Large Language Models Are Unreliable for Cyber Threat Intelligence

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mezzi, Emanuele, Massacci, Fabio, Tuma, Katja
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917074613305344
author Mezzi, Emanuele
Massacci, Fabio
Tuma, Katja
author_facet Mezzi, Emanuele
Massacci, Fabio
Tuma, Katja
contents Several recent works have argued that Large Language Models (LLMs) can be used to tame the data deluge in the cybersecurity field, by improving the automation of Cyber Threat Intelligence (CTI) tasks. This work presents an evaluation methodology that other than allowing to test LLMs on CTI tasks when using zero-shot learning, few-shot learning and fine-tuning, also allows to quantify their consistency and their confidence level. We run experiments with three state-of-the-art LLMs and a dataset of 350 threat intelligence reports and present new evidence of potential security risks in relying on LLMs for CTI. We show how LLMs cannot guarantee sufficient performance on real-size reports while also being inconsistent and overconfident. Few-shot learning and fine-tuning only partially improve the results, thus posing doubts about the possibility of using LLMs for CTI scenarios, where labelled datasets are lacking and where confidence is a fundamental factor.
format Preprint
id arxiv_https___arxiv_org_abs_2503_23175
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Large Language Models Are Unreliable for Cyber Threat Intelligence
Mezzi, Emanuele
Massacci, Fabio
Tuma, Katja
Cryptography and Security
Artificial Intelligence
Machine Learning
Several recent works have argued that Large Language Models (LLMs) can be used to tame the data deluge in the cybersecurity field, by improving the automation of Cyber Threat Intelligence (CTI) tasks. This work presents an evaluation methodology that other than allowing to test LLMs on CTI tasks when using zero-shot learning, few-shot learning and fine-tuning, also allows to quantify their consistency and their confidence level. We run experiments with three state-of-the-art LLMs and a dataset of 350 threat intelligence reports and present new evidence of potential security risks in relying on LLMs for CTI. We show how LLMs cannot guarantee sufficient performance on real-size reports while also being inconsistent and overconfident. Few-shot learning and fine-tuning only partially improve the results, thus posing doubts about the possibility of using LLMs for CTI scenarios, where labelled datasets are lacking and where confidence is a fundamental factor.
title Large Language Models Are Unreliable for Cyber Threat Intelligence
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2503.23175