zone: Analysing llm capabilities in software vulnerability detection,” in Computer Security – ESORICS 2024 , J. Garcia-Alfaro, R. Kozik, M. Chora ´s, and S. Katsikas, Eds. Cham: Springer Nature Switzerla...

  61. [66]

    Chatgpt for vulnerability detection, classification, and repair: How far are we?

    M. Fu, C. K. Tantithamthavorn, V . Nguyen, and T. Le, “Chatgpt for vulnerability detection, classification, and repair: How far are we?” in 2023 30th Asia-Pacific Software Engineering Conference (APSEC) , 2023, pp. 632–636

  62. [67]

    Chain-of- thought prompting of large language models for discovering and fixing software vulnerabilities,

    Y . Nong, M. Aldeen, L. Cheng, H. Hu, F. Chen, and H. Cai, “Chain-of- thought prompting of large language models for discovering and fixing software vulnerabilities,” arXiv preprint arXiv:2402.17230, 2024

  63. [68]

    Lmtracker: Lateral movement path detection based on heterogeneous graph embedding,

    Y . Fang, C. Wang, Z. Fang, and C. Huang, “Lmtracker: Lateral movement path detection based on heterogeneous graph embedding,” Neurocomputing, vol. 474, pp. 37–47, 2022

  64. [69]

    Jbeil: Temporal graph-based inductive learning to infer lateral movement in evolving enterprise networks,

    J. Khoury, D. Klisura, H. Zanddizari, G. De La Torre Parra, P. Najafirad, and E. Bou-Harb, “Jbeil: Temporal graph-based inductive learning to infer lateral movement in evolving enterprise networks,” in 2024 IEEE Symposium on Security and Privacy (SP) , 2024, pp. 3644–3660

  65. [75]

    How to mitigate ddos intelligently in sd-iov: A moving target defense approach,

    T. Zhang, C. Xu, P. Zou, H. Tian, X. Kuang, S. Yang, L. Zhong, and D. Niyato, “How to mitigate ddos intelligently in sd-iov: A moving target defense approach,” IEEE Transactions on Industrial Informatics, vol. 19, no. 1, pp. 1097–1106, 2023. IEEE TRANSACTIONS ON NETWORK SCIENC...

  66. [76]

    Uncovering lateral movement using authentication logs,

    H. Bian, T. Bai, M. A. Salahuddin, N. Limam, A. A. Daya, and R. Boutaba, “Uncovering lateral movement using authentication logs,” IEEE Transactions on Network and Service Management, vol. 18, no. 1, pp. 1049–1063, 2021

  67. [77]

    Log parsing: How far can chatgpt go?

    V .-H. Le and H. Zhang, “Log parsing: How far can chatgpt go?” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2023, pp. 1699–1704

  68. [78]

    Detecting lateral movement: A systematic survey,

    C. Smiliotopoulos, G. Kambourakis, and C. Kolias, “Detecting lateral movement: A systematic survey,” Heliyon, vol. 10, no. 4, p. e26317, 02 2024, doi: 10.1016/j.heliyon.2024.e26317

  69. [79]

    Definition: Threat intelligence,

    R. McMillan, “Definition: Threat intelligence,” [Online], 2022, accessed: Dec. 10, 2024. [Online]. Available: https://gartner.com/

  70. [80]

    Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives,

    N. Sun, M. Ding, J. Jiang, W. Xu, X. Mo, Y . Tai, and J. Zhang, “Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives,” IEEE Communications Surveys & Tutorials , vol. 25, no. 3, pp. 1748–1774, 2023

  71. [81]

    Security and resilience in sustainable smart cities through cyber threat intelligence,

    K. Nova, “Security and resilience in sustainable smart cities through cyber threat intelligence,” International Journal of Information and Cybersecurity, vol. 6, no. 1, pp. 21–42, 2022

  72. [82]

    The use of large language models (llm) for cyber threat intelligence (cti) in cybercrime forums,

    V . Clairoux-Trepanier, I.-M. Beauchamp, E. Ruellan, M. Paquet- Clouston, S.-O. Paquette, and E. Clay, “The use of large language models (llm) for cyber threat intelligence (cti) in cybercrime forums,” arXiv preprint arXiv:2408.03354 , 2024

  73. [83]

    Localintel: Generating organizational threat intel- ligence from global and local cyber knowledge,

