Adaptable and Timely Incident Response for Industrial Enterprise Networks Using LLM-based Predictive Reinforcement Learning
Abstract
Adaptable and timely incident response is critical for industrial enterprise networks to recover from diverse cyberattacks. However, existing works have two limitations: 1) performance degradation when facing diverse attacks or deployed in different network environments; and 2) insufficient timeliness and effectiveness without jointly considering recovery delays and operational failures. Therefore, we develop an incident response method for industrial enterprise networks using large language model (LLM)-based predictive reinforcement learning, consisting of three parts: prior candidate-plan generation using LLMs, lookahead prediction using world-model rollouts, and posterior decision-making using proximal policy optimization (PPO). We propose selecting a plan by jointly considering its LLM-derived prior preference and the return and uncertainty from world-model rollouts. This approach captures regularities among prior preference, return, and uncertainty across incident scenarios, improving generalization to diverse attacks and network environments. Furthermore, we propose a reward function that penalizes recovery delays and operational failures to guide plan-selection policy learning, improving response timeliness and effectiveness. Evaluations show that our method outperforms selected SOTAs under diverse attacks and across different network environments, and our reward function achieves higher recovery precision, shorter recovery delay, and fewer operational failures than the reward functions used in selected SOTAs.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.