Open Access iconOpen Access

ARTICLE

A Large Language Model-Driven Autonomous Framework for Intelligent Cyber Threat Detection and Response

Tahani Alsubait*

Department of Computer Science and Artificial Intelligence, College of Computing, Umm Al-Qura University, Makkah, Saudi Arabia

* Corresponding Author: Tahani Alsubait. Email: email

(This article belongs to the Special Issue: Intelligent Anomaly Detection Solutions for Advanced Environments)

Computers, Materials & Continua 2026, 89(1), 34 https://doi.org/10.32604/cmc.2026.083550

Abstract

The recent sophistication of contemporary cyber threats, such as advanced persistent threats (APTs), zero-day exploits, and polymorphic malware, has revealed serious limitations of traditional rule-based and shallow machine learning detection systems. This paper introduces a new self-managed cyber threat detection and response model, CyberSentinel-LLM, that leverages a fine-tuned large language model (LLM) and a multi-agent reinforcement learning system. The framework employs a LoRA-adapted LLaMA-3-8B backbone (fine-tuned on domain-specific cybersecurity log data using Low-Rank Adaptation with rank r = 16) for contextual log analysis, semantic threat classification, and automated incident response through four specialised agents: Detection, Classification, Response, and Forensic. A temporal transformer encoder reads long-range sequential dependencies in system logs and network traffic, and a deep reinforcement learning (DRL) component allows coordination of adaptive responses. Extensive experiments on two publicly available benchmark datasets, namely, HDFS and BGL of the LogHub repository, show that CyberSentinel-LLM has a high accuracy (96.8), F1-score (96.5), and AUC-ROC (98.7) on HDFS, and high accuracy (95.5) and F1-score (95.2) on BGL, outperforming ten state-of-the-art baselines. Ablation experiments demonstrate the significance of each building element, whereas latency analysis shows real-time inference at 45 ms per log sequence. The framework sets a new paradigm of intelligent cybersecurity operations driven by large language models (LLMs).

Keywords

Large language models; cyber threat detection; autonomous security; log anomaly detection; multi-agent system; deep reinforcement learning; intelligent cybersecurity

Cite This Article

APA Style
Alsubait, T. (2026). A Large Language Model-Driven Autonomous Framework for Intelligent Cyber Threat Detection and Response. Computers, Materials & Continua, 89(1), 34. https://doi.org/10.32604/cmc.2026.083550
Vancouver Style
Alsubait T. A Large Language Model-Driven Autonomous Framework for Intelligent Cyber Threat Detection and Response. Comput Mater Contin. 2026;89(1):34. https://doi.org/10.32604/cmc.2026.083550
IEEE Style
T. Alsubait, “A Large Language Model-Driven Autonomous Framework for Intelligent Cyber Threat Detection and Response,” Comput. Mater. Contin., vol. 89, no. 1, pp. 34, 2026. https://doi.org/10.32604/cmc.2026.083550



cc Copyright © 2026 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 218

    View

  • 56

    Download

  • 0

    Like

Share Link