Score
Designs and generates machine-readable, non-real-time operational policy artifacts using large language models, including structured scheduling rules, service priority lists, numeric weight bounds, and explicit safety constraints. Produces periodic or batch policy updates and human- and machine-interpretable policy documents (RAPP-style) intended for orchestration and resource-allocation specification rather than real-time control.
This study addresses the challenge of automatically transforming healthcare policy documents