REVIEW 3 major objections 6 minor 2 cited by
Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey
T0 review · 3 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read This survey maps where large language models currently help defend cyberattacks and claims the biggest open gap is post-intrusion defense—lateral movement, data exfiltration, and post-exfiltration.
desk verdict Useful attack-lifecycle survey of LLM defenses, but the central gap claim contradicts its own lateral-movement section and the absent methodology makes 'systematic' a stretch. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The organizing device is the five-phase cyber attack lifecycle (reconnaissance, foothold establishment, lateral movement, data exfiltration, post-exfiltration), used as a grid on which each surveyed LLM defense is placed. The grid does the argument's work: gaps become visible as phases with few or no entries, and the paper's headline conclusion—that post-intrusion phases are understudied—is read directly off the empty cells. The CTI lifecycle (requirements, collection, processing, analysis, dissemination, feedback) plays a supporting role, showing where LLMs already automate analyst work.
What would settle it
Run a systematic literature search with explicit inclusion criteria and coverage statistics across top security and AI venues for LLM-based defense in the data exfiltration and post-exfiltration phases. If such a search surfaces a substantial corpus of papers the survey omitted, the claimed gap shrinks; if it confirms near-zero results, the gap holds. A cheaper check: the paper reviews lateral-movement detection systems in Section V.C yet declares lateral movement understudied in Section V.D—determining whether those cited lateral-movement works actually target post-intrusion behavior would decide whether the inconsistency is semantic or substantive.
Extended reading notes
Core claim
The paper's central claim is that a systematic, attacker-lifecycle view of LLM-based defense reveals a consistent pattern: LLM research clusters in the reconnaissance and foothold establishment phases, with meaningful but thinner work on lateral movement detection, while data exfiltration and post-exfiltration are largely untouched. It also claims that LLMs can carry out the labor-intensive parts of cyber threat intelligence—collection, processing, and analysis—and that deployment strategies for resource-limited next-generation networks are emerging but immature. The paper further asserts that LLM-based defenses bring their own internal and external risks, including prompt injection, data poisoning, and hallucination-driven misinformation, which must be mitigated before such defenses are reliable. Taken together, these claims position the lifecycle as the right lens for planning LLM security research and identify post-intrusion defense as the field's open frontier.
Load-bearing premise
The central gap claim presupposes that the surveyed corpus represents the full body of LLM defense research; the paper gives no search protocol, inclusion criteria, or coverage statistics, so a larger or differently selected corpus could change which phases appear understudied.
Editorial extensions
If this is right
- LLM-based defense research should shift toward the post-intrusion stages, where the survey finds almost no LLM-based methods for lateral movement, data exfiltration, or post-exfiltration.
- Practitioners deploying LLM-based IDS, honeypots, or EDR should plan for prompt injection and data-poisoning attacks aimed at the defensive model itself, since these are among the risks the survey catalogs.
- Automating CTI collection and analysis with LLMs is feasible today, but hallucination and delayed inference remain barriers to real-time defensive use.
- Deploying LLM security tools in next-generation networks (IoT, 6G, satellite-aerial-ground integrated networks) requires model compression, split learning, or federated approaches because of resource limits.
- Because most evaluated systems rely on black-box LLMs, measured success rates may be inflated by pre-training data overlap, so open datasets and transparent models are a stated priority.
Reading between the lines
- If the post-intrusion gap is real, one testable direction is to adapt pre-intrusion LLM detectors—for example, log anomaly detectors and traffic analyzers—to outbound flows and post-compromise behavior, then benchmark them on exfiltration datasets.
- The lifecycle grid could be extended to insider threats or supply-chain compromise, which would likely reveal the same empty post-intrusion cells and give the gap claim wider scope.
- The survey's own evidence suggests the boundary between 'lateral movement' and 'post-intrusion' is where the corpus thins; a finer-grained taxonomy that separates detection of lateral movement from response and recovery might make the gap more or less severe depending on where the line is drawn.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This survey reviews applications of Large Language Models in cybersecurity, organizing the defense literature around a five-phase attack lifecycle (reconnaissance, foothold establishment, lateral movement, data exfiltration, post-exfiltration), the Cyber Threat Intelligence lifecycle, deployment in traditional and next-generation networks, and risks posed to and by LLMs. It claims as central contributions a systematic mapping of LLM defense work across the attack lifecycle and the identification of a significant research gap in post-intrusion defenses. The treatment is descriptive: each phase's subsection summarizes selected primary papers in thematic tables, and the later chapters catalog CTI tasks, network deployment scenarios, and LLM-specific security risks.
Significance. If its claims were fully supported, the survey would be a useful map for researchers planning LLM-based defense work, especially because it organizes material by attack lifecycle phase and CTI lifecycle stage, and because it explicitly covers deployment in next-generation networks and LLM-inherent risks such as prompt injection and hallucination. The paper is not a derivation or an empirical study; there are no machine-checked proofs or fitted parameters to assess. Its value lies in corpus organization and in the research-gap statement, and both are currently undermined by an internal contradiction and by the absence of a reproducible search methodology. The potential significance is real, but the manuscript in its present form does not yet support the advertised contribution.
major comments (3)
- [V.D, with V.C and Table V] The central gap claim is internally inconsistent. Section V.D states that 'a significant research gap exists in the application of LLM-based defense methods to post-intrusion scenarios, including lateral movement, data exfiltration, and post-exfiltration phases,' yet Section V.C, titled 'The Defensive Role of LLM in the Lateral Movement Phase,' reviews six LLM-based lateral-movement detection systems, namely IDS-Agent [70], IoV-BERT-IDS [71], HilBERT [72], LogPrompt [73], and an LLM-based EDR approach [74]. Since Section IV defines lateral movement as a phase that occurs after the attacker has established a foothold, lateral movement is a post-intrusion phase under the paper's own attack model. The same contradiction is visible in Table II, where 'Our survey' marks coverage of defense against lateral movement. The gap statement must be revised to exclude lateral movement, or it must explain why the systems in Section V.C are considered insufficient to count as coverage.
- [II.C and V.D] The research-gap conclusion is not verifiable from the manuscript because no systematic search protocol is documented. The paper does not report the databases queried, search strings, inclusion or exclusion criteria, screening procedure, or the number of papers retrieved and excluded. Since the central claim rests on the absence of LLM-based defense papers in particular lifecycle phases, the reader cannot tell whether the alleged gap reflects the actual literature or the chosen corpus. I recommend adding a methodology subsection that specifies the search and selection process and reports phase-wise counts of included works, so that the gap statement can be checked and reproduced.
- [II.B.2] A paragraph is duplicated nearly verbatim within the related-work subsection. The text beginning 'Both Ref. [15] and Ref. [16] provide systematic summaries and organization of current research on the application of LLMs in cybersecurity' appears twice, with the second copy again covering the same descriptions of Ref. [17], Ref. [3], and Ref. [18]. This is a clear editorial defect that needs correction, and the duplication makes the surrounding discussion of Motlagh et al. and Chen et al. appear twice in inconsistent verb forms.
minor comments (6)
- [II.A] The phrase 'ransformer architecture' should read 'transformer architecture'.
- [Table II caption] The caption spells 'EXPLORED' as 'RXPLORED' twice; the symbols '●' and '○' should also be defined with the correct spelling.
- [III] The text contains 'prompt ngineering' and the phrase 'the specialized and complex character of cybersecurity tasks challenges the applicability of LLM'; both need grammatical and typographical correction.
- [V.A.1] The phrase 'a true negativity rate of 0.9' should be 'a true negative rate of 0.9' or 'specificity of 0.9'.
- [V.D] The subsection declares data exfiltration and post-exfiltration to be understudied but cites no literature search confirming that no relevant work exists; even after the contradiction over lateral movement is fixed, the authors should soften the claim to 'we found few works' unless they can provide transparent corpus statistics.
- [II.B.2] The phrase 'the the National Institute of Standards and Technology' contains a duplicated article in both copies of the duplicated paragraph.
Circularity Check
No circularity: this is a literature survey whose claims are external summaries, not derivations from fitted inputs.
full rationale
This paper is a systematic survey, not a derivation. Its central outputs are (a) a taxonomy of LLM defensive roles across the cyber attack lifecycle, (b) a research-gap statement for post-intrusion scenarios, and (c) summaries of external works. None of these are produced from equations or fitted parameters, so the primary circularity patterns (self-definitional equivalence, fitted input called prediction, etc.) do not apply. The paper does cite works by its own authors (e.g., [75], [98], [102]), but these citations support background claims about networking scenarios and are not load-bearing for the survey's central defensive-role analysis. The research-gap claim in Section V.D is not circular; it is an empirical judgment about the surveyed corpus. However, it is internally inconsistent as written: Section V.C and Table V review LLM-based lateral-movement defenses (e.g., IDS-Agent [70], IoV-BERT-IDS [71], HilBERT [72], LogPrompt [73], and an LLM-based EDR approach [74]), and Table II marks 'Our survey' as covering defense against lateral movement. That contradiction undermines the accuracy of the gap claim and is a correctness/consistency issue, but it is not a case where a predicted result reduces to its input by construction. The absence of a search protocol further limits falsifiability, but again this bears on rigor, not circularity. Accordingly the appropriate circularity score is 0.
Assumptions & free parameters
assumptions (3)
- domain assumption The external cyber attack lifecycle can be divided into five phases: reconnaissance, foothold establishment, lateral movement, data exfiltration, and post-exfiltration.
- domain assumption The CTI lifecycle has six phases (requirements, collection, processing, analysis, dissemination, feedback) and LLM applications concentrate in collection, processing, and analysis.
- domain assumption Reconnaissance attacks can be classified into third-party source-based, human-based, and system-based types.
Cite this review
Pith. "Pith review of Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey." pith.science (2026). https://pith.science/paper/QHVCDPLZ
@misc{pith2026250415622,
author = {Pith},
title = {Pith review of: Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey},
year = {2026},
howpublished = {\url{https://pith.science/paper/QHVCDPLZ}},
note = {Machine review of arXiv:2504.15622}
}
read the original abstract
With the rapid development of technology and the acceleration of digitalisation, the frequency and complexity of cyber security threats are increasing. Traditional cybersecurity approaches, often based on static rules and predefined scenarios, are struggling to adapt to the rapidly evolving nature of modern cyberattacks. There is an urgent need for more adaptive and intelligent defence strategies. The emergence of Large Language Model (LLM) provides an innovative solution to cope with the increasingly severe cyber threats, and its potential in analysing complex attack patterns, predicting threats and assisting real-time response has attracted a lot of attention in the field of cybersecurity, and exploring how to effectively use LLM to defend against cyberattacks has become a hot topic in the current research field. This survey examines the applications of LLM from the perspective of the cyber attack lifecycle, focusing on the three phases of defense reconnaissance, foothold establishment, and lateral movement, and it analyzes the potential of LLMs in Cyber Threat Intelligence (CTI) tasks. Meanwhile, we investigate how LLM-based security solutions are deployed and applied in different network scenarios. It also summarizes the internal and external risk issues faced by LLM during its application. Finally, this survey also points out the facing risk issues and possible future research directions in this domain.
Figures
Figures from the paper (1 more)
Forward citations
Cited by 2 Pith papers
-
Rectified Schr\"odinger Bridge Matching for Few-Step Visual Navigation
RSBM exploits velocity field invariance across regularization levels to achieve over 94% cosine similarity and 92% success in visual navigation using only 3 integration steps.
-
Agentic SABRE: An Uncertainty-Aware Neuro-Symbolic Multi-Agent Framework for Adaptive Ransomware Detection
An uncertainty-aware multi-agent framework fuses semantic and behavioural ransomware signals via risk and uncertainty thresholds, reducing false escalations at equal recall while preserving calibrated triage.
Reference graph
Works this paper leans on
-
[70]
IDS-agent: An LLM agent for explainable intrusion detection in iot networks,
Y . Li, Z. Xiang, N. D. Bastian, D. Song, and B. Li, “IDS-agent: An LLM agent for explainable intrusion detection in iot networks,” in NeurIPS 2024 Workshop on Open-World Agents , 2024
work page 2024
-
[71]
Iov-bert-ids: Hybrid network intrusion detection system in iov using large language models,
M. Fu, P. Wang, M. Liu, Z. Zhang, and X. Zhou, “Iov-bert-ids: Hybrid network intrusion detection system in iov using large language models,” IEEE Transactions on Vehicular Technology, vol. 74, no. 2, pp. 1909– 1921, 2025
work page 1909
-
[72]
Improving log-based anomaly detection by pre-training hierarchical transformers,
S. Huang, Y . Liu, C. Fung, H. Wang, H. Yang, and Z. Luan, “Improving log-based anomaly detection by pre-training hierarchical transformers,” IEEE Transactions on Computers, vol. 72, no. 9, pp. 2656–2667, 2023
