Skip to content
Enrique Tomás Martínez Beltrán
HomeResearchPublicationsTopicsTeachingBlog
Contact
EN/ES
HomeResearchPublicationsTopicsTeachingBlogContact
EN/ES

Enrique Tomás Martínez Beltrán

Postdoctoral research in AI, cybersecurity and federated learning, spanning threat analysis, closed-loop cyberdefense and trustworthy decentralized learning.

  • Privacy Policy
  • Terms of Service
  • Accessibility Statement
  • Google Scholaropens in a new tab
  • ORCIDopens in a new tab
  • LinkedInopens in a new tab
  • GitHubopens in a new tab
All profiles
  • ResearchGateopens in a new tab
  • Scopusopens in a new tab
  • DBLPopens in a new tab
  • Web of Scienceopens in a new tab

Enrique Tomás Martínez Beltrán. All rights reserved.

Back to top

This site loads optional analytics from Google and external analytics providers only if you accept. You can decline and continue using the site normally.

  1. Home
  2. LLMs for Cyberdefense Support
Research topic

LLMs for Cyberdefense Support

Use of LLMs as a support layer for attack explanation, mitigation recommendation and human-in-the-loop incident analysis.

LLMsCyberdefenseHuman-in-the-loopAttack Explanation

LLMs as an analyst support layer

LLMs can help translate low-level security signals into explanations, response options and investigation hypotheses. In cyberdefense, the useful role is not autonomous decision-making, but bounded support that improves analyst understanding and response speed.

  • Explain attack context in language operators can inspect and challenge.
  • Map evidence to candidate mitigations without hiding uncertainty.
  • Keep humans responsible for final operational decisions.

Reliability constraints

Security use cases require stronger controls than general-purpose assistants. Outputs need provenance, grounding in observed evidence, traceable recommendations and safeguards against hallucinated mitigations or overconfident explanations.

Connection with trustworthy AI

LLM-assisted cyberdefense overlaps with explainability, evaluation, human factors and accountable AI. The research question is how to make these systems useful without increasing operational risk.

On this page

LLMs as an analyst support layerReliability constraintsConnection with trustworthy AIFrequently asked questions

Frequently asked questions

Should LLMs automatically mitigate cyberattacks?

In high-impact settings, LLMs are better positioned as advisory systems. They can explain and suggest, while humans and controlled playbooks approve actions.

What is the main risk of LLMs in cyberdefense?

The main risk is producing plausible but unsupported explanations or mitigations. Grounding, evaluation and human review are essential.

Where can LLMs help security analysts most?

They are useful for summarizing evidence, explaining alerts, comparing response options and documenting incident reasoning.

Related projects

DEFENDIS: Decentralized Federated Learning for IoT Device Identification and Security

DEFENDIS develops a framework for uniquely identifying IoT devices in a distributed manner while solving security threats through decentralized federated learning.

View Project

EU-GUARDIAN: European Framework and Proofs-of-concept for the Intelligent Automation of Cyber Defence Incident Management

A European research project on methods and proofs of concept for supporting cyber defence incident management.

View Project

ROBUST-6G: Smart, Automated and Reliable Security Service Platform for 6G

ROBUST-6G studies security mechanisms for 6G systems, including monitoring, secure data management, trustworthy AI services, federated learning, and threat response.

View Project

CyberBrain: Cybersecurity in BCI for Advanced Driver Assistance

A cybersecurity framework for Brain-Computer Interface systems in advanced driver assistance scenarios, focused on detecting and preventing attacks across the BCI lifecycle.

View Project

Related notes

Large Language Models for Cybersecurity: A Careful Starting Point

A practical map of LLM roles in cyberdefense, from threat-intelligence support to alert triage and explanation, with explicit limits and controls.

Large Language ModelsLLMsCybersecurity
Read More

Autonomous Cyberdefense Needs More Than an LLM

How to frame autonomous cyberdefense as a bounded control loop with evidence, policies, recovery paths and accountable human intervention.

Autonomous CyberdefenseLLMsCybersecurity
Read More

LLM-Supported Attack Mitigation Without Unsafe Autopilot

A design pattern for using language models to explain incidents and compare mitigation options while approved policies retain control of execution.

Attack MitigationLLMsAutonomous Cyberdefense
Read More

Retrieval-Augmented Generation for Cybersecurity Workflows

A grounded introduction to RAG for threat intelligence, incident analysis and cyberdefense, including retrieval quality, provenance and failure modes.

RAGRetrieval-Augmented GenerationLLMs
Read More

GraphRAG for Cyber Threat Intelligence

How graph-based retrieval can connect actors, techniques, assets and incidents while preserving a traceable path to source evidence.

GraphRAGRAGThreat Intelligence
Read More