PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
March 15, 2026Computers, materials & continua/Computers, materials & continua (Print)1 citationsOpen Access

Large Language Models for Cybersecurity Intelligence: A Systematic Review of Emerging Threats, Defensive Capabilities, and Security Evaluation Frameworks

View Full Paper
HAHamed AlqahtaniGKGulshan Kumar

Key Points

  • The central aim is to synthesize the role of LLMs in enhancing cybersecurity while identifying emerging threats.
  • Conducted a systematic review of 167 peer-reviewed studies from 2022 to 2025
  • Proposed a unified threat-defence-evaluation taxonomy
  • Analyzed LLM-enabled threats and defensive applications
  • Identified AIGC-driven threats such as phishing and disinformation campaigns
  • Highlighted advancements in intrusion detection and malware analysis using LLMs
  • Demonstrated a disparity between offensive and defensive cybersecurity innovations

Abstract

Large Language Models (LLMs) are becoming integral components of modern cybersecurity ecosystems, simultaneously strengthening defensive capabilities while giving rise to a new class of Artificial Intelligence–Generated Content (AIGC)-driven threats. This PRISMA-guided systematic review synthesises 167 peer-reviewed studies published between 2022 and 2025 and proposes a unified threat–defence–evaluation taxonomy as a central analytical framework to consolidate a previously fragmented body of research. Guided by this taxonomy, the review first examines AIGC-enabled threats, including automated and highly personalised phishing, polymorphic malware and exploit generation, jailbreak and adversarial prompting, prompt-injection attack vectors, multimodal deception, persona-steering attacks, and large-scale disinformation campaigns. The surveyed evidence indicates a qualitative escalation in adversarial capabilities, with LLMs significantly enhancing scalability, adaptability, and realism while markedly reducing the technical barriers to conducting sophisticated attacks. Second, the review analyses LLM-enabled defensive applications spanning intrusion and anomaly detection, malware analysis and log-semantic modelling, multilingual threat intelligence extraction, vulnerability discovery and code repair, and Security Operations Center (SOC) automation through Retrieval-Augmented Generation (RAG) and multi-agent systems. Although these approaches demonstrate strong potential as semantic reasoning and decision-support components within hybrid security architectures, their real-world effectiveness remains constrained by hallucination risks, adversarial susceptibility, distributional shifts, and operational overhead. Third, the review synthesises current security evaluation and red-teaming practices, revealing a fragmented assessment landscape characterised by narrow benchmarks, inconsistent evaluation metrics, and limited longitudinal robustness analysis. Overall, the taxonomy-driven synthesis highlights a structurally imbalanced ecosystem in which offensive innovation outpaces defensive maturity and governance, and it informs a structured, research-question-aligned roadmap for developing trustworthy, resilient, and policy-aligned LLM-powered cybersecurity systems.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Alqahtani et al. (2026) studied this question.

synapsesocial.com/papers/69b606ea83145bc643d1d509https://doi.org/10.32604/cmc.2026.077367
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Large Language Models for Cybersecurity Intelligence, Threat Hunting, and Decision Support2025 · 11 citations
  2. 2Large Language Models for Cyber Security: A Systematic Literature Review2024 · 27 citations
  3. 3Large Language Models for Cyber Security: A Systematic Literature Review2025 · 132 citations
  4. 4Large Language Models in Cybersecurity: A Survey of Applications, Vulnerabilities, and Defense Techniques2025 · 54 citations
  5. 5Exploring the Role of Large Language Models in Cybersecurity: A Systematic Survey2025