2023
-
[73]
Logprompt: A log-based anomaly detection framework using prompts,
T. Zhang, X. Huang, W. Zhao, S. Bian, and P. Du, “Logprompt: A log-based anomaly detection framework using prompts,” in 2023 International Joint Conference on Neural Networks (IJCNN) , 2023, pp. 1–8
work page 2023
-
[74]
Towards Automatic Hands-on-Keyboard Attack Detection Using LLMs in EDR Solutions
A. Portnoy, E. Azikri, and S. Kels, “Towards automatic hands-on- keyboard attack detection using llms in edr solutions,” arXiv preprint arXiv:2408.01993, 2024
work page Pith review arXiv 2024
-
[15]
When LLMs meet cybersecurity: a systematic literature review,
J. Zhang, H. Bu, H. Wen, Y . Liu, H. Fei, R. Xi, L. Li, Y . Yang, H. Zhu, and D. Meng, “When LLMs meet cybersecurity: a systematic literature review,” Cybersecurity, vol. 8, no. 1, p. 55, Feb. 2025
2025
-
[16]
Large language models meet next-generation networking technologies: A review,
C.-N. Hang, P.-D. Yu, R. Morabito, and C.-W. Tan, “Large language models meet next-generation networking technologies: A review,” Future Internet, vol. 16, no. 10, 2024
2024
-
[17]
Large language models in cybersecurity: State-of-the-art,
F. N. Motlagh, M. Hajizadeh, M. Majd, P. Najafi, F. Cheng, and C. Meinel, “Large language models in cybersecurity: State-of-the-art,” arXiv preprint arXiv:2402.00891, 2024
arXiv 2024
-
[3]
A survey of large language models for cyber threat detection,
Y . Chen, M. Cui, D. Wang, Y . Cao, P. Yang, B. Jiang, Z. Lu, and B. Liu, “A survey of large language models for cyber threat detection,” Computers & Security , vol. 145, p. 104016, 2024
2024
-
[18]
A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,
Y . Yao, J. Duan, K. Xu, Y . Cai, Z. Sun, and Y . Zhang, “A survey on large language model (llm) security and privacy: The good, the bad, and the ugly,” High-Confidence Computing , vol. 4, no. 2, p. 100211, 2024
2024
Show all 130 references
-
[1]
How machine learning changes the nature of cyberattacks on iot networks: A survey,
E. Bout, V . Loscri, and A. Gallais, “How machine learning changes the nature of cyberattacks on iot networks: A survey,” IEEE Commu- nications Surveys & Tutorials , vol. 24, no. 1, pp. 248–279, 2022
2022
-
[2]
Robust and resilient distributed optimal frequency control for microgrids against cyber attacks,
Y . Liu, Y . Li, Y . Wang, X. Zhang, H. B. Gooi, and H. Xin, “Robust and resilient distributed optimal frequency control for microgrids against cyber attacks,” IEEE Transactions on Industrial Informatics , vol. 18, no. 1, pp. 375–386, 2022
2022
-
[4]
Generative ai based secure wireless sensing for isac networks,
J. Wang, H. Du, Y . Liu, G. Sun, D. Niyato, S. Mao, D. I. Kim, and X. Shen, “Generative ai based secure wireless sensing for isac networks,” arXiv preprint arXiv:2408.11398, 2024
2024 arXiv
-
[5]
A novel cyberattack-resilient frequency control method for interconnected power systems using smo-based attack estimation,
A. D. Syrmakesis, H. H. Alhelou, and N. D. Hatziargyriou, “A novel cyberattack-resilient frequency control method for interconnected power systems using smo-based attack estimation,” IEEE Transactions on Power Systems, vol. 39, no. 4, pp. 5672–5686, 2024
2024
-
[6]
A novel iot network intrusion detection approach based on adaptive particle swarm optimization convolutional neural network,
X. Kan, Y . Fan, Z. Fang, L. Cao, N. N. Xiong, D. Yang, and X. Li, “A novel iot network intrusion detection approach based on adaptive particle swarm optimization convolutional neural network,”Information Sciences, vol. 568, pp. 147–162, 2021
2021
-
[7]
Secure intelligent fuzzy blockchain framework: Ef- fective threat detection in iot networks,
A. Yazdinejad, A. Dehghantanha, R. M. Parizi, G. Srivastava, and H. Karimipour, “Secure intelligent fuzzy blockchain framework: Ef- fective threat detection in iot networks,” Computers in Industry , vol. 144, p. 103801, 2023
2023
-
[8]
Redun- dancy planning for cost efficient resilience to cyber attacks,
J. Soikkeli, G. Casale, L. Mu ˜noz-Gonz´alez, and E. C. Lupu, “Redun- dancy planning for cost efficient resilience to cyber attacks,” IEEE Transactions on Dependable and Secure Computing , vol. 20, no. 2, pp. 1154–1168, 2023
2023
-
[9]
The role of national cybersecurity strategies on the improvement of cybersecurity education,
S. AlDaajeh, H. Saleous, S. Alrabaee, E. Barka, F. Breitinger, and K.- K. Raymond Choo, “The role of national cybersecurity strategies on the improvement of cybersecurity education,” Computers & Security , vol. 119, p. 102754, 2022
2022
-
[10]
Large lan- guage models for cyber resilience: A comprehensive review, challenges, and future perspectives,
W. Ding, M. Abdel-Basset, A. M. Ali, and N. Moustafa, “Large lan- guage models for cyber resilience: A comprehensive review, challenges, and future perspectives,” Applied Soft Computing, vol. 170, p. 112663, 2025
2025
-
[11]
Trusting artificial intel- ligence in cybersecurity is a double-edged sword,
M. Taddeo, T. McCutcheon, and L. Floridi, “Trusting artificial intel- ligence in cybersecurity is a double-edged sword,” Nature Machine Intelligence, vol. 1, no. 12, pp. 557–560, 2019
2019
-
[12]
Transformers and large language models for efficient intrusion detection systems: A comprehensive survey,
H. Kheddar, “Transformers and large language models for efficient intrusion detection systems: A comprehensive survey,” arXiv preprint arXiv:2408.07583, 2025
2025 arXiv
-
[13]
Llms in software security: A survey of vulnerability detection techniques and insights,
Z. Sheng, Z. Chen, S. Gu, H. Huang, G. Gu, and J. Huang, “Llms in software security: A survey of vulnerability detection techniques and insights,” arXiv preprint arXiv:2502.07049, 2025
2025 arXiv
-
[14]
Large language model for vulnerability detection and repair: Literature review and the road ahead,
X. Zhou, S. Cao, X. Sun, and D. Lo, “Large language model for vulnerability detection and repair: Literature review and the road ahead,” ACM Trans. Softw. Eng. Methodol. , Dec. 2024, just Accepted
2024
-
[19]
Lawllm: Law large language model for the us legal system,
D. Shu, H. Zhao, X. Liu, D. Demeter, M. Du, and Y . Zhang, “Lawllm: Law large language model for the us legal system,” in Proceedings of the 33rd ACM International Conference on Information and Knowledge Management, ser. CIKM ’24. New York, NY , USA: Association for Computing ...
2024
-
[20]
Llm-based agentic systems in medicine and healthcare,
J. Qiu, K. Lam, G. Li, A. Acharya, T. Y . Wong, A. Darzi, W. Yuan, and E. J. Topol, “Llm-based agentic systems in medicine and healthcare,” Nature Machine Intelligence , vol. 6, no. 12, pp. 1418–1420, 12 2024
2024
-
[21]
Ai for education (ai4edu): Advancing personalized education with llm and adaptive learning,
Q. Wen, J. Liang, C. Sierra, R. Luckin, R. Tong, Z. Liu, P. Cui, and J. Tang, “Ai for education (ai4edu): Advancing personalized education with llm and adaptive learning,” ser. KDD ’24. New York, NY , USA: Association for Computing Machinery, 2024, p. 6743–6744
2024
-
[22]
Secqa: A concise question-answering dataset for evalu- ating large language models in computer security,
Z. Liu, “Secqa: A concise question-answering dataset for evalu- ating large language models in computer security,” arXiv preprint arXiv:2312.15838, 2023
2023 arXiv
-
[23]
Cybermetric: A benchmark dataset based on retrieval-augmented gen- eration for evaluating llms in cybersecurity knowledge,
N. Tihanyi, M. A. Ferrag, R. Jain, T. Bisztray, and M. Debbah, “Cybermetric: A benchmark dataset based on retrieval-augmented gen- eration for evaluating llms in cybersecurity knowledge,” in 2024 IEEE International Conference on Cyber Security and Resilience (CSR) , 2024, pp. 296–302
2024
-
[24]
Cyberbench: A multi-task benchmark for evaluating large language models in cybersecurity,
Z. Liu, J. Shi, and J. F. Buford, “Cyberbench: A multi-task benchmark for evaluating large language models in cybersecurity,” AAAI-24 Workshop on Artificial Intelligence for Cyber Security (AICS), 2024
2024
-
[25]
Secure: Benchmarking large language models for cybersecurity,
D. Bhusal, M. T. Alam, L. Nguyen, A. Mahara, Z. Lightcap, R. Frazier, R. Fieblinger, G. L. Torales, B. A. Blakely, and N. Rastogi, “Secure: Benchmarking large language models for cybersecurity,” arXiv preprint arXiv:2405.20441, 2024
2024 arXiv
-
[26]
Hackmentor: Fine-tuning large language models for cybersecurity,
J. Zhang, H. Wen, L. Deng, M. Xin, Z. Li, L. Li, H. Zhu, and L. Sun, “Hackmentor: Fine-tuning large language models for cybersecurity,” in 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom) , 2023, pp. 452–461
2023
-
[27]
Time for action: Automated analysis of cyber threat intelligence in the wild,
G. Siracusano, D. Sanvito, R. Gonzalez, M. Srinivasan, S. Kamatchi, W. Takahashi, M. Kawakita, T. Kakumaru, and R. Bifulco, “Time for action: Automated analysis of cyber threat intelligence in the wild,” arXiv preprint arXiv:2307.10214, 2023
2023 arXiv
-
[28]
A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,
A. Alshamrani, S. Myneni, A. Chowdhary, and D. Huang, “A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,” IEEE Communications Surveys & Tutorials , vol. 21, no. 2, pp. 1851–1877, 2019
2019
-
[29]
Domain and website attribution beyond whois,
S. Sebasti ´an, R.-G. Diugan, J. Caballero, I. Sanchez-Rola, and L. Bilge, “Domain and website attribution beyond whois,” in Proceedings of the 39th Annual Computer Security Applications Conference , ser. ACSAC ’23. New York, NY , USA: Association for Computing Machinery, 2023...
2023
-
[30]
Automation of recon process for ethical hackers,
V . R. Saraswathi, I. S. Ahmed, S. M. Reddy, S. Akshay, V . M. Reddy, and S. M. Reddy, “Automation of recon process for ethical hackers,” in 2022 International Conference for Advancement in Technology (ICONAT), 2022, pp. 1–6
2022
-
[31]
An enhanced social engineering optimizer for solving an energy-efficient disassembly line balancing problem based on bucket brigades and cloud theory,
G. Tian, C. Zhang, A. M. Fathollahi-Fard, Z. Li, C. Zhang, and Z. Jiang, “An enhanced social engineering optimizer for solving an energy-efficient disassembly line balancing problem based on bucket brigades and cloud theory,” IEEE Transactions on Industrial Informat- ics, vol....
2023
-
[32]
Survey and taxonomy of adversarial reconnaissance techniques,
S. Roy, N. Sharmin, J. C. Acosta, C. Kiekintveld, and A. Laszka, “Survey and taxonomy of adversarial reconnaissance techniques,” ACM Comput. Surv., vol. 55, no. 6, Dec. 2022
2022
-
[33]
A hybrid cyber defense mechanism to mitigate the persistent scan and foothold attack,
S. Wang, Q. Pei, Y . Zhang, X. Liu, and G. Tang, “A hybrid cyber defense mechanism to mitigate the persistent scan and foothold attack,” Security and Communication Networks , vol. 2020, no. 1, p. 8882200, 2020
2020
-
[34]
Catching phishers by their bait: Investigating the dutch phishing landscape through phishing kit detection,
H. Bijmans, T. Booij, A. Schwedersky, A. Nedgabat, and R. van Wegberg, “Catching phishers by their bait: Investigating the dutch phishing landscape through phishing kit detection,” in 30th USENIX Security Symposium (USENIX Security 21) . USENIX Association, Aug. 2021, pp. 3757–3774
2021
-
[35]
An attack exploiting cyber-arm industry,
J. Gan, C. Luo, W. Shi, Y . Liu, X. Liu, and Z. Tian, “An attack exploiting cyber-arm industry,” IEEE Transactions on Dependable and Secure Computing, vol. 22, no. 2, pp. 1686–1702, 2025
2025
-
[36]
Sbi model for the detection of advanced persistent threat based on strange behavior of using credential dumping technique,
N. Mohamed and B. Belaton, “Sbi model for the detection of advanced persistent threat based on strange behavior of using credential dumping technique,” IEEE Access, vol. 9, pp. 42 919–42 932, 2021. IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, VOL. XX, NO. XX, XXXX XXXX 17
2021
-
[37]
Hidden markov model and cyber deception for the prevention of adversarial lateral movement,
M. A. R. A. Amin, S. Shetty, L. Njilla, D. K. Tosh, and C. Kamhoua, “Hidden markov model and cyber deception for the prevention of adversarial lateral movement,” IEEE Access, vol. 9, pp. 49 662–49 682, 2021
2021
-
[38]
Advanced persistent threats (apt): evolution, anatomy, attribution and countermea- sures,
A. Sharma, B. B. Gupta, A. K. Singh, and V . Saraswat, “Advanced persistent threats (apt): evolution, anatomy, attribution and countermea- sures,” Journal of Ambient Intelligence and Humanized Computing , vol. 14, no. 7, pp. 9355–9381, 2023
2023
-
[39]
How to disturb network reconnaissance: A moving target defense approach based on deep reinforcement learning,
T. Zhang, C. Xu, J. Shen, X. Kuang, and L. A. Grieco, “How to disturb network reconnaissance: A moving target defense approach based on deep reinforcement learning,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 5735–5748, 2023
2023
-
[40]
Pllm- cs: Pre-trained large language model (llm) for cyber threat detection in satellite networks,
M. Hassanin, M. Keshk, S. Salim, M. Alsubaie, and D. Sharma, “Pllm- cs: Pre-trained large language model (llm) for cyber threat detection in satellite networks,” Ad Hoc Networks , vol. 166, p. 103645, 2025
2025
-
[41]
Audit-llm: Multi-agent collaboration for log-based insider threat detection,
C. Song, L. Ma, J. Zheng, J. Liao, H. Kuang, and L. Yang, “Audit-llm: Multi-agent collaboration for log-based insider threat detection,” arXiv preprint arXiv:2408.08902, 2024
2024 arXiv
-
[42]
Llm in the shell: Generative honeypots,
M. Sladi ´c, V . Valeros, C. Catania, and S. Garcia, “Llm in the shell: Generative honeypots,” in2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) , 2024, pp. 430–435
2024
-
[43]
Prompting large language models for malicious webpage detection,
L. Li and B. Gong, “Prompting large language models for malicious webpage detection,” in 2023 IEEE 4th International Conference on Pattern Recognition and Machine Learning (PRML) , 2023, pp. 393– 400
2023
-
[44]
Chatspamdetector: Leveraging large language models for effective phishing email detec- tion,
T. Koide, N. Fukushi, H. Nakano, and D. Chiba, “Chatspamdetector: Leveraging large language models for effective phishing email detec- tion,” arXiv preprint arXiv:2402.18093, 2024
2024 arXiv
-
[45]
Large language models for code analysis: Do llms really do their job?
