Skip to main navigation Skip to search Skip to main content

Large Language Models Are Unreliable for Cyber Threat Intelligence

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

68 Downloads (Pure)

Abstract

Several recent works have argued that Large Language Models (LLMs) can be used to tame the data deluge in the cybersecurity field, by improving the automation of Cyber Threat Intelligence (CTI) tasks. This work presents an evaluation methodology that other than allowing to test LLMs on CTI tasks when using zero-shot learning, few-shot learning, and fine-tuning, also allows to quantify their consistency and their confidence level. We run experiments with three state-of-the-art LLMs and a dataset of 350 threat intelligence reports and present new evidence of potential security risks in relying on LLMs for CTI. We show how LLMs cannot guarantee sufficient performance on real-size reports while also being inconsistent and overconfident. Few-shot learning and fine-tuning only partially improve the results, thus posing doubts about the possibility of using LLMs for CTI scenarios, where labelled datasets are lacking and where confidence is a fundamental factor.

Original languageEnglish
Title of host publicationAvailability, Reliability and Security
Subtitle of host publication20th International Conference, ARES 2025, Ghent, Belgium, August 11–14, 2025, Proceedings, Part II
EditorsMila Dalla Preda, Sebastian Schrittwieser, Vincent Naessens, Bjorn De Sutter
PublisherSpringer Nature
Pages343-364
Number of pages22
Volume2
ISBN (Electronic)9783032006271
ISBN (Print)9783032006264
DOIs
Publication statusPublished - 2025
Event20th International Conference on Availability, Reliability and Security, ARES 2025 - Ghent, Belgium
Duration: 11 Aug 202514 Aug 2025

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume15993 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349
NameARES: International Conference on Availability, Reliability and Security
PublisherSpringer
Volume2025

Conference

Conference20th International Conference on Availability, Reliability and Security, ARES 2025
Country/TerritoryBelgium
CityGhent
Period11/08/2514/08/25

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.

Fingerprint

Dive into the research topics of 'Large Language Models Are Unreliable for Cyber Threat Intelligence'. Together they form a unique fingerprint.

Cite this