paper-with-me

Papers

Leveraging Large Language Models for Cybersecurity Risk Assessment -- A Case from Forestry Cyber-Physical Systems

2025-10-07 · Fikret Mert Gultekin, Oscar Lilja, Ranim Khojah, Rebekka Wohlrab, Marvin Damschen, Mazen Mohamad arxiv

In safety-critical software systems, cybersecurity activities become essential, with risk assessment being one of the most critical. In many software teams, cybersecurity experts are either entirely absent or represented by only a small number of specialists. As a result, the workload for these experts becomes high, and software engineers would need to conduct cybersecurity activities themselves. This creates a need for a tool to support cybersecurity experts and engineers in evaluating vulnerabilities and threats during the risk assessment process. This paper explores the potential of leveraging locally hosted large language models (LLMs) with retrieval-augmented generation to support cybersecurity risk assessment in the forestry domain while complying with data protection and privacy requirements that limit external data sharing. We performed a design science study involving 12 experts in interviews, interactive sessions, and a survey within a large-scale project. The results demonstrate that LLMs can assist cybersecurity experts by generating initial risk assessments, identifying threats, and providing redundancy checks. The results also highlight the necessity for human oversight to ensure accuracy and compliance. Despite trust concerns, experts were willing to utilize LLMs in specific evaluation and assistance roles, rather than solely relying on their generative capabilities. This study provides insights that encourage the use of LLM-based agents to support the risk assessment process of cyber-physical systems in safety-critical domains.

📄 PDF Abstract BibTeX arXiv:2510.06343

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

LLM Cyber Evaluations Don't Capture Real-World Risk

2025-01-31 · Kamilė Lukošiūtė, Adam Swanda

Large language models (LLMs) are demonstrating increasing prowess in cybersecurity applications, creating creating inherent risks alongside their potential for strengthening defenses. In this position paper, we argue tha…

Supporting Cybersecurity Risk Management for Medical Devices via the SECUMAN Ontology and Shapes

2026-08-01 · Martin Diller, Anne Esslinger, Piotr Gorczyca, Evi Hartig 외 arxiv

We propose the SECUMAN ontology and shapes for representing and analysing cybersecurity risk-management documentation for medical devices. Cybersecurity risks are increasingly relevant for connected medical devices and m…

Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques

2025-07-18 · Niveen O. Jaffal, Mohammed Alkhanafseh, David Mohaisen arxiv

Large Language Models (LLMs) are transforming cybersecurity by enabling intelligent, adaptive, and automated approaches to threat detection, vulnerability assessment, and incident response. With their advanced language u…

Dynamic Risk Assessments for Offensive Cybersecurity Agents

2025-05-23 · Boyi Wei, Benedikt Stroebl, Jiacen Xu, Joie Zhang 외

Foundation models are increasingly becoming better autonomous programmers, raising the prospect that they could also automate dangerous offensive cyber-operations. Current frontier model audits probe the cybersecurity ri…

GPU

Cyber Risk Assessment for Capital Management

2022-05-17 · Wing Fung Chong, Runhuan Feng, Hins Hu, Linfeng Zhang

This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cy…

Decision MakingManagement