    S. Mitra, S. Neupane, T. Chakraborty, S. Mittal, A. Piplai, M. Gaur, and S. Rahimi, “Localintel: Generating organizational threat intel- ligence from global and local cyber knowledge,” arXiv preprint arXiv:2401.10036, 2024

  74. [84]

    Actionable cyber threat intelligence using knowledge graphs and large language models,

    R. Fieblinger, M. T. Alam, and N. Rastogi, “Actionable cyber threat intelligence using knowledge graphs and large language models,” in 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2024, pp. 100–111

  75. [85]

    Cti view: Apt threat intelligence analysis system,

    Y . Zhou, Y . Tang, M. Yi, C. Xi, and H. Lu, “Cti view: Apt threat intelligence analysis system,” Security and Communication Networks , vol. 2022, no. 1, p. 9875199, 2022

  76. [86]

    Cskg4apt: A cyber- security knowledge graph for advanced persistent threat organization attribution,

    Y . Ren, Y . Xiao, Y . Zhou, Z. Zhang, and Z. Tian, “Cskg4apt: A cyber- security knowledge graph for advanced persistent threat organization attribution,” IEEE Transactions on Knowledge and Data Engineering , vol. 35, no. 6, pp. 5695–5709, 2023

  77. [87]

    Crimson: Empowering strategic reasoning in cybersecurity through large language models,

    J. Jin, B. Tang, M. Ma, X. Liu, Y . Wang, Q. Lai, J. Yang, and C. Zhou, “Crimson: Empowering strategic reasoning in cybersecurity through large language models,” arXiv preprint arXiv:2403.00878, 2024

  78. [88]

    Inferring recovery steps from cyber threat intelligence reports,

    Z. L. Kucsv ´an, M. Caselli, A. Peter, and A. Continella, “Inferring recovery steps from cyber threat intelligence reports,” in Detection of Intrusions and Malware, and Vulnerability Assessment , F. Maggi, M. Egele, M. Payer, and M. Carminati, Eds. Cham: Springer Nature Switze...

  79. [89]

    Mining temporal attack patterns from cyberthreat intelligence reports,

    M. R. Rahman, B. Wroblewski, Q. Matthews, B. Morgan, T. Menzies, and L. Williams, “Mining temporal attack patterns from cyberthreat intelligence reports,” arXiv preprint arXiv:2401.01883, 2024

  80. [90]

    Large language models empowered autonomous edge ai for connected intelligence,

    Y . Shen, J. Shao, X. Zhang, Z. Lin, H. Pan, D. Li, J. Zhang, and K. B. Letaief, “Large language models empowered autonomous edge ai for connected intelligence,” IEEE Communications Magazine , vol. 62, no. 10, pp. 140–146, 2024

  81. [91]

    A survey of network automation for industrial internet-of-things toward industry 5.0,

    H. R. Chi, C. K. Wu, N.-F. Huang, K.-F. Tsang, and A. Radwan, “A survey of network automation for industrial internet-of-things toward industry 5.0,” IEEE Transactions on Industrial Informatics , vol. 19, no. 2, pp. 2065–2077, 2023

  82. [92]

    Five facets of 6g: Research challenges and opportunities,

    L.-H. Shen, K.-T. Feng, and L. Hanzo, “Five facets of 6g: Research challenges and opportunities,” ACM Comput. Surv. , vol. 55, no. 11, Feb. 2023

  83. [93]

    (com)2net: A novel communication and computation integrated net- work architecture,

    W. Zhang, D. Yang, C. Zhang, Q. Ye, H. Zhang, and X. Shen, “(com)2net: A novel communication and computation integrated net- work architecture,” IEEE Network, vol. 38, no. 2, pp. 35–44, 2024

  84. [94]

    Det(com)2: Deterministic communication and computation integration toward aigc services,

    W. Zhang, N. Tang, D. Yang, R. Guo, H. Zhang, and X. Shen, “Det(com)2: Deterministic communication and computation integration toward aigc services,” IEEE Wireless Communications, vol. 31, no. 3, pp. 32–41, 2024

  85. [95]

    Intelligent resource adaptation for diversified service requirements in industrial iot,

    W. Zhang, Y . He, T. Zhang, C. Ying, and J. Kang, “Intelligent resource adaptation for diversified service requirements in industrial iot,” IEEE Transactions on Cognitive Communications and Networking , pp. 1–1, 2024

  86. [96]

    Intrusion detection scheme with dimensionality reduc- tion in next generation networks,

    K. Sood, M. R. Nosouhi, D. D. N. Nguyen, F. Jiang, M. Chowdhury, and R. Doss, “Intrusion detection scheme with dimensionality reduc- tion in next generation networks,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 965–979, 2023

  87. [97]

    Enabling intelligent connectivity: A survey of secure isac in 6g networks,

    X. Zhu, J. Liu, L. Lu, T. Zhang, T. Qiu, C. Wang, and Y . Liu, “Enabling intelligent connectivity: A survey of secure isac in 6g networks,” IEEE Communications Surveys & Tutorials , pp. 1–1, 2024

  88. [98]

    Moving target defense meets artificial intelligence-driven network: A comprehensive survey,

    T. Zhang, F. Kong, D. Deng, X. Tang, X. Wu, C. Xu, L. Zhu, J. Liu, B. Ai, Z. Han, and R. H. Deng, “Moving target defense meets artificial intelligence-driven network: A comprehensive survey,” IEEE Internet of Things Journal , pp. 1–1, 2025

  89. [99]

    Mobile edge intelligence for large language models: A contemporary survey,

    G. Qu, Q. Chen, W. Wei, Z. Lin, X. Chen, and K. Huang, “Mobile edge intelligence for large language models: A contemporary survey,” IEEE Communications Surveys & Tutorials , pp. 1–1, 2025

  90. [100]

    Toward democratized generative ai in next-generation mobile edge networks,

    R. Zhang, J. He, X. Luo, D. Niyato, J. Kang, Z. Xiong, Y . Li, and B. Sikdar, “Toward democratized generative ai in next-generation mobile edge networks,” IEEE Network, pp. 1–1, 2025

  91. [101]

    Integration of federated learning and ai-generated content: A survey of overview, op- portunities, challenges, and solutions,

    Y . Liu, J. Yin, W. Zhang, C. An, Y . Xia, and H. Zhang, “Integration of federated learning and ai-generated content: A survey of overview, op- portunities, challenges, and solutions,” IEEE Communications Surveys & Tutorials, pp. 1–1, 2024

  92. [102]

    Generative ai for space-air-ground integrated networks,

    R. Zhang, H. Du, D. Niyato, J. Kang, Z. Xiong, A. Jamalipour, P. Zhang, and D. I. Kim, “Generative ai for space-air-ground integrated networks,” IEEE Wireless Communications, vol. 31, no. 6, pp. 10–20, 2024

  93. [103]

    Mobile network-specialized large lan- guage models for 6g: Architectures, innovations, challenges, and future trends,

    A. Chaoub and M. Elkotob, “Mobile network-specialized large lan- guage models for 6g: Architectures, innovations, challenges, and future trends,” arXiv preprint arXiv:2502.04933, 2025

  94. [104]

    When large language model agents meet 6g networks: Perception, grounding, and alignment,

    M. Xu, D. Niyato, J. Kang, Z. Xiong, S. Mao, Z. Han, D. I. Kim, and K. B. Letaief, “When large language model agents meet 6g networks: Perception, grounding, and alignment,” IEEE Wireless Communications, vol. 31, no. 6, pp. 63–71, 2024

  95. [105]

    Next- gen service function chain deployment: Combining multi-objective optimization with ai large language models,

    Y . Li, Q. Zhang, H. Yao, R. Gao, X. Xin, and M. Guizani, “Next- gen service function chain deployment: Combining multi-objective optimization with ai large language models,” IEEE Network , pp. 1– 1, 2025

  96. [106]

    Hierarchical micro-segmentations for zero-trust services via large language model (llm)-enhanced graph diffusion,

    Y . Liu, G. Liu, H. Du, D. Niyato, J. Kang, Z. Xiong, D. I. Kim, and X. Shen, “Hierarchical micro-segmentations for zero-trust services via large language model (llm)-enhanced graph diffusion,” arXiv preprint arXiv:2406.13964, 2024

  97. [107]

    Llm-twin: mini-giant model-driven beyond 5g digital twin networking framework with semantic secure communication and computation,

    Y . Hong, J. Wu, and R. Morello, “Llm-twin: mini-giant model-driven beyond 5g digital twin networking framework with semantic secure communication and computation,” Scientific Reports, vol. 14, no. 1, p. 19065, 08 2024

  98. [108]

    Rethinking the reversal curse of LLMs: a prescription from human knowledge reversal,

    Z. Lu, L. Jin, P. Li, Y . Tian, L. Zhang, S. Wang, G. Xu, C. Tian, and X. Cai, “Rethinking the reversal curse of LLMs: a prescription from human knowledge reversal,” in Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing , Y . Al-Onaizan, M. ...