C. Fang, N. Miao, S. Srivastav, J. Liu, R. Zhang, R. Fang, Asmita, R. Tsang, N. Nazari, H. Wang, and H. Homayoun, “Large language models for code analysis: Do llms really do their job?” in 33rd USENIX Security Symposium (USENIX Security 24) . Philadelphia, PA: USENIX Associati...
2024
-
[46]
Towards novel malicious packet recognition: A few-shot learning approach,
K. Stein, A. A. Mahyari, G. Francia, and E. El-Sheikh, “Towards novel malicious packet recognition: A few-shot learning approach,” in MILCOM 2024 - 2024 IEEE Military Communications Conference (MILCOM), 2024, pp. 847–852
2024
-
[47]
Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,
Z. Yu, M. Wen, X. Guo, and H. Jin, “Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset,” in Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, ser. ISSTA 2024. New York, NY , USA: Association for Computin...
2024
-
[48]
Exploring large language model-powered pedagogical approaches to cybersecurity education,
C. Chhetri, “Exploring large language model-powered pedagogical approaches to cybersecurity education,” in Proceedings of the 25th Annual Conference on Information Technology Education, ser. SIGITE ’24. New York, NY , USA: Association for Computing Machinery, 2024, p. 163–166
2024
-
[49]
Llm-driven sat impact on phishing defense: A cross-sectional analysis,
H. ˙IS ¸, “Llm-driven sat impact on phishing defense: A cross-sectional analysis,” in 2024 12th International Symposium on Digital Forensics and Security (ISDFS) , 2024, pp. 1–5
2024
-
[50]
Probabilistic models for evaluating network edge’s resistance against scan and foothold attack,
S. Wang, Q. Pei, Y . Xiao, F. Shao, S. Yuan, J. Chu, and R. Liao, “Probabilistic models for evaluating network edge’s resistance against scan and foothold attack,” IET Communications , vol. 18, no. 20, pp. 1983–1995, 2024
1983
-
[51]
Grace: Empowering llm-based software vulnerability detection with graph structure and in- context learning,
G. Lu, X. Ju, X. Chen, W. Pei, and Z. Cai, “Grace: Empowering llm-based software vulnerability detection with graph structure and in- context learning,” Journal of Systems and Software, vol. 212, p. 112031, 2024
2024
-
[52]
Security vulnerability detection with multitask self-instructed fine-tuning of large language models,
A. Z. H. Yang, H. Tian, H. Ye, R. Martins, and C. L. Goues, “Security vulnerability detection with multitask self-instructed fine-tuning of large language models,” arXiv preprint arXiv:2406.05892, 2024
2024 arXiv
-
[53]
Vtt- llm: Advancing vulnerability-to-tactic-and-technique mapping through fine-tuning of large language model,
C. Zhang, L. Wang, D. Fan, J. Zhu, T. Zhou, L. Zeng, and Z. Li, “Vtt- llm: Advancing vulnerability-to-tactic-and-technique mapping through fine-tuning of large language model,” Mathematics, vol. 12, no. 9, p. 1286, 2024
2024
-
[54]
Apply transfer learning to cy- bersecurity: Predicting exploitability of vulnerabilities by description,
J. Yin, M. Tang, J. Cao, and H. Wang, “Apply transfer learning to cy- bersecurity: Predicting exploitability of vulnerabilities by description,” Knowledge-Based Systems, vol. 210, p. 106529, 2020
2020
-
[55]
Fellmvp: An ensemble llm framework for classifying smart contract vulnerabilities,
Y . Luo, W. Xu, K. Andersson, M. S. Hossain, and D. Xu, “Fellmvp: An ensemble llm framework for classifying smart contract vulnerabilities,” in 2024 IEEE International Conference on Blockchain (Blockchain) , 2024, pp. 89–96
2024
-
[56]
Con- tracttinker: Llm-empowered vulnerability repair for real-world smart contracts,
C. Wang, J. Zhang, J. Gao, L. Xia, Z. Guan, and Z. Chen, “Con- tracttinker: Llm-empowered vulnerability repair for real-world smart contracts,” in Proceedings of the 39th IEEE/ACM International Con- ference on Automated Software Engineering, ser. ASE ’24. New York, NY , USA: A...
2024
-
[57]
Zeroleak: Automated side-channel patching in source code using llms,
M. C. Tol and B. Sunar, “Zeroleak: Automated side-channel patching in source code using llms,” in Computer Security – ESORICS 2024 , J. Garcia-Alfaro, R. Kozik, M. Chora ´s, and S. Katsikas, Eds. Cham: Springer Nature Switzerland, 2024, pp. 290–310
2024
-
[58]
Automating zero- shot patch porting for hard forks,
S. Pan, Y . Wang, Z. Liu, X. Hu, X. Xia, and S. Li, “Automating zero- shot patch porting for hard forks,” in Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis , ser. ISSTA 2024. New York, NY , USA: Association for Computing Machinery,...
2024
-
[59]
Leveraging large language model for automatic patch correctness assessment,
X. Zhou, B. Xu, K. Kim, D. Han, H. H. Nguyen, T. Le-Cong, J. He, B. Le, and D. Lo, “Leveraging large language model for automatic patch correctness assessment,” IEEE Transactions on Software Engi- neering, vol. 50, no. 11, pp. 2865–2883, 2024
2024
-
[60]
Getting pwn’d by ai: Penetration testing with large language models,
A. Happe and J. Cito, “Getting pwn’d by ai: Penetration testing with large language models,” in Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , ser. ESEC/FSE 2023. New York, NY , USA: Associa...
2023
-
[61]
Multitask-based evaluation of open- source llm on software vulnerability,
X. Yin, C. Ni, and S. Wang, “Multitask-based evaluation of open- source llm on software vulnerability,” IEEE Transactions on Software Engineering, vol. 50, no. 11, pp. 3071–3087, 2024
2024
-
[62]
An empirical study of automated vulnerability localization with large language models,
J. Zhang, C. Wang, A. Li, W. Sun, C. Zhang, W. Ma, and Y . Liu, “An empirical study of automated vulnerability localization with large language models,” arXiv preprint arXiv:2404.00287, 2024
2024
-
[63]
Microwalk: A framework for finding side channels in binaries,
J. Wichelmann, A. Moghimi, T. Eisenbarth, and B. Sunar, “Microwalk: A framework for finding side channels in binaries,” in Proceedings of the 34th Annual Computer Security Applications Conference , ser. ACSAC ’18. New York, NY , USA: Association for Computing Machinery, 2018, ...
2018
-
[64]
Diversevul: A new vulnerable source code dataset for deep learning based vulner- ability detection,
Y . Chen, Z. Ding, L. Alowain, X. Chen, and D. Wagner, “Diversevul: A new vulnerable source code dataset for deep learning based vulner- ability detection,” in Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses , ser. RAID ’23. New ...
2023
-
[65]
Outside the comfort zone: Analysing llm capabilities in software vulnerability detection,
Y . Guo, C. Patsakis, Q. Hu, Q. Tang, and F. Casino, “Outside the comfort zone: Analysing llm capabilities in software vulnerability detection,” in Computer Security – ESORICS 2024 , J. Garcia-Alfaro, R. Kozik, M. Chora ´s, and S. Katsikas, Eds. Cham: Springer Nature Switzerla...
2024
-
[66]
Chatgpt for vulnerability detection, classification, and repair: How far are we?
M. Fu, C. K. Tantithamthavorn, V . Nguyen, and T. Le, “Chatgpt for vulnerability detection, classification, and repair: How far are we?” in 2023 30th Asia-Pacific Software Engineering Conference (APSEC) , 2023, pp. 632–636
2023
-
[67]
Chain-of- thought prompting of large language models for discovering and fixing software vulnerabilities,
Y . Nong, M. Aldeen, L. Cheng, H. Hu, F. Chen, and H. Cai, “Chain-of- thought prompting of large language models for discovering and fixing software vulnerabilities,” arXiv preprint arXiv:2402.17230, 2024
2024 arXiv
-
[68]
Lmtracker: Lateral movement path detection based on heterogeneous graph embedding,
Y . Fang, C. Wang, Z. Fang, and C. Huang, “Lmtracker: Lateral movement path detection based on heterogeneous graph embedding,” Neurocomputing, vol. 474, pp. 37–47, 2022
2022
-
[69]
Jbeil: Temporal graph-based inductive learning to infer lateral movement in evolving enterprise networks,
J. Khoury, D. Klisura, H. Zanddizari, G. De La Torre Parra, P. Najafirad, and E. Bou-Harb, “Jbeil: Temporal graph-based inductive learning to infer lateral movement in evolving enterprise networks,” in 2024 IEEE Symposium on Security and Privacy (SP) , 2024, pp. 3644–3660
2024
-
[75]
How to mitigate ddos intelligently in sd-iov: A moving target defense approach,
T. Zhang, C. Xu, P. Zou, H. Tian, X. Kuang, S. Yang, L. Zhong, and D. Niyato, “How to mitigate ddos intelligently in sd-iov: A moving target defense approach,” IEEE Transactions on Industrial Informatics, vol. 19, no. 1, pp. 1097–1106, 2023. IEEE TRANSACTIONS ON NETWORK SCIENC...
2023
-
[76]
Uncovering lateral movement using authentication logs,
H. Bian, T. Bai, M. A. Salahuddin, N. Limam, A. A. Daya, and R. Boutaba, “Uncovering lateral movement using authentication logs,” IEEE Transactions on Network and Service Management, vol. 18, no. 1, pp. 1049–1063, 2021
2021
-
[77]
Log parsing: How far can chatgpt go?
V .-H. Le and H. Zhang, “Log parsing: How far can chatgpt go?” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2023, pp. 1699–1704
2023
-
[78]
Detecting lateral movement: A systematic survey,
C. Smiliotopoulos, G. Kambourakis, and C. Kolias, “Detecting lateral movement: A systematic survey,” Heliyon, vol. 10, no. 4, p. e26317, 02 2024, doi: 10.1016/j.heliyon.2024.e26317
2024 doi
-
[79]
Definition: Threat intelligence,
R. McMillan, “Definition: Threat intelligence,” [Online], 2022, accessed: Dec. 10, 2024. [Online]. Available: https://gartner.com/
2022
-
[80]
Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives,
N. Sun, M. Ding, J. Jiang, W. Xu, X. Mo, Y . Tai, and J. Zhang, “Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives,” IEEE Communications Surveys & Tutorials , vol. 25, no. 3, pp. 1748–1774, 2023
2023
-
[81]
Security and resilience in sustainable smart cities through cyber threat intelligence,
K. Nova, “Security and resilience in sustainable smart cities through cyber threat intelligence,” International Journal of Information and Cybersecurity, vol. 6, no. 1, pp. 21–42, 2022
2022
-
[82]
The use of large language models (llm) for cyber threat intelligence (cti) in cybercrime forums,
V . Clairoux-Trepanier, I.-M. Beauchamp, E. Ruellan, M. Paquet- Clouston, S.-O. Paquette, and E. Clay, “The use of large language models (llm) for cyber threat intelligence (cti) in cybercrime forums,” arXiv preprint arXiv:2408.03354 , 2024
2024 arXiv
-
[83]
Localintel: Generating organizational threat intel- ligence from global and local cyber knowledge,
S. Mitra, S. Neupane, T. Chakraborty, S. Mittal, A. Piplai, M. Gaur, and S. Rahimi, “Localintel: Generating organizational threat intel- ligence from global and local cyber knowledge,” arXiv preprint arXiv:2401.10036, 2024
2024 arXiv
-
[84]
Actionable cyber threat intelligence using knowledge graphs and large language models,
R. Fieblinger, M. T. Alam, and N. Rastogi, “Actionable cyber threat intelligence using knowledge graphs and large language models,” in 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), 2024, pp. 100–111
2024
-
[85]
Cti view: Apt threat intelligence analysis system,
Y . Zhou, Y . Tang, M. Yi, C. Xi, and H. Lu, “Cti view: Apt threat intelligence analysis system,” Security and Communication Networks , vol. 2022, no. 1, p. 9875199, 2022
2022
-
[86]
Cskg4apt: A cyber- security knowledge graph for advanced persistent threat organization attribution,
Y . Ren, Y . Xiao, Y . Zhou, Z. Zhang, and Z. Tian, “Cskg4apt: A cyber- security knowledge graph for advanced persistent threat organization attribution,” IEEE Transactions on Knowledge and Data Engineering , vol. 35, no. 6, pp. 5695–5709, 2023
2023
-
[87]
Crimson: Empowering strategic reasoning in cybersecurity through large language models,
J. Jin, B. Tang, M. Ma, X. Liu, Y . Wang, Q. Lai, J. Yang, and C. Zhou, “Crimson: Empowering strategic reasoning in cybersecurity through large language models,” arXiv preprint arXiv:2403.00878, 2024
2024 arXiv
-
[88]
Inferring recovery steps from cyber threat intelligence reports,
Z. L. Kucsv ´an, M. Caselli, A. Peter, and A. Continella, “Inferring recovery steps from cyber threat intelligence reports,” in Detection of Intrusions and Malware, and Vulnerability Assessment , F. Maggi, M. Egele, M. Payer, and M. Carminati, Eds. Cham: Springer Nature Switze...
2024
-
[89]
Mining temporal attack patterns from cyberthreat intelligence reports,
M. R. Rahman, B. Wroblewski, Q. Matthews, B. Morgan, T. Menzies, and L. Williams, “Mining temporal attack patterns from cyberthreat intelligence reports,” arXiv preprint arXiv:2401.01883, 2024
2024 arXiv
-
[90]
Large language models empowered autonomous edge ai for connected intelligence,
Y . Shen, J. Shao, X. Zhang, Z. Lin, H. Pan, D. Li, J. Zhang, and K. B. Letaief, “Large language models empowered autonomous edge ai for connected intelligence,” IEEE Communications Magazine , vol. 62, no. 10, pp. 140–146, 2024
2024
-
[91]
A survey of network automation for industrial internet-of-things toward industry 5.0,
H. R. Chi, C. K. Wu, N.-F. Huang, K.-F. Tsang, and A. Radwan, “A survey of network automation for industrial internet-of-things toward industry 5.0,” IEEE Transactions on Industrial Informatics , vol. 19, no. 2, pp. 2065–2077, 2023
2023
-
[92]
Five facets of 6g: Research challenges and opportunities,
L.-H. Shen, K.-T. Feng, and L. Hanzo, “Five facets of 6g: Research challenges and opportunities,” ACM Comput. Surv. , vol. 55, no. 11, Feb. 2023
2023
-
[93]
(com)2net: A novel communication and computation integrated net- work architecture,
W. Zhang, D. Yang, C. Zhang, Q. Ye, H. Zhang, and X. Shen, “(com)2net: A novel communication and computation integrated net- work architecture,” IEEE Network, vol. 38, no. 2, pp. 35–44, 2024
2024
-
[94]
Det(com)2: Deterministic communication and computation integration toward aigc services,
W. Zhang, N. Tang, D. Yang, R. Guo, H. Zhang, and X. Shen, “Det(com)2: Deterministic communication and computation integration toward aigc services,” IEEE Wireless Communications, vol. 31, no. 3, pp. 32–41, 2024
2024
-
[95]
Intelligent resource adaptation for diversified service requirements in industrial iot,
W. Zhang, Y . He, T. Zhang, C. Ying, and J. Kang, “Intelligent resource adaptation for diversified service requirements in industrial iot,” IEEE Transactions on Cognitive Communications and Networking , pp. 1–1, 2024
2024
-
[96]
Intrusion detection scheme with dimensionality reduc- tion in next generation networks,
K. Sood, M. R. Nosouhi, D. D. N. Nguyen, F. Jiang, M. Chowdhury, and R. Doss, “Intrusion detection scheme with dimensionality reduc- tion in next generation networks,” IEEE Transactions on Information Forensics and Security, vol. 18, pp. 965–979, 2023
2023
-
[97]
Enabling intelligent connectivity: A survey of secure isac in 6g networks,
X. Zhu, J. Liu, L. Lu, T. Zhang, T. Qiu, C. Wang, and Y . Liu, “Enabling intelligent connectivity: A survey of secure isac in 6g networks,” IEEE Communications Surveys & Tutorials , pp. 1–1, 2024
2024
-
[98]
Moving target defense meets artificial intelligence-driven network: A comprehensive survey,
T. Zhang, F. Kong, D. Deng, X. Tang, X. Wu, C. Xu, L. Zhu, J. Liu, B. Ai, Z. Han, and R. H. Deng, “Moving target defense meets artificial intelligence-driven network: A comprehensive survey,” IEEE Internet of Things Journal , pp. 1–1, 2025
2025
-
[99]
Mobile edge intelligence for large language models: A contemporary survey,
G. Qu, Q. Chen, W. Wei, Z. Lin, X. Chen, and K. Huang, “Mobile edge intelligence for large language models: A contemporary survey,” IEEE Communications Surveys & Tutorials , pp. 1–1, 2025
2025
-
[100]
Toward democratized generative ai in next-generation mobile edge networks,
R. Zhang, J. He, X. Luo, D. Niyato, J. Kang, Z. Xiong, Y . Li, and B. Sikdar, “Toward democratized generative ai in next-generation mobile edge networks,” IEEE Network, pp. 1–1, 2025
2025
-
[101]
Integration of federated learning and ai-generated content: A survey of overview, op- portunities, challenges, and solutions,
Y . Liu, J. Yin, W. Zhang, C. An, Y . Xia, and H. Zhang, “Integration of federated learning and ai-generated content: A survey of overview, op- portunities, challenges, and solutions,” IEEE Communications Surveys & Tutorials, pp. 1–1, 2024
2024
-
[102]
Generative ai for space-air-ground integrated networks,
R. Zhang, H. Du, D. Niyato, J. Kang, Z. Xiong, A. Jamalipour, P. Zhang, and D. I. Kim, “Generative ai for space-air-ground integrated networks,” IEEE Wireless Communications, vol. 31, no. 6, pp. 10–20, 2024
2024
-
[103]
Mobile network-specialized large lan- guage models for 6g: Architectures, innovations, challenges, and future trends,
A. Chaoub and M. Elkotob, “Mobile network-specialized large lan- guage models for 6g: Architectures, innovations, challenges, and future trends,” arXiv preprint arXiv:2502.04933, 2025
2025 arXiv
-
[104]
When large language model agents meet 6g networks: Perception, grounding, and alignment,
M. Xu, D. Niyato, J. Kang, Z. Xiong, S. Mao, Z. Han, D. I. Kim, and K. B. Letaief, “When large language model agents meet 6g networks: Perception, grounding, and alignment,” IEEE Wireless Communications, vol. 31, no. 6, pp. 63–71, 2024
2024
-
[105]
Next- gen service function chain deployment: Combining multi-objective optimization with ai large language models,
Y . Li, Q. Zhang, H. Yao, R. Gao, X. Xin, and M. Guizani, “Next- gen service function chain deployment: Combining multi-objective optimization with ai large language models,” IEEE Network , pp. 1– 1, 2025
2025
-
[106]
Hierarchical micro-segmentations for zero-trust services via large language model (llm)-enhanced graph diffusion,
Y . Liu, G. Liu, H. Du, D. Niyato, J. Kang, Z. Xiong, D. I. Kim, and X. Shen, “Hierarchical micro-segmentations for zero-trust services via large language model (llm)-enhanced graph diffusion,” arXiv preprint arXiv:2406.13964, 2024
2024 arXiv
-
[107]
Llm-twin: mini-giant model-driven beyond 5g digital twin networking framework with semantic secure communication and computation,
Y . Hong, J. Wu, and R. Morello, “Llm-twin: mini-giant model-driven beyond 5g digital twin networking framework with semantic secure communication and computation,” Scientific Reports, vol. 14, no. 1, p. 19065, 08 2024
2024
-
[108]
Rethinking the reversal curse of LLMs: a prescription from human knowledge reversal,
Z. Lu, L. Jin, P. Li, Y . Tian, L. Zhang, S. Wang, G. Xu, C. Tian, and X. Cai, “Rethinking the reversal curse of LLMs: a prescription from human knowledge reversal,” in Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing , Y . Al-Onaizan, M. ...
2024
-
[109]
Ergodic sum rate for uplink noma transmission in satellite-aerial-ground integrated networks,
H. KONG, M. LIN, J. ZHANG, J. OUY ANG, J.-B. W ANG, and P. K. UPADHY AY , “Ergodic sum rate for uplink noma transmission in satellite-aerial-ground integrated networks,” Chinese Journal of Aeronautics, vol. 35, no. 9, pp. 58–70, 2022
2022
-
[110]
Utilizing large language models for advanced optimization and intelligent management in space-air-ground integrated networks,
J. Tang, F. Tang, S. Long, M. Zhao, and N. Kato, “Utilizing large language models for advanced optimization and intelligent management in space-air-ground integrated networks,”IEEE Network, pp. 1–1, 2024
2024
-
[111]
Lever- aging large language models for integrated satellite-aerial-terrestrial networks: Recent advances and future directions,
S. Javaid, R. A. Khalil, N. Saeed, B. He, and M.-S. Alouini, “Lever- aging large language models for integrated satellite-aerial-terrestrial networks: Recent advances and future directions,” IEEE Open Journal of the Communications Society , vol. 6, pp. 399–432, 2025
2025
-
[112]
Formalizing and benchmarking prompt injection attacks and defenses,
Y . Liu, Y . Jia, R. Geng, J. Jia, and N. Z. Gong, “Formalizing and benchmarking prompt injection attacks and defenses,” in 33rd USENIX Security Symposium (USENIX Security 24) . Philadelphia, PA: USENIX Association, Aug. 2024, pp. 1831–1847
2024
-
[113]
A survey of safety and trustworthiness of large language models through the lens of verification and validation,
X. Huang, W. Ruan, W. Huang, G. Jin, Y . Dong, C. Wu, S. Bensalem, R. Mu, Y . Qi, X. Zhaoet al., “A survey of safety and trustworthiness of large language models through the lens of verification and validation,” Artificial Intelligence Review , vol. 57, no. 7, p. 175, 2024
2024
-
[114]
Struq: Defending against prompt injection with structured queries,
S. Chen, J. Piet, C. Sitawarin, and D. Wagner, “Struq: Defending against prompt injection with structured queries,” 2024
2024
-
[115]
Jatmo: Prompt injection defense by task-specific finetuning,
J. Piet, M. Alrashed, C. Sitawarin, S. Chen, Z. Wei, E. Sun, B. Alomair, and D. Wagner, “Jatmo: Prompt injection defense by task-specific finetuning,” in Computer Security – ESORICS 2024 , J. Garcia-Alfaro, R. Kozik, M. Chora ´s, and S. Katsikas, Eds. Cham: Springer Nature Swi...
2024
-
[116]
Purifying large language models by ensembling a small language model,
T. Li, Q. Liu, T. Pang, C. Du, Q. Guo, Y . Liu, and M. Lin, “Purifying large language models by ensembling a small language model,” arXiv preprint arXiv:2402.14845, 2024
2024 arXiv
-
[117]
Test-time backdoor mitigation for black-box large IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, VOL. XX, NO. XX, XXXX XXXX 19 language models with defensive demonstrations,
W. Mo, J. Xu, Q. Liu, J. Wang, J. Yan, H. Askari, C. Xiao, and M. Chen, “Test-time backdoor mitigation for black-box large IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, VOL. XX, NO. XX, XXXX XXXX 19 language models with defensive demonstrations,” arXiv preprint arXiv:2...
2025 arXiv
-
[118]
Factscore: Fine-grained atomic evaluation of factual precision in long form text generation,
S. Min, K. Krishna, X. Lyu, M. Lewis, W. tau Yih, P. W. Koh, M. Iyyer, L. Zettlemoyer, and H. Hajishirzi, “Factscore: Fine-grained atomic evaluation of factual precision in long form text generation,” arXiv preprint arXiv:2305.14251, 2023
2023 arXiv
-
[119]
A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,
L. Huang, W. Yu, W. Ma, W. Zhong, Z. Feng, H. Wang, Q. Chen, W. Peng, X. Feng, B. Qin et al. , “A survey on hallucination in large language models: Principles, taxonomy, challenges, and open questions,” ACM Transactions on Information Systems , vol. 43, no. 2, pp. 1–55, 2025
2025
-
[120]
Factuality enhanced language models for open- ended text generation,
N. Lee, W. Ping, P. Xu, M. Patwary, P. N. Fung, M. Shoeybi, and B. Catanzaro, “Factuality enhanced language models for open- ended text generation,” in Advances in Neural Information Processing Systems, S. Koyejo, S. Mohamed, A. Agarwal, D. Belgrave, K. Cho, and A. Oh, Eds., v...
2022
-
[121]
Unknown web attack threat detection based on large language model,
Y . Xu, Q. Zhang, H. Deng, Z. Liu, C. Yang, and Y . Fang, “Unknown web attack threat detection based on large language model,” Applied Soft Computing, vol. 173, p. 112905, 2025
2025
-
[122]
Data quality for software vulnerability datasets,
R. Croft, M. A. Babar, and M. M. Kholoosi, “Data quality for software vulnerability datasets,” in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) , 2023, pp. 121–133
2023
-
[123]
A case study of llm for automated vulnerability repair: Assessing impact of reasoning and patch validation feedback,
U. Kulsum, H. Zhu, B. Xu, and M. d’Amorim, “A case study of llm for automated vulnerability repair: Assessing impact of reasoning and patch validation feedback,” inProceedings of the 1st ACM International Conference on AI-Powered Software , ser. AIware 2024. New York, NY , USA...
2024
-
[124]
Comparison of static application security testing tools and large language models for repo-level vulnerability detection,
X. Zhou, D.-M. Tran, T. Le-Cong, T. Zhang, I. C. Irsan, J. Sumarlin, B. Le, and D. Lo, “Comparison of static application security testing tools and large language models for repo-level vulnerability detection,” arXiv preprint arXiv:2407.16235, 2024
2024 arXiv
-
[125]
Chatphishdetector: Detecting phishing sites using large language models,
T. Koide, H. Nakano, and D. Chiba, “Chatphishdetector: Detecting phishing sites using large language models,” IEEE Access, vol. 12, pp. 154 381–154 400, 2024
2024
-
[126]
Apelid: Enhancing real- time intrusion detection with augmented wgan and parallel ensemble learning,
H. V . V o, H. P. Du, and H. N. Nguyen, “Apelid: Enhancing real- time intrusion detection with augmented wgan and parallel ensemble learning,” Computers & Security , vol. 136, p. 103567, 2024
2024
-
[127]
Examin- ing zero-shot vulnerability repair with large language models,
H. Pearce, B. Tan, B. Ahmad, R. Karri, and B. Dolan-Gavitt, “Examin- ing zero-shot vulnerability repair with large language models,” in 2023 IEEE Symposium on Security and Privacy (SP) , 2023, pp. 2339–2356. Shuang Tian received the B.Eng. degree in com- puter science and tech...
2023
-
[1999]
He has authored or coauthored over 200 publications
He is currently a Full Professor and the Dean of the School of Cyberspace Science and Technol- ogy, Beijing Jiaotong University. He has authored or coauthored over 200 publications. In recent years, he has been mainly engaged in research on trusted computing, privacy protectio...
2013
-
[2018]
student at ETH Zurich, Switzerland, supported by the China Schol- arship Council in 2021
He served as a joint Ph.D. student at ETH Zurich, Switzerland, supported by the China Schol- arship Council in 2021. He is currently an Assistant Professor (Lecturer) with the School of Cyberspace Science and Technology, Beijing Jiaotong Univer- sity, China. He has published s...
2021
-
[2021]
Starting from December 2021, he works as an asso- ciate professor with the School of Electronic and In- formation Engineering, Beijing Jiaotong University
From 2019 to 2020, he was a visiting PhD student with the Department of Electrical and Com- puter Engineering, University of Waterloo, Canada. Starting from December 2021, he works as an asso- ciate professor with the School of Electronic and In- formation Engineering, Beijing...
2019
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.