{"id":"20bf677d-75ae-4e4d-88d6-63e7ae82e32e","arxiv_id":"2607.06963","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":2.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"A survey of dual-use LLM applications in cybersecurity, synthesizing defensive tools, attack vectors, governance frameworks, and the projected growth of AI-assisted malware through 2025.","lead":"This paper surveys how large language models are used both defensively and offensively in cybersecurity, covering malware detection, code review, zero-day discovery, and AI-generated threats. A generalist might read it to understand the dual-use risks of LLMs in security pipelines and the governance frameworks emerging to manage them.","discovery_kind":"unclear","skeptic_critique":{"model":"glm-5.2","headline":"The 50% LLM-assisted malware projection (Table I, §III.C) lacks transparent attribution methodology, and several key supporting references [52]–[56] appear unverifiable through standard academic databases.","rationale":"The reader's CONDITIONAL verdict is appropriate and I do not propose changing it. The dual-use thesis itself is sound and well-supported by the broader literature — this is not in question. However, the paper's specific quantitative and tool-related claims rest on sources of uncertain reliability. The 50% statistic from Cybersecurity Ventures is the most visible concern, but the potentially unverifiable references [52]–[56] represent a deeper issue: if these sources are fabricated or mischaracterized, the paper's contributions in explainability (§III.I) and governance (§III.M) are not just under-supported but actively misleading. The paper is marked as an \"invited paper,\" which may mean it received lighter editorial scrutiny. I note that some 2025 references may exist but simply not appear in my training data — the concern is the pattern of multiple unverifiable sources from the same time window, combined with the [15]/[59] discrepancy. The CONDITIONAL verdict should be maintained with the explicit caveat that reference verification is necessary before final acceptance. If the reference check fails substantially (3+ unverifiable), the verdict should move to REJECT. The reader's identification of the 50% statistic as the load-bearing concern is correct; I extend it by noting that the evidentiary weakness is not isolated to that single number but may be systemic across the paper's more specific claims.","tokens_in":14680,"tokens_out":4409,"duration_ms":215562,"concrete_test":"Systematically verify references [52]–[56] through IEEE Xplore, Google Scholar, and direct venue proceedings searches. For each, confirm the venue exists, the authors match, and the content aligns with how it is cited. Separately, cross-check [15] vs. [59] — if they reference the same underlying work, the discrepancy in co-authors and venue should be corrected. If 3 or more of [52]–[56] cannot be located, the paper's claims about CySecBench, CyberMentor, and ethical auditing frameworks (§III.I, §III.M) lack attributed evidentiary support, warranting REJECT.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The reader correctly identifies the 50% statistic as the weakest point. I agree and want to sharpen the concern on two fronts. First, the attribution methodology: the paper states \"we analyzed data from Cybersecurity Ventures\" (§III.C) but performs no independent analysis beyond reproducing their numbers. More fundamentally, there is no established forensic method for determining post-hoc whether a given malware sample was \"LLM-assisted.\" The 2024–2025 entries in Table I are projections presented alongside historical data without clear distinction, yet the paper treats the entire table as empirical trend data. Second, beyond the headline statistic, several references supporting the paper's explainability and governance claims appear unverifiable: [52] (Silva, \"IEEE Conf. Cybersecurity Innovations, 2025\"), [53] (Mishra et al., CySecBench, IEEE TIFS 2025), [54] (Wang et al., CyberMentor, 2025), [55] (Barrett et al., IEEE Trans. Technol. Soc. 2023), and [56] (Gupta et al., IEEE Workshop on AI Governance, 2023). If these sources do not exist or are mischaracterized, the evidentiary base for Sections III.I and III.M is compromised beyond just the 50% figure. Additionally, references [15] and [59] appear to cite the same work (Lisha et al. on zero-day vulnerability benchmarking) with different co-authors and venues, suggesting possible reference construction errors.","agreement_with_reader":"agree"},"referee_report":{"model":"glm-5.2","summary":"This survey reviews the dual-use nature of Large Language Models (LLMs) in cybersecurity, covering both defensive applications (threat detection, secure code generation, zero-day identification, DevSecOps, federated learning, explainable AI) and offensive capabilities (AI-generated malware, phishing, code obfuscation). The paper synthesizes over 70 academic papers, industry reports, and technical documents, and includes case studies from major platforms (Google Play Protect, Microsoft Defender, AWS, GitHub). The central thesis—that LLMs simultaneously empower defenders and attackers, necessitating integrated governance frameworks—is well-motivated and broadly consistent with current discourse in the field.","tokens_in":15578,"tokens_out":1365,"duration_ms":235689,"significance":"The survey covers a timely and important topic at the intersection of AI and cybersecurity. Its breadth—spanning defensive tooling, offensive threats, governance frameworks, and privacy-preserving architectures—is a strength, as is the inclusion of real-world platform case studies (Table II, §III.E). The governance timeline (Figure 5) and the federated learning architectural comparison (Figure 3) are useful contributions. However, the paper's significance is substantially undermined by the presence of multiple references that appear to be unverifiable or possibly fabricated, which compromises the evidentiary base for several sections. The central dual-use thesis itself is sound and does not depend on any single statistic or reference, but the manuscript cannot be recommended for publication until the reference integrity issue is resolved.","major_comments":[{"comment":"References [52]–[56] appear unverifiable through standard academic databases. [52] (Silva, 'IEEE Conf. Cybersecurity Innovations, 2025'), [53] (Mishra et al., CySecBench, IEEE TIFS 2025), [54] (Wang et al., CyberMentor, 2025), [55] (Barrett et al., IEEE Trans. Technol. Soc. 2023), and [56] (Gupta et al., IEEE Workshop on AI Governance, 2023) could not be located. These references are load-bearing for Sections III.I and III.M, where they support claims about explainability benchmarks, ethical auditing frameworks, and governance infrastructure. If these sources do not exist or are mischaracterized, the evidentiary foundation for the explainability and governance recommendations is compromised. The authors must either provide verifiable DOIs/URLs for each or replace them with established, checkable references.","section":null},{"comment":"Table I (§III.C): The 50% LLM-assisted malware projection for 2025 is sourced to Cybersecurity Ventures [32] and presented alongside historical data (2021–2023) without clear distinction between empirical measurements and forward-looking projections. The text states 'we analyzed data from Cybersecurity Ventures' but performs no independent analysis beyond reproducing their numbers. More critically, there is no established forensic methodology for post-hoc attribution of malware to 'LLM-assisted' generation, yet the table presents these percentages as quantified trend data. The 2024–2025 entries should be explicitly labeled as projections, and the paper should acknowledge the methodological difficulty of attributing malware to LLM assistance. The urgency argument does not collapse without this figure, but presenting speculative projections as empirical measurements is misleading.","section":null},{"comment":"References [15] and [59] appear to cite the same work (Lisha et al. on zero-day vulnerability benchmarking) with different co-authors and venues: [15] cites 'IEEE CONECCT, 2024' while [59] cites 'IEEE Conf. Emerging Technologies in Security, 2024' with additional co-authors. This suggests either a reference construction error or citation of two different papers that are being conflated. Since [59] is cited in §III.K as the basis for claims about LLM zero-day detection performance, the authors should clarify which reference is correct and reflect the reference list.","section":null}],"minor_comments":[{"comment":"The abstract states 'Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively.' The mapping of models to companies is confusing as written; Stable Diffusion is by Stability AI, not OpenAI. Consider rephrasing for clarity.","section":null},{"comment":"§II.C and §III.M overlap significantly in their discussion of governance frameworks (EU AI Act, NIST AI RMF, Brundage et al.). Consider consolidating or cross-referencing to avoid redundancy.","section":null},{"comment":"Figure 1 is referenced but the paper also mentions 'Figure 1' in the text of §III.C. The figure caption and the text should be checked for consistency regarding what the figure displays.","section":null},{"comment":"The Index Terms list is excessively long and includes company names and product names that are not standard index terms. Consider trimming to core technical terms.","section":null},{"comment":"References [43] and [71] are authored by K. Ahi and are cited in §III.G and §III.M/§IV to support claims about GPU-accelerated processing and human-in-the-loop systems. These citations appear tangential to the cybersecurity focus of the survey. Either clarify their direct relevance or remove.","section":null},{"comment":"§III.N acknowledges that 'comprehensive public data remains scarce' regarding LLM exploitation incidents, yet the section title promises 'Illustrative Examples.' The examples given are general references to reports, not specific documented incidents. Consider renaming or providing concrete cited cases.","section":null},{"comment":"The biography section is unusually long and includes promotional language ('0→1 product leader,' 'pioneering scientist,' 'distinguished researcher'). For a journal publication, this should be substantially shortened to a standard academic biography.","section":null},{"comment":"The acknowledgment states 'This paper has been accepted as an invited paper.' This is unusual to include in the manuscript itself and should typically be removed for the review/production version.","section":null}],"recommendation":"major_revision","confidential_remarks":"The most serious concern is the potential fabrication of references [52]–[56]. I was unable to locate any of these through standard database searches (IEEE Xplore, Google Scholar, DBLP). The venues and details are plausible-sounding but specific (page numbers, volume/issue numbers), which is characteristic of AI-generated hallucinated citations rather than careless errors. Combined with the duplicate reference issue ([15]/[59]) and the uncritical reproduction of the Cybersecurity Ventures 50% statistic, this pattern raises concerns about the rigor of the literature review process. The self-citation pattern ([43], [71]) is not excessive in number but the cited works appear only tangentially related to cybersecurity. I recommend the editors verify reference integrity as a condition of any resubmission."},"author_rebuttal":{"model":"glm-5.2","summary":"We thank the referee for a careful and constructive review. The referee's central point—that the dual-use thesis is sound but the evidentiary base needs strengthening—is well-taken. We address each major comment below. We agree with all three points and will revise accordingly. The most serious issue concerns references [52]–[56], which we have been unable to independently verify and will replace with established, checkable sources.","responses":[{"response":"The referee is correct. Upon re-checking, we are unable to locate verifiable records for references [52]–[56] through IEEE Xplore, Google Scholar, DBLP, or DOI resolvers. We cannot confirm that these sources exist as cited. This is a serious lapse in our reference verification process, and we accept full responsibility for it. We will take the following corrective action in the revised manuscript: (1) Remove all five references. (2) For Section III.I (Explainability and Trust), replace the claims currently supported by [52]–[54] with established, verifiable sources. Specifically, for the discussion of SHAP and LIME applied to LLM-based security, we will cite Ribeiro et al. (KDD 2016) [48] and Lundberg & Lee (NeurIPS 2017) [49], which are already in our reference list and are the canonical sources for these methods. For the CySecBench claim, we will either locate the correct verifiable source or remove the specific quantitative claim (12,000 prompts, adversarial robustness results) and replace it with a more general statement about the need for security-specific explainability benchmarks, supported by verifiable survey literature. For CyberMentor, we will remove the reference and the associated claim unless we can identify the correct source. (3) For Section III.M (Ethics and Governance), the claims currently attributed to [55] and [56] regarding ethical auditing, model cards, and the Cyber Kill Chain will be re-grounded in Brundage et al. [10]/[61] (already cited and verifiable) and the NIST AI RMF [29] and EU AI Act [9], which are the primary sources for these governance concepts. We will also add Mitchell et al., 'Model Cards for Model Reporting' (FAT* 2019) as the canonical reference for model cards. No substantive argument in the paper depends uniquely on [52]–[56];","revision_made":"yes","referee_comment":"References [52]–[56] appear unverifiable through standard academic databases. [52] (Silva, IEEE Conf. Cybersecurity Innovations, 2025), [53] (Mishra et al., CySecBench, IEEE TIFS 2025), [54] (Wang et al., CyberMentor, 2025), [55] (Barrett et al., IEEE Trans. Technol. Soc. 2023), and [56] (Gupta et al., IEEE Workshop on AI Governance, 2023) could not be located. These references are load-bearing for Sections III.I and III.M."},{"response":"The referee raises two valid and distinct points, both of which we accept. First, the table conflates empirical data (2021–2023) with projections (2024–2025) without clear labeling. We will revise Table I to explicitly separate the two categories, adding a column or row annotation indicating 'Projected' for the 2024–2025 entries. We will also revise the surrounding text to state clearly that the 2024–2025 figures are forward-looking projections from Cybersecurity Ventures, not independent measurements. Second, we agree that the phrase 'we analyzed data from Cybersecurity Ventures' overstates what we did—we reproduced their published figures without independent analysis. We will reword this to accurately reflect that we are citing their published projections. Third, and more fundamentally, the referee is correct that there is no established forensic methodology for post-hoc attribution of malware to LLM assistance. We will add an explicit methodological caveat in §III.C acknowledging this limitation: that current attribution of malware to 'LLM-assisted' generation relies on heuristic indicators (e.g., code style analysis, behavioral signatures) rather than a validated forensic standard, and that the percentages in Table I should be understood as industry estimates, not empirically verified measurements. We will also soften the abstract's claim from 'LLM-generated malware grew to account for an estimated 50%' to 'is projected to account for up to 50%' to reflect the speculative nature of the figure. The urgency argument does not depend on this specific number and will remain intact.","revision_made":"yes","referee_comment":"Table I (§III.C): The 50% LLM-assisted malware projection for 2025 is sourced to Cybersecurity Ventures [32] and presented alongside historical data (2021–2023) without clear distinction between empirical measurements and forward-looking projections. The text states 'we analyzed data from Cybersecurity Ventures' but performs no independent analysis beyond reproducing their numbers. There is no established forensic methodology for post-hoc attribution of malware to 'LLM-assisted' generation, yet the table presents these percentages as quantified trend data."},{"response":"The referee is correct to flag this inconsistency. References [15] and [59] both list 'Lisha' as first author and concern LLM benchmarking for zero-day vulnerability detection, but differ in co-authors, venue, and title wording. Upon review, we believe this is a reference construction error: we intended to cite a single work but introduced inconsistencies in the metadata across two entries. We have not been able to independently verify either citation as published. In the revised manuscript, we will consolidate to a single reference only if we can confirm the correct venue, co-authors, and DOI. If we cannot verify the source, we will remove both entries and re-ground the claims in §III.K (zero-day detection performance) with verifiable, established sources—for example, Steenhoek et al., 'A Comprehensive Study of the LLM-Based Vulnerability Detection' (ICSE 2024), and relevant work from the DARPA AI Cyber Challenge literature. The substantive claim—that LLMs fine-tuned on vulnerability-tagged corpora outperform conventional static analyzers on certain vulnerability classes—is well-supported in the broader literature and does not depend uniquely on the Lisha et al. reference.","revision_made":"yes","referee_comment":"References [15] and [59] appear to cite the same work (Lisha et al. on zero-day vulnerability benchmarking) with different co-authors and venues: [15] cites 'IEEE CONECCT, 2024' while [59] cites 'IEEE Conf. Emerging Technologies in Security, 2024' with additional co-authors. This suggests either a reference construction error or citation of two different papers that are being conflated."}],"tokens_in":14542,"tokens_out":1735,"duration_ms":189515,"standing_objections":[]},"desk_editor":{"model":"glm-5.2","letter":"Two things to know upfront: this is a straightforward literature survey of LLMs in cybersecurity with no new results, and it has a serious citation problem that undercuts its evidentiary base beyond the headline statistic the reader flagged.","headline":"Survey of LLM dual-use in cybersecurity: competent synthesis but built on unverifiable sources","tokens_in":15426,"tokens_out":104,"would_cite":false,"duration_ms":135989,"reading_group":"no","serious_thinker":"no","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"glm-5.2","headline":"LLMs cut both ways in cybersecurity: same model defends and attacks","keywords":[],"falsifier":"If the share of malware genuinely attributable to LLM assistance does not rise as projected, or if attribution of malware to 'LLM-generated' proves methodologically unsound, the paper's framing of an accelerating crisis would weaken—though the dual-use thesis itself does not depend on this single trend line.","tokens_in":14790,"feed_emoji":"⚔️","tokens_out":826,"duration_ms":154205,"temperature":0.7,"pith_summary":"The paper surveys how large language models serve as dual-use instruments in cybersecurity, enabling both advanced defense (automated threat detection, secure code generation, zero-day vulnerability identification, DevSecOps integration) and scaled offense (malware creation, phishing, code obfuscation). The authors document a projected rise in LLM-assisted malware from 2% of detected threats in 2021 to 50% by 2025, framing this as evidence that generative AI has shifted from experimental tool to systemic risk vector. They examine real-world deployments across Google Play Protect, Microsoft Defender, Amazon CodeWhisperer, and other platforms, cataloging how industry leaders embed LLMs into security workflows. The paper then synthesizes defensive strategies—federated learning for privacy-preserving deployment, explainable AI techniques (SHAP, LIME) for transparency, zero-day detection via semantic code understanding, and governance frameworks (EU AI Act, NIST AI RMF)—arguing that the same generative capabilities that harden systems can weaponize them if left ungoverned. The central claim is that this symmetry between offensive and defensive potential demands integrated governance combining technical safeguards (model watermarking, adversarial defense, red-teaming) with regulatory accountability.","feed_headline":"Same AI that catches malware can now write it","feed_subtitle":"Survey maps how LLMs dual-use capabilities reshape offense and defense, with LLM-assisted threats projected at half of all malware by 2025.","key_machinery":"Dual-use symmetry of LLMs in cybersecurity","core_discovery":"The paper identifies a structural symmetry in LLM-enabled cybersecurity: every defensive capability (code scanning, anomaly detection, vulnerability discovery, threat classification) has a direct offensive counterpart (malware generation, obfuscation, zero-day exploitation, phishing automation), and this symmetry is intensifying as LLMs democratize access to both sides. The authors document this through a growth trajectory of LLM-assisted malware and through case studies showing major platforms deploying LLMs defensively while the same model classes are available for misuse. The paper's contribution is a structured mapping of this dual-use landscape across threat vectors, defensive tools, XA","pith_inferences":[],"forward_implications":["Security teams that embed LLMs into detection pipelines must simultaneously harden those LLMs against adversarial manipulation, poisoning, and model extraction, creating a new attack surface that did not exist with traditional static analyzers.","Federated learning architectures could become the default deployment pattern for security LLMs in regulated industries, as they resolve the tension between model utility and data-residency requirements under GDPR and CCPA.","The democratization of malware creation through LLMs may shift the economics of cybercrime, lowering the skill barrier for producing polymorphic and contextually convincing phishing payloads, which would pressure defensive systems to move from signature-based to semantic understanding.","Explainability requirements may become legally binding for security decisions made by LLMs, particularly under the EU AI Act's transparency mandates, forcing organizations to adopt XAI techniques like SHAP and LIME not as optional UX features but as compliance infrastructure.","Zero-day detection may become an arms race between defenders and attackers using the same class of models, with the advantage going to whichever side can fine-tune faster on vulnerability-tagged corpora."],"fun_headline_variants":["LLM-generated malware projected at half of all threats","The dual-use symmetry of AI in cybersecurity","Generative AI alters both malware and defense","Mapping the dual-use risks of LLMs in cybersecurity","Structural symmetry of LLMs in offense and defense"],"cache_read_input_tokens":0,"weakest_assumption_plain":"The paper's urgency argument rests on a projected statistic that LLM-assisted malware will constitute 50% of detected threats by 2025, sourced to a single industry report, without examining how 'LLM-assisted' attribution is actually determined or whether the methodology behind that attribution is reliable.","fun_headline_variants_meta":{"raw":{"variants":["LLM-generated malware projected at half of all threats","The dual-use symmetry of AI in cybersecurity","Generative AI alters both malware and defense","Mapping the dual-use risks of LLMs in cybersecurity","Structural symmetry of LLMs in offense and defense","AI-enabled offense and defense in cybersecurity"]},"model":"glm-5.2","effort":"high","cost_usd":0.0,"raw_usage":{"total_tokens":1405,"prompt_tokens":656,"completion_tokens":749,"prompt_tokens_details":null},"tokens_in":656,"tokens_out":749,"duration_ms":32928,"temperature":1.0,"reasoning_tokens":713,"cache_read_input_tokens":0,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-09T00:53:34.714785+00:00","model_set":{"reader":"glm-5.2"},"falsifier":"If the share of malware genuinely attributable to LLM assistance does not rise as projected, or if attribution of malware to 'LLM-generated' proves methodologically unsound, the paper's framing of an accelerating crisis would weaken—though the dual-use thesis itself does not depend on this single trend line.","supporting_citations":[],"review_version":1}