  99. [109]

    Ergodic sum rate for uplink noma transmission in satellite-aerial-ground integrated networks,

    H. KONG, M. LIN, J. ZHANG, J. OUY ANG, J.-B. W ANG, and P. K. UPADHY AY , “Ergodic sum rate for uplink noma transmission in satellite-aerial-ground integrated networks,” Chinese Journal of Aeronautics, vol. 35, no. 9, pp. 58–70, 2022

  100. [110]

    Utilizing large language models for advanced optimization and intelligent management in space-air-ground integrated networks,

    J. Tang, F. Tang, S. Long, M. Zhao, and N. Kato, “Utilizing large language models for advanced optimization and intelligent management in space-air-ground integrated networks,”IEEE Network, pp. 1–1, 2024

  101. [111]

    Lever- aging large language models for integrated satellite-aerial-terrestrial networks: Recent advances and future directions,

    S. Javaid, R. A. Khalil, N. Saeed, B. He, and M.-S. Alouini, “Lever- aging large language models for integrated satellite-aerial-terrestrial networks: Recent advances and future directions,” IEEE Open Journal of the Communications Society , vol. 6, pp. 399–432, 2025

  102. [112]

    Formalizing and benchmarking prompt injection attacks and defenses,

    Y . Liu, Y . Jia, R. Geng, J. Jia, and N. Z. Gong, “Formalizing and benchmarking prompt injection attacks and defenses,” in 33rd USENIX Security Symposium (USENIX Security 24) . Philadelphia, PA: USENIX Association, Aug. 2024, pp. 1831–1847

  103. [113]

    A survey of safety and trustworthiness of large language models through the lens of verification and validation,

    X. Huang, W. Ruan, W. Huang, G. Jin, Y . Dong, C. Wu, S. Bensalem, R. Mu, Y . Qi, X. Zhaoet al., “A survey of safety and trustworthiness of large language models through the lens of verification and validation,” Artificial Intelligence Review , vol. 57, no. 7, p. 175, 2024

  104. [114]

    Struq: Defending against prompt injection with structured queries,

    S. Chen, J. Piet, C. Sitawarin, and D. Wagner, “Struq: Defending against prompt injection with structured queries,” 2024

  105. [115]

    Jatmo: Prompt injection defense by task-specific finetuning,

    J. Piet, M. Alrashed, C. Sitawarin, S. Chen, Z. Wei, E. Sun, B. Alomair, and D. Wagner, “Jatmo: Prompt injection defense by task-specific finetuning,” in Computer Security – ESORICS 2024 , J. Garcia-Alfaro, R. Kozik, M. Chora ´s, and S. Katsikas, Eds. Cham: Springer Nature Swi...

  106. [116]

    Purifying large language models by ensembling a small language model,

    T. Li, Q. Liu, T. Pang, C. Du, Q. Guo, Y . Liu, and M. Lin, “Purifying large language models by ensembling a small language model,” arXiv preprint arXiv:2402.14845, 2024

  107. [117]

    Test-time backdoor mitigation for black-box large IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, VOL. XX, NO. XX, XXXX XXXX 19 language models with defensive demonstrations,

    W. Mo, J. Xu, Q. Liu, J. Wang, J. Yan, H. Askari, C. Xiao, and M. Chen, “Test-time backdoor mitigation for black-box large IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, VOL. XX, NO. XX, XXXX XXXX 19 language models with defensive demonstrations,” arXiv preprint arXiv:2...

