A small-language-model architecture for AI-driven detection, prediction and safe defence of operational technology. Operational technology (OT) and industrial control systems (ICS) increasingly connect information technology, industrial networks, programmable logic controllers (PLCs), SCADA, distributed control systems, robotics and physical processes. This convergence creates a cybersecurity environment in which compromise of a digital asset may propagate into physical consequences. The emergence of tool-using and autonomous large language model (LLM) agents introduces an additional dimension to this threat. Recent research has demonstrated that LLMs can generate attacks against PLC environments, and that autonomous agents can, under appropriate conditions, progress from PLC interaction toward sustained physical objectives. Existing AI cybersecurity approaches predominantly focus on alert classification, anomaly detection, vulnerability identification, malware analysis or natural-language security assistance. These capabilities do not fully address the central OT problem: determining how a cyber event propagates through industrial topology and ultimately affects a physical process. This paper proposes HERMES-OT, a cyber-physical defence architecture based on a hierarchy of compact, specialised language models rather than a single general-purpose LLM, combining industrial telemetry, asset topology, vulnerability intelligence, attack graphs, process-state information, engineering knowledge and digital-twin simulation. The architecture introduces a reasoning chain that runs observe, understand, correlate, predict, simulate, prescribe, validate, learn. Probabilistic reasoning is surrounded by deterministic constraints: a policy engine provides authority, a safety layer provides boundaries, and the human retains control where risk demands it. The central hypothesis is that specialised small language models, coordinated through structured graphs and deterministic safety mechanisms, can provide sufficiently reliable industrial security reasoning while reducing inference latency, computational requirements and exposure of sensitive industrial information. The paper also proposes the OT-HERMES benchmark, a cyber-physical evaluation framework measuring detection, asset reasoning, vulnerability correlation, attack-path prediction, physical-impact prediction, defensive prescription, safety and computational efficiency. The research question is: what is the smallest AI model, or combination of small models, that can reliably reason about cyber-physical risk in an industrial environment? Status: this is a research proposal. No experimental performance figures are claimed for HERMES-OT. The architecture and the eight contributions are proposed and the six hypotheses stated, but not experimentally validated. Implementation and controlled experiments are the next stage of the work, and are essential before the system is presented as empirically validated.
Yasir Musawar· Zenodo (CERN European Organi...· 0 citations
A small-language-model architecture for AI-driven detection, prediction and safe defence of operational technology. Operational technology (OT) and industrial control systems (ICS) increasingly connect information technology, industrial networks, programmable logic controllers (PLCs), SCADA, distributed control systems, robotics and physical processes. This convergence creates a cybersecurity environment in which compromise of a digital asset may propagate into physical consequences. The emergence of tool-using and autonomous large language model (LLM) agents introduces an additional dimension to this threat. Recent research has demonstrated that LLMs can generate attacks against PLC environments, and that autonomous agents can, under appropriate conditions, progress from PLC interaction toward sustained physical objectives. Existing AI cybersecurity approaches predominantly focus on alert classification, anomaly detection, vulnerability identification, malware analysis or natural-language security assistance. These capabilities do not fully address the central OT problem: determining how a cyber event propagates through industrial topology and ultimately affects a physical process. This paper proposes HERMES-OT, a cyber-physical defence architecture based on a hierarchy of compact, specialised language models rather than a single general-purpose LLM, combining industrial telemetry, asset topology, vulnerability intelligence, attack graphs, process-state information, engineering knowledge and digital-twin simulation. The architecture introduces a reasoning chain that runs observe, understand, correlate, predict, simulate, prescribe, validate, learn. Probabilistic reasoning is surrounded by deterministic constraints: a policy engine provides authority, a safety layer provides boundaries, and the human retains control where risk demands it. The central hypothesis is that specialised small language models, coordinated through structured graphs and deterministic safety mechanisms, can provide sufficiently reliable industrial security reasoning while reducing inference latency, computational requirements and exposure of sensitive industrial information. The paper also proposes the OT-HERMES benchmark, a cyber-physical evaluation framework measuring detection, asset reasoning, vulnerability correlation, attack-path prediction, physical-impact prediction, defensive prescription, safety and computational efficiency. The research question is: what is the smallest AI model, or combination of small models, that can reliably reason about cyber-physical risk in an industrial environment? Status: this is a research proposal. No experimental performance figures are claimed for HERMES-OT. The architecture and the eight contributions are proposed and the six hypotheses stated, but not experimentally validated. Implementation and controlled experiments are the next stage of the work, and are essential before the system is presented as empirically validated.
Yasir Musawar· Zenodo (CERN European Organi...· 0 citations