

de Recherche et d’Innovation
en Cybersécurité et Société
Elhajjout, A.; Jarir, Z.; Moudoud, H.; Davoust, A.; Houda, Z. A. El
Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks Article d'actes
Dans: Dig Tech Pap IEEE Int Conf Consum Electron, Institute of Electrical and Electronics Engineers Inc., 2026, ISBN: 0747668X (ISSN); 979-833155343-2 (ISBN), (Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron).
Résumé | Liens | BibTeX | Étiquettes: Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation
@inproceedings{elhajjoutLeveragingLargeLanguage2026,
title = {Leveraging Large Language Models for Contextual Threat Hypothesis Generation in IoT Networks},
author = {A. Elhajjout and Z. Jarir and H. Moudoud and A. Davoust and Z. A. El Houda},
url = {https://www.scopus.com/pages/publications/105037351870?origin=resultslist},
doi = {10.1109/ICCE67443.2026.11449914},
isbn = {0747668X (ISSN); 979-833155343-2 (ISBN)},
year = {2026},
date = {2026-01-01},
booktitle = {Dig Tech Pap IEEE Int Conf Consum Electron},
publisher = {Institute of Electrical and Electronics Engineers Inc.},
abstract = {Modern Security Operations Centers face numerous challenges in managing the volume and complexity of security alerts from Internet of Things (IoT) networks. While traditional rule-based systems excel at detection, they provide limited contextual reasoning to help analysts understand ambiguous alerts. Large Language Models (LLMs) have shown promise across various cybersecurity domains. However, their potential to generate rich, explanatory threat hypotheses for ambiguous IoT alerts remains largely unexplored. To address these issues, in this paper, we present a systematic investigation of Large Language Model-based threat hypothesis generation with three key contributions. First, we introduce a context-aware structured prompting framework capable of synthesizing heterogeneous device telemetry into coherent threat narratives. Second, we formalize the assessment of explainability in security through a rigorous multidimensional quality metric system. Third, we provide the first comparative analysis of five state-of-the-art models on real-world IoT incidents, revealing critical performance tradeoffs. Results show that GPT-4o-mini achieves 88.2% accuracy on diverse attack types, while Qwen 3-235B achieves 95.2% accuracy on network-focused attacks. Statistical analysis reveals significant model-dataset interactions. These findings show that properly guided Large Language Models can augment analyst capabilities by providing detailed, contextual explanations that facilitate efficient alert triage. © 2026 IEEE.},
note = {Journal Abbreviation: Dig Tech Pap IEEE Int Conf Consum Electron},
keywords = {Alert Triage, Cybersecurity, Hypotheses generation, Internet of thing security, Internet of things, IoT Security, Language model, Large datasets, Large language model, large language models, Network security, Prompt Engineering, Security alerts, Security operation center, Security Operations, Security systems, Threat Hypothesis Generation},
pubstate = {published},
tppubtype = {inproceedings}
}