  108. [118]

    Factscore: Fine-grained atomic evaluation of factual precision in long form text generation,

    S. Min, K. Krishna, X. Lyu, M. Lewis, W. tau Yih, P. W. Koh, M. Iyyer, L. Zettlemoyer, and H. Hajishirzi, “Factscore: Fine-grained atomic evaluation of factual precision in long form text generation,” arXiv preprint arXiv:2305.14251, 2023

  109. [119]

    A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,

    L. Huang, W. Yu, W. Ma, W. Zhong, Z. Feng, H. Wang, Q. Chen, W. Peng, X. Feng, B. Qin et al. , “A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,” ACM Transactions on Information Systems , vol. 43, no. 2, pp. 1–55, 2025

  110. [120]

    Factuality enhanced language models for open- ended text generation,

    N. Lee, W. Ping, P. Xu, M. Patwary, P. N. Fung, M. Shoeybi, and B. Catanzaro, “Factuality enhanced language models for open- ended text generation,” in Advances in Neural Information Processing Systems, S. Koyejo, S. Mohamed, A. Agarwal, D. Belgrave, K. Cho, and A. Oh, Eds., v...

  111. [121]

    Unknown web attack threat detection based on large language model,

    Y . Xu, Q. Zhang, H. Deng, Z. Liu, C. Yang, and Y . Fang, “Unknown web attack threat detection based on large language model,” Applied Soft Computing, vol. 173, p. 112905, 2025

  112. [122]

    Data quality for software vulnerability datasets,

    R. Croft, M. A. Babar, and M. M. Kholoosi, “Data quality for software vulnerability datasets,” in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) , 2023, pp. 121–133

  113. [123]

    A case study of llm for automated vulnerability repair: Assessing impact of reasoning and patch validation feedback,

    U. Kulsum, H. Zhu, B. Xu, and M. d’Amorim, “A case study of llm for automated vulnerability repair: Assessing impact of reasoning and patch validation feedback,” inProceedings of the 1st ACM International Conference on AI-Powered Software , ser. AIware 2024. New York, NY , USA...

  114. [124]

    Comparison of static application security testing tools and large language models for repo-level vulnerability detection,

    X. Zhou, D.-M. Tran, T. Le-Cong, T. Zhang, I. C. Irsan, J. Sumarlin, B. Le, and D. Lo, “Comparison of static application security testing tools and large language models for repo-level vulnerability detection,” arXiv preprint arXiv:2407.16235, 2024

  115. [125]

    Chatphishdetector: Detecting phishing sites using large language models,

    T. Koide, H. Nakano, and D. Chiba, “Chatphishdetector: Detecting phishing sites using large language models,” IEEE Access, vol. 12, pp. 154 381–154 400, 2024

  116. [126]

    Apelid: Enhancing real- time intrusion detection with augmented wgan and parallel ensemble learning,

    H. V . V o, H. P. Du, and H. N. Nguyen, “Apelid: Enhancing real- time intrusion detection with augmented wgan and parallel ensemble learning,” Computers & Security , vol. 136, p. 103567, 2024

  117. [127]

    Examin- ing zero-shot vulnerability repair with large language models,

    H. Pearce, B. Tan, B. Ahmad, R. Karri, and B. Dolan-Gavitt, “Examin- ing zero-shot vulnerability repair with large language models,” in 2023 IEEE Symposium on Security and Privacy (SP) , 2023, pp. 2339–2356. Shuang Tian received the B.Eng. degree in com- puter science and tech...

  118. [1999]

    He has authored or coauthored over 200 publications

    He is currently a Full Professor and the Dean of the School of Cyberspace Science and Technol- ogy, Beijing Jiaotong University. He has authored or coauthored over 200 publications. In recent years, he has been mainly engaged in research on trusted computing, privacy protectio...

  119. [2018]

    student at ETH Zurich, Switzerland, supported by the China Schol- arship Council in 2021

    He served as a joint Ph.D. student at ETH Zurich, Switzerland, supported by the China Schol- arship Council in 2021. He is currently an Assistant Professor (Lecturer) with the School of Cyberspace Science and Technology, Beijing Jiaotong Univer- sity, China. He has published s...

  120. [2021]

    Starting from December 2021, he works as an asso- ciate professor with the School of Electronic and In- formation Engineering, Beijing Jiaotong University

    From 2019 to 2020, he was a visiting PhD student with the Department of Electrical and Com- puter Engineering, University of Waterloo, Canada. Starting from December 2021, he works as an asso- ciate professor with the School of Electronic and In- formation Engineering, Beijing...

Pith tools

Reviewed August 16, 2026 · model on record in the stance chip above.