Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Leveraging Large Language Models for Cybersecurity Risk Assessment - A Case from Forestry Cyber-Physical Systems
Chalmers University of Technology, University of Gothenburg, Gothenburg, Sweden.
Chalmers University of Technology, University of Gothenburg, Gothenburg, Sweden.
Chalmers University of Technology, University of Gothenburg, Gothenburg, Sweden.
Chalmers University of Technology, University of Gothenburg, Gothenburg, Sweden, Chalmers University of Technology, University of Gothenburg, Carnegie Mellon University Gothenburg, Pittsburgh, United States.
Show others and affiliations
2025 (English)In: Proceedings - 2025 40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025, Institute of Electrical and Electronics Engineers (IEEE) , 2025, p. 58-65Conference paper, Published paper (Refereed)
Abstract [en]

In safety-critical software systems, cybersecurity activities become essential, with risk assessment being one of the most critical. In many software teams, cybersecurity experts are either entirely absent or represented by only a small number of specialists. As a result, the workload for these experts becomes high, and software engineers would need to conduct cybersecurity activities themselves. This creates a need for a tool to support cybersecurity experts and engineers in evaluating vulnerabilities and threats during the risk assessment process. This paper explores the potential of leveraging locally hosted large language models (LLMs) with retrieval-augmented generation to support cybersecurity risk assessment in the forestry domain while complying with data protection and privacy requirements that limit external data sharing. We performed a design science study involving 12 experts in interviews, interactive sessions, and a survey within a large-scale project. The results demonstrate that LLMs can assist cybersecurity experts by generating initial risk assessments, identifying threats, and providing redundancy checks. The results also highlight the necessity for human oversight to ensure accuracy and compliance. Despite trust concerns, experts were willing to utilize LLMs in specific evaluation and assistance roles, rather than solely relying on their generative capabilities. This study provides insights that encourage the use of LLMbased agents to support the risk assessment process of cyber-physical systems in safety-critical domains

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE) , 2025. p. 58-65
Keywords [en]
Cyber-Physical Systems, Cybersecurity, Large Language Models, Risk Assessment
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:ri:diva-81340DOI: 10.1109/ASEW67777.2025.00021Scopus ID: 2-s2.0-105033704800OAI: oai:DiVA.org:ri-81340DiVA, id: diva2:2053332
Conference
40th IEEE/ACM International Conference on Automated Software Engineering Workshops, ASEW 2025
Available from: 2026-04-16 Created: 2026-04-16 Last updated: 2026-04-16Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Damschen, MarvinMohamad, Mazen

Search in DiVA

By author/editor
Damschen, MarvinMohamad, Mazen
By organisation
Electrification and Reliability
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 14 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf