Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.083550
Special Issues
Table of Content

Open Access

ARTICLE

A Large Language Model-Driven Autonomous Framework for Intelligent Cyber Threat Detection and Response

Tahani Alsubait*
Department of Computer Science and Artificial Intelligence, College of Computing, Umm Al-Qura University, Makkah, Saudi Arabia
* Corresponding Author: Tahani Alsubait. Email: email
(This article belongs to the Special Issue: Intelligent Anomaly Detection Solutions for Advanced Environments)

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.083550

Received 06 April 2026; Accepted 24 June 2026; Published online 16 July 2026

Abstract

The recent sophistication of contemporary cyber threats, such as advanced persistent threats (APTs), zero-day exploits, and polymorphic malware, has revealed serious limitations of traditional rule-based and shallow machine learning detection systems. This paper introduces a new self-managed cyber threat detection and response model, CyberSentinel-LLM, that leverages a fine-tuned large language model (LLM) and a multi-agent reinforcement learning system. The framework employs a LoRA-adapted LLaMA-3-8B backbone (fine-tuned on domain-specific cybersecurity log data using Low-Rank Adaptation with rank r = 16) for contextual log analysis, semantic threat classification, and automated incident response through four specialised agents: Detection, Classification, Response, and Forensic. A temporal transformer encoder reads long-range sequential dependencies in system logs and network traffic, and a deep reinforcement learning (DRL) component allows coordination of adaptive responses. Extensive experiments on two publicly available benchmark datasets, namely, HDFS and BGL of the LogHub repository, show that CyberSentinel-LLM has a high accuracy (96.8), F1-score (96.5), and AUC-ROC (98.7) on HDFS, and high accuracy (95.5) and F1-score (95.2) on BGL, outperforming ten state-of-the-art baselines. Ablation experiments demonstrate the significance of each building element, whereas latency analysis shows real-time inference at 45 ms per log sequence. The framework sets a new paradigm of intelligent cybersecurity operations driven by large language models (LLMs).

Keywords

Large language models; cyber threat detection; autonomous security; log anomaly detection; multi-agent system; deep reinforcement learning; intelligent cybersecurity
  • 50

    View

  • 11

    Download

  • 0

    Like

Share Link