Randomized trial investigates the capability of LLMs to synthesize cyber-attacks in industrial control systems, suggesting potential security risks.
Large Language Models (LLM) such as ChatGPT, Meta AI, and Google Gemini have become highly accessible and ubiquitous across a wide range of applications, including speech synthesis, code generation, and media content creation. Recent research indicates that an alternative motivation for such tools is to rapidly develop malware to conduct cyber attacks. In this paper, we investigate how generative LLM tools can be used to synthesise cyber-attacks targeting Industrial Control Systems (ICS). We introduce a methodology that uses LLMs to generate attack techniques based on the MITRE attack framework to target a variety of Programmable Logic Controllers (PLC) models from by different industrial vendors. We investigate the capability of five leading off-the-shelf LLMs by providing different levels of attacker context to enhance the generation. Through a comprehensive evaluation of the generated code and the resulting LLM outputs, we demonstrate that current general-purpose LLMs are capable of identifying the necessary steps required to synthesise attacks that can manipulate the operations of real PLCs. We highlight that the success of LLM-generated PLC cyberattacks depends on the level of target context initially provided, emphasising the importance of mitigating early-stage reconnaissance attacks in OT environments.
No takes yet. Share an insight, caveat, or question.
Cook et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: