Despite the significant advances that Large Language Models (LLMs) offer in processing vast amounts of data and providing actionable insights quickly, their application in the technical field of cybersecurity poses significant challenges. These include the tendency to produce hallucinatory and unreliable results when these models are tested on questions where factuality is important. Furthermore, while Retrieval Augmented Generation (RAG) systems are useful in enriching model answers with relevant information, they struggle with issues related to retrieval speed, choice of embeddings and thresholds and handling multi-hop queries. This paper describes these challenges and discusses strategies to overcome them in order to improve the adaptability and reliability of these models in responding to rapidly evolving cybersecurity threats.

Cybersecurity with LLMs and RAGs: Challenges and Innovations / Simoni, Marco; Saracino, Andrea. - (2026), pp. 169-183. - LECTURE NOTES OF THE INSTITUTE FOR COMPUTER SCIENCES, SOCIAL INFORMATICS AND TELECOMMUNICATIONS ENGINEERING. [10.1007/978-3-031-94458-1_8].

Cybersecurity with LLMs and RAGs: Challenges and Innovations

Simoni, Marco
Primo
;
2026

Abstract

Despite the significant advances that Large Language Models (LLMs) offer in processing vast amounts of data and providing actionable insights quickly, their application in the technical field of cybersecurity poses significant challenges. These include the tendency to produce hallucinatory and unreliable results when these models are tested on questions where factuality is important. Furthermore, while Retrieval Augmented Generation (RAG) systems are useful in enriching model answers with relevant information, they struggle with issues related to retrieval speed, choice of embeddings and thresholds and handling multi-hop queries. This paper describes these challenges and discusses strategies to overcome them in order to improve the adaptability and reliability of these models in responding to rapidly evolving cybersecurity threats.
2026
Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
9783031944574
9783031944581
Large Language Models; Malware Analysis; Retrieval Augmented Generation; Threat Intelligence; Vulnerability Detection
02 Pubblicazione su volume::02a Capitolo o Articolo
Cybersecurity with LLMs and RAGs: Challenges and Innovations / Simoni, Marco; Saracino, Andrea. - (2026), pp. 169-183. - LECTURE NOTES OF THE INSTITUTE FOR COMPUTER SCIENCES, SOCIAL INFORMATICS AND TELECOMMUNICATIONS ENGINEERING. [10.1007/978-3-031-94458-1_8].
File allegati a questo prodotto
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1752452
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact