paper-with-me

홈 › Papers

Large Language Models are Unreliable for Cyber Threat Intelligence

2025-03-29 · Emanuele Mezzi, Fabio Massacci, Katja Tuma

Several recent works have argued that Large Language Models (LLMs) can be used to tame the data deluge in the cybersecurity field, by improving the automation of Cyber Threat Intelligence (CTI) tasks. This work presents an evaluation methodology that other than allowing to test LLMs on CTI tasks when using zero-shot learning, few-shot learning and fine-tuning, also allows to quantify their consistency and their confidence level. We run experiments with three state-of-the-art LLMs and a dataset of 350 threat intelligence reports and present new evidence of potential security risks in relying on LLMs for CTI. We show how LLMs cannot guarantee sufficient performance on real-size reports while also being inconsistent and overconfident. Few-shot learning and fine-tuning only partially improve the results, thus posing doubts about the possibility of using LLMs for CTI scenarios, where labelled datasets are lacking and where confidence is a fundamental factor.

📄 PDF Abstract BibTeX arXiv:2503.23175

Code (0)

등록된 구현이 없습니다.

Tasks

Few-Shot LearningZero-Shot Learning

Similar Papers 제목 키워드 기반

KGV: Integrating Large Language Models with Knowledge Graphs for Cyber Threat Intelligence Credibility Assessment

2024-08-15 · Zongzong Wu, Fengxiao Tang, Ming Zhao, Yufeng Li

Cyber threat intelligence is a critical tool that many organizations and individuals use to protect themselves from sophisticated, organized, persistent, and weaponized cyber attacks. However, few studies have focused on…

Fact CheckingKnowledge GraphsSemantic SimilaritySemantic Textual Similarity

The Use of Large Language Models (LLM) for Cyber Threat Intelligence (CTI) in Cybercrime Forums

2024-08-06 · Vanessa Clairoux-Trepanier, Isa-May Beauchamp, Estelle Ruellan, Masarah Paquet-Clouston 외

Large language models (LLMs) can be used to analyze cyber threat intelligence (CTI) data from cybercrime forums, which contain extensive information and key discussions about emerging cyber threats. However, to date, the…

Gathering Cyber Threat Intelligence from Twitter Using Novelty Classification

2019-07-03 · Ba Dung Le, Guanhua Wang, Mehwish Nasim, Ali Babar

Preventing organizations from Cyber exploits needs timely intelligence about Cyber vulnerabilities and attacks, referred as threats. Cyber threat intelligence can be extracted from various sources including social media …

Binary ClassificationClassificationGeneral ClassificationNovelty Detection

LLM-Assisted Proactive Threat Intelligence for Automated Reasoning

2025-04-01 · Shuva Paul, Farhad Alemi, Richard Macwan

Successful defense against dynamically evolving cyber threats requires advanced and sophisticated techniques. This research presents a novel approach to enhance real-time cybersecurity threat detection and response by in…

RAGRetrievalRetrieval-augmented Generation

CTIBench: A Benchmark for Evaluating LLMs in Cyber Threat Intelligence

2024-06-11 · Md Tanvirul Alam, Dipkamal Bhusal, Le Nguyen, Nidhi Rastogi

Cyber threat intelligence (CTI) is crucial in today's cybersecurity landscape, providing essential insights to understand and mitigate the ever-evolving cyber threats. The recent rise of Large Language Models (LLMs) have…