Skip to content
Conference Open access

Towards AI-Guided Security Hardening of Industrial Systems Based on IEC 62443

2026 · Proceedings of the 23rd International Conference on Security and Cryptography · 0 citations · 18 references

TL;DR

This paper investigates a secure-by-design engineering process focusing on the initial architectural design and examines the role that AI-powered agents can play in supporting it, as well as the conditions required for their effective and reliable use.

Abstract

: Industrial systems are increasingly exposed to cyber threats, requiring stronger design methodologies to ensure resilience and security. In critical infrastructures, compliance with standards such as IEC 62443 is essential for ensuring security throughout the system lifecycle. This paper investigates a secure-by-design engineering process focusing on the initial architectural design and examines the role that AI-powered agents can play in supporting it, as well as the conditions required for their effective and reliable use. This study experiments with an open-source agentic framework to generate zone-and-conduit architectures from an initial system blueprint. A multi-agent workflow is implemented, including agents responsible for architecture generation, compliance verification against IEC 62443 requirements, and security stress testing using attack tree analysis. A drinking water utility case study, subject to NIS regulatory constraints, is used to compare AI-assisted and manually produced architectures. The results highlight both the benefits and limitations of AI-assisted design, leading to the identification of recommendations and open issues for further research, with potential applicability beyond the industrial domain.

Read PDF

Similar papers

Open access Aug 2026

Security-by-Design and Risk-Based Certification for AI-Enabled Smart Home

The integration of Artificial Intelligence (AI) into Internet of Things (IoT) ecosystems has enabled the development of advanced cyber–physical systems, including smart appliances, while introducing security, privacy, and AI governance risks that extend beyond the scope of traditional threat models. Existing approaches often address cybersecurity, AI risk management, and regulatory compliance in isolation, leaving manufacturers without a systematic method for translating identified threats into architectural controls and certification requirements. To address this gap, this study proposes a Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning. The resulting cross-layer analysis informs a four-level certification model (L1–L4) that deterministically maps each appliance configuration to a set of mandatory security and governance controls according to its degree of autonomy and AI capability. The framework is instantiated and evaluated using a physical smart-refrigerator prototype, demonstrating how threat identification can be systematically translated into design decisions and certification requirements. The proposed framework provides manufacturers, certification bodies, and researchers with a reproducible engineering pathway for designing and evaluating secure, governance-aligned AI-enabled IoT appliances.

Iván Ortiz-Garcés, Roberto O. Andrade · 0 citations
Review Open access Aug 2026

AI-Driven Problem Solving for Cyber-Physical Systems Security: An Assessment Framework

Cyber-Physical Systems (CPS) are using more AI for smart decisions and automation, but also faces new security issues. This study surveys existing CPS security assessment methodologies across healthcare, automotive, energy, and critical infrastructure, identifying their limitations in addressing emerging digital-physical threats. We find that traditional risk assessment and testing approaches, often network-centric and compliance-driven, are insufficient for AI-powered CPS. New vulnerabilities arise from the tight coupling of cyber and physical components, such as adversarial manipulation of sensors that can cause dangerous misbehavior, supply chain attacks on AI models, and the inability to patch critical devices on the fly. We use AI techniques and problem-solving methods to improve the security of CPS. The framework helps detect threats, monitor system activities, and reduce security risks in real time. It also follows important security and privacy standards such as NIST, IEC 62443, ISO 21434, and GDPR. The system continuously checks CPS operations, uses AI tools to find weaknesses, and supports security compliance. We also study real-world CPS attacks, including industrial malware, car hacking, and medical device attacks, to show the importance of the framework. In this research, we present prototype implementation and experimental evaluation along with a case study of protecting a smart manufacturing plant during a ransomware attack using the proposed approach.

Unknown authors · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, Shilpi Sharma · 1 citation
Book Open access Jul 2026

An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling

Empirical evidence is provided that generative AI can effectively support security requirements engineering when embedded within human-centered workflows and organizational governance structures, offering practical insights for adoption in regulated software development contexts.

F. Martins, Elaine Venson · 0 citations
Open access Aug 2026

Designing an AI-Assisted Cyber Threat Intelligence Framework for Industry 4.0: A Human-in-the-Loop Design Science Approach

The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate. Following a Design Science Research approach, the framework was evaluated through expert assessment involving twelve cybersecurity practitioners with experience in industrial and Security Operations Centre (SOC) environments and complemented by a proof-of-concept artefact instantiation based on the APT41 DUST campaign. The prototype integrated five heterogeneous CTI evidence sources and executed the automated analytical workflow in approximately 25 s (25.29 s) while illustrating evidence-grounded retrieval, specialized agent orchestration, and human-supervised intelligence generation. Practitioner feedback indicated that AI-assisted contextual intelligence and agent-based reasoning were perceived as valuable, while successful adoption depends primarily on governance, explainability, trust, and alignment with existing operational workflows rather than algorithmic sophistication alone. The study contributes a design-science artefact that combines retrieval-augmented intelligence, modular AI agents, and human oversight, providing practical design guidance for trustworthy AI-assisted CTI deployment in safety-critical Industry 4.0 environments.

Majed Albarrak, Sandeep Jagtap · 0 citations
Aug 2026

Securing agentic AI workflows: A defence-in-depth framework for autonomous systems

The rapid enterprise adoption of agentic artificial intelligence (AI) has introduced a category of security risk that existing cyber security frameworks were not designed to address. With 78 per cent of Fortune 500 companies projected to deploy agentic AI by 2026 and the global market expected to reach US$89.6bn, the attack surface created by these autonomous workflows demands urgent attention from security practitioners. This paper examines the distinct threat model presented by agentic AI, drawing on recent high-profile incidents, including the weaponisation of a large language model in a state-sponsored espionage campaign affecting 30 organisations and the compromise of an open-source agent framework exposing 30,000 Internet-facing instances, to illustrate the consequences of inadequate controls. Grounded in the Open Worldwide Application Security Project’s Top 10 for Agentic Applications (2026) and the National Institute of Standards and Technology’s ongoing agentic AI security initiative, the paper proposes a five-layer defence-in-depth framework encompassing input validation, identity and least privilege, runtime sandboxing, human-in-the-loop governance, and continuous behavioural monitoring. It identifies sandboxing and least-privilege enforcement as the highest return on investment controls, provides a prioritised implementation roadmap, and discusses the emerging paradigm of cryptographic workflow authentication. The analysis concludes that organisations treating agentic AI security as an extension of traditional application security will find themselves critically exposed and that a purpose-built security architecture is now a business imperative. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.

Sushma Mahadevaswamy · 0 citations