LATIDIA · Ciberseguridad
Hacia una ciberdefensa jerárquica con grandes modelos lingüísticos: de la planificación a la ejecución
arXiv:2610.00590v1 Tipo de anuncio: nuevo Resumen: Un ciberdefensor autónomo entrenado con aprendizaje de refuerzo (RL) generalmente está vinculado a la red en la que fue entrenado, lo que limita su capacidad de generalizar como
WhatsApp ↗Telegram ↗
La noticia
arXiv:2610.00590v1 Announce Type: new Abstract: An autonomous cyber defender trained with reinforcement learning (RL) is typically tied to the network on which it was trained, limiting its ability to generalize as network scale changes. Hierarchical RL reduces decision complexity by separating strategic targeting from tactical execution, but it does not eliminate this retraining dependence. We investigate whether frozen, zero-shot large language models (LLMs) can provide retraining-free control in hierarchical cyber defense and how performance changes as LLM control is extended from planning to execution. We formulate a controller-agnostic planner-executor hierarchy in which the planner selects a subnet to defend over a fixed horizon and the executor selects defensive actions within