Skip to content
Review Open access

LLM-Driven Security and Resilience in 6G Mission-Critical Communication Networks

2026 · IEEE Open Journal of the Communications Society · Vol 7, pp. 8963-8984 · 1 citation · 61 references

TL;DR

Working baseline levels of capability are provided with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions are mapped out.

Abstract

The large language models (LLMs) are beginning to provide tangible changes to the practice of network security: better threat detection; tighter enforcement of policy; and faster incident response. This survey provides a practitioner’s perspective on the use of LLMs in each of the key areas of network security, with a focus on 6G-enabled mission-critical communication systems, including public safety networks, emergency response coordination, and resilient infrastructure supporting URLLC, non-terrestrial networks (NTN), and edge deployments; these include traffic analysis, anomaly detection, threat intelligence, intrusion detection, vulnerability management, access control, compliance auditing, and security training. The survey documents specific improvements provided by LLMs with respect to context-aware classification, parsing of logs at a fine level of granularity, translating high-level policies to executable rules, and scripting of realistic threat scenarios to test against. We show how the combination of prompt engineering, multimodal embeddings, federated learning, and retrieval-augmented generation (RAG) can be used to expand the capabilities of the Security Operations Center (SOC), and automated defense. We also identify some of the risks associated with the use of LLMs, which include hallucination in output, leakage of sensitive information, and creation of new attack vectors through integration with the model; we also note some of the safeguards that have begun to emerge. We further analyze concrete public safety and emergency response scenarios - including LLM-assisted disaster-zone threat detection and emergency communication prioritization under adversarial overload - examining the specific vulnerabilities introduced by NTN-enabled 6G architectures and the stringent latency requirements of URLLC deployments. In conclusion, we provide working baseline levels of capability with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and map out specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions.

Read PDF

Similar papers

Open access Jul 2026

Security Assurance in 5G-Advanced (3GPP Release 18): Protecting Edge Computing, Network Automation, and Non-Public Networks

5G-Advanced (3GPP Release 18) architectural changes include multi-access edge computing (MEC) architectural changes, network automation, and non-public networks (NPNs). It is important to note that even though these advancements provide substantial performance advantages, they destroy fixed-perimeter security models, providing a distributed attack surface. The use of current security assessment strategies, which are usually non-fluid and isolated, is inadequate to offer the required runtime security health assurance needed in such fluid environments. This study presents a new security assurance framework (SAF) that would be used to provide ongoing evidence-based protection on core, edge, and private network domains. This framework employs a four-layer architecture, including monitoring, analytics (LM), policy engine, and enforcement, to convert security periodically audited to a dynamic threat-control-metric evidence chain. A 96% attack detection rate and a 99.8% reduction in response time (with a mean of 20.1 s) are proven by validation on an emulated 5G-Advanced testbed (approximating Release 18 features using Open5GS (v2.7.2 Rel-17, community developed, Seoul, Republic of Korea and custom extensions) based on a design science research (DSR) paradigm. Although the overhead (13% CPU, 21.4% memory) is manageable, the findings prove that all-time, multi-domain assurance is crucial to the healthy functioning of 5G-Advanced and is a key roadmap to autonomous 6G security.

E. Egho-Promise, Ekereuke Udoh, Edita Gashi et al. · 0 citations
Review Open access 2026

Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness

The proposed Large Language Model-Assisted Threat-Driven Testing System enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby strengthening organizational cyber-readiness at significantly lower cost than traditional security testing approaches.

Praise Emeka Nze, A. Ademuwagun, Muktar Bello et al. · 0 citations
Book Open access Aug 2026

The 2nd SeT-LLM Workshop on Secure and Trustworthy Large Language Models

The 2nd SeT-LLM Workshop on Secure and Trustworthy Large Language Models brings together researchers and practitioners from data mining, machine learning, security, and responsible AI to address issues from a data-centric, system-level perspective.

Lu Lin, Jinghui Chen, Ting Wang et al. · 0 citations
Conference Open access 2026

Performance Evaluation of Pfsense in Detecting and Preventing Network Attacks in Controlled Environments

Research results indicate that pfSense, with properly configured IDS/IPS systems, can effectively detect and block a significant percentage of attacks, making it a reliable solution for network protection, particularly in resource-constrained environments.

Nemanja Jeličić, Marko Šarac · 0 citations
Open access Jul 2026

Unveiling hidden adversaries - detecting command & control servers

The increasingly advanced forms of cyber-attacks have highlighted the importance of advanced threat hunting as a necessary skillset. The current research examines the effectiveness of using Elasticsearch, Kibana, and Lucene for an intelligence-driven threat hunting to identify attack infrastructure or a Command & Control (C2) server. By aggregating all system traffic logs and security artifacts into a single data lake/warehouse, organizations are able to leverage centralized analysis of information from different sources on a corporate scale. Utilizing Kibana’s ability to perform network and log analysis, using Lucene’s rich syntax to make sophisticated queries will empower individuals to make valuable findings from log and network traffic logs that identify behaviours and patterns typical of C2 activities. A novel intelligence-based threat hunting approach is presented here that utilizes Elasticsearch, with domain-specific language additions to refine search queries and investigate for C2 related activity. A detailed analysis of the research based on real-world datasets is conducted to evaluation the threat hunting framework’s abilities in detecting C2 servers and minimize true/false positives in relation to organizational security concerns.

N. Alsharabi, Akashdeep Bhardwaj, Amr Jadi et al. · 0 citations
Conference Jul 2026

A Comparative Analysis of Security Vulnerabilities and Defense Mechanisms in Large Language Models

Large Language Models (LLMs) are now deployed at an unprecedented scale across many critical sectors, rapidly transitioning from experimental AI tools to embedded components of production software systems. This accelerated adoption, often enabled by low-code integrations, has lowered technical barriers while simultaneously expanding the attack surface of modern applications, particularly when deployments occur without sufficient domain-specific security expertise. In many cases, security maturity has not progressed at the same pace as capability expansion, creating systemic exposure across confidentiality, integrity, and availability dimensions. To provide structured clarity amid this rapid growth, this paper presents a comparative and standards-aligned analysis of LLM security risks and defense mechanisms grounded in the OWASP GenAI Top-10 (2025). We systematically examine each vulnerability class, map representative attack patterns to primary mitigation strategies, evaluate their security property impact, and analyze practical limitations and implementation trade-offs. In addition, we introduce a severity-based assessment to prioritize risks according to operational and systemic impact, offering a quantitative perspective on defensive readiness. Our findings indicate that current mitigation strategies are predominantly reactive, concentrated at inference time, and unevenly distributed across the LLM lifecycle. Controls addressing training pipelines, supplychain dependencies, and autonomous system behaviors remain comparatively less mature and less standardized. By integrating vulnerability classification, defense mapping, severity prioritization, and trade-off analysis within a unified framework, this study provides actionable guidance for strengthening secure, resilient, and standards-driven LLM deployment in high-stakes environments.

Md Abdul Barek, Md Bajlur Rashid, A. K. I. Riad et al. · 0 citations