An off-the-shelf LLM prompted on tokenized Modbus traffic from public ICS datasets matches supervised baselines in normal-versus-critical classification accuracy while generating token-grounded audit records without any model updates.
Alani, Amine Bermak, and Issa Khalil
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2026 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Large Language Models as Explainable Cyberattack Detectors for Energy Industrial Control Systems
An off-the-shelf LLM prompted on tokenized Modbus traffic from public ICS datasets matches supervised baselines in normal-versus-critical classification accuracy while generating token-grounded audit records without any model updates.