Reasoning Topology Matters: A Controlled Study of LLM-Based Cybersecurity Analysis

📅 2026-09-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过引入三种结构(线性、分支和图)来组织中间推理步骤,提高LLM在网络安全分析中的性能,图结构表现最佳。
📝 Abstract
Large Language Models (LLMs) are increasingly used in cybersecurity, where accurate analysis often requires multi-step and context-dependent reasoning over complex and heterogeneous data. However, existing prompting approaches typically focus on eliciting reasoning without explicitly considering how intermediate reasoning steps are structurally organized. We introduce Security Reasoning Topology, which models reasoning through three representative structures: Linear, Branching, and Graph. To evaluate their effects, we conduct controlled experiments on three cybersecurity datasets covering MITRE ATT&CK network traffic, cyber threat intelligence (CTI), and CVE vulnerability analysis. We evaluate multiple LLMs, including Llama 2 (7B, 13B, 70B), GPT-5.1, and Mistral Large 3, while keeping task inputs consistent and controlling reasoning structure through system-level prompting. Results show that reasoning topology substantially affects performance: Graph reasoning achieves the highest overall accuracy, improving over few-shot prompting by 9.8-12.2 percentage points across datasets, while Branching provides a strong intermediate solution. The results further show that the effect of reasoning topology remains consistent across model families and scales, highlighting reasoning topology as an important design factor for LLM-based cybersecurity analysis.
Problem

Research questions and friction points this paper is trying to address.

Large Language Models
cybersecurity analysis
reasoning topology
intermediate reasoning steps
structural organization
Innovation

Methods, ideas, or system contributions that make the work stand out.

Security Reasoning Topology
Graph Reasoning
LLM-based Cybersecurity Analysis
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
J
Jiling Zhou
Department of Computing, University of Turku, Turku, Finland
A
Aisvarya Adeseye
Department of Computing, University of Turku, Turku, Finland
A
Antti Hakkala
Department of Computing, University of Turku, Turku, Finland
Seppo Virtanen
Seppo Virtanen
Professor of Cyber Security Engineering, University of Turku
CybersecurityNetwork SecurityInternet VotingNetwork TechnologyEmbedded Systems
J
Jouni Isoaho
Department of Computing, University of Turku, Turku, Finland