Autonome Cyberabwehr/Autonomous cyber defence – Methodology for risk-based autonomous cyber defence with LLM and RAG
Table of contents
Bibliographic information

Open Access Full access
wt Werkstattstechnik online
Volume 115 (2025), Issue 09
- Authors:
- | | | | | | | | | | | | | | | | | | | | | | | | | | | | | |
- Publisher
- VDI fachmedien, Düsseldorf
- Copyright Year
- 2025
- ISSN-Online
- 1436-4980
- ISSN-Print
- 1436-4980
Chapter information
Open Access Full access
Volume 115 (2025), Issue 09
Autonome Cyberabwehr/Autonomous cyber defence – Methodology for risk-based autonomous cyber defence with LLM and RAG
- Authors:
- |
- ISSN-Print
- 1436-4980
- ISSN-Online
- 1436-4980
- Preview:
This article presents a methodology for autonomous cyber defence in Industry 4.0 environments, linking organisational risk management with generative AI. Combining LLMs, RAG, and standardised SOPs creates, a structured decision-making process that enables real-time response and traceable mitigation. Conceptual foundations, technical implications, and practical potential are discussed. A prototype implementation was evaluated separately.
Bibliography
No match found. Try another term.
- [1] Degen, F.: Lithium-ion battery cell production in Europe: Scenarios for reducing energy consumption and greenhouse gas emissions until 2030. Journal of Industrial Ecology (2023) 3, pp. 964–976 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [2] Stock, D.; Bauernhansl, T.; Weyrich, M. et al.: System Architectures for Cyber-Physical Production Systems enabling Self-X and Autonomy. IEEE International Conference on Emerging Technologies and Factory Automation (ETFA) 2020 (2020), pp. 148–155 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [3] Bitkom: Financial damage from cybercrime in Germany in 2024 (in billion euros). Internet: www.statista.com/statistics/1360289/financial-damage-cyber-crimes-germany/. Zugriff am 12.08.2025 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [4] Beerman, J.; Berent, D.; Falter, Z. et al.: A Review of Colonial Pipeline Ransomware Attack. International Symposium on Cluster, Cloud and Internet Computing Workshops (CCGridW) 2023 (2023) 23, pp. 8–15 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [5] Kushner, D.: The Real Story of Stuxnet. IEEE Spectrum (2013) 50, pp. 48–53 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [6] Adamov, A.; Carlsson, A.; Surmacz, T.: An Analysis of LockerGoga Ransomware. IEEE East-West Design & Test Symposium (EWDTS) (2019), pp. 1–5 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [7] Mekdad, Y.; Bernieri, G.; Conti, M. et al.: A threat model method for ICS malware: the TRISIS case. ACM International Conference on Computing Frontiers (2021), pp. 221–228 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [8] Scarfone, K.; Mell, P.: Guide to Intrusion Detection and Prevention Systems (IDPS). NIST Special Publication 800–94 (2007), doi.org/10.6028/NIST.SP.800–94 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [9] DIN EN ISO/IEC 27001: Informationssicherheit, Cybersicherheit und Datenschutz – Informationssicherheitsmanagementsysteme – Anforderungen (ISO/IEC 27001:2022). Deutsche Fassung EN ISO/IEC 27001:2023, Ausgabe 2024–01 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [10] Dhirani, L.; Armstrong, E.; Newe, T.: Industrial IoT, Cyber Threats, and Standards Landscape: Evaluation and Roadmap. Sensors 2021 (2021) 21, #3901 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [11] European Union Agency for Cyber-Security: ENISA Threat Landscape for Industrial Control Systems 2024. Internet: www.enisa.europa.eu/publications/enisa-threat-landscape-2024 . Zugriff am 12.08.2025 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [12] Cao, C.; Wang, F.; Lindley, L. et al.: Managing Linux servers with LLM-based AI agents: An empirical evaluation with GPT4. Machine Learning with Applications 17 (2024) #100570, doi.org/10.1016/j.mlwa.2024.100570 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [13] Xu, H.; Wang, S.; Li, N. et al.: Large Language Models for Cyber Security: A Systematic Literature Review. arXiv preprint 2405.04760, doi.org/10.48550/arXiv.2405.04760 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [14] Liu, O.; Fu, D.; Yogatama, D. et al.: DeLLMa: Decision Making Under Uncertainty with Large Language Models. arXiv preprint 2024, doi.org/10.48550/arXiv.2402.02392 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [15] Li, S.; Puig, X.; Paxton, C. et al.: Pre-Trained Language Models for Interactive Decision-Making. arXiv preprint 2022, doi.org/10.48550/arXiv.2202.01771 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [16] Gokcimen, T.; Das, B.: A novel system for strengthening security in large language models against hallucination and injection attacks with effective strategies. Alexandria Engineering Journal 123 (2025), pp. 71–90 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [17] Wang, W.; Wang, Y.; Joty, S. et al.: RAP-Gen: Retrieval-Augmented Patch Generation with CodeT5 for Automatic Program Repair. ACM Joint Meeting European Software Engineering Conference and Symposium on the Foundations of Software Engineering (2023) 31, pp. 146–158 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [18] Hou, X.; Zhao, Y.; Wang, S. et al.: Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions. arXiv preprint 2025, doi.org/10.48550/arXiv.2503.23278 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [19] Geyer, M.; Schwab, J.: Risk-Aware Autonomous Defence with Generative AI: Ethical and Accountability Challenges in Cyber-Physical Infrastructures. In: Workshop on AI in Security and Defense (AI4SD) at ECAI 2025, OpenHSU Proceedings, 2025 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [20] Geyer, M.: Autonome IT-/OT-Verteidigung in der Intralogistik. Entwicklung eines resilienten KI-basierten Sicherheitssystems für die vernetzte Batteriezellenproduktion. Masterarbeit, Universität Stuttgart, 2025 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [21] CrowdStrike: The 1/10/60 Minute Challenge: A Framework for Stopping Breaches Faster. Stand: 2025. Internet: https://www.crowdstrike.com/en-us/resources/crowdcasts/the-1–10–60-minute-challenge-a-framework-for-stopping-breaches-faster/. Zugriff am 12.08.2025 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
- [22] Fraunhofer IPA: DigiBattPro 4.0 – BMBF: Digitalisierungslösungen und Materialentwicklung für die Batterieproduktion. Stand: 2025. Internet: www.ipa.fraunhofer.de/de/referenzprojekte/DigiBattPro40-BMBF.html. Zugriff am 12.08.2025 Open Google Scholar DOI: 10.37544/1436-4980-2025-09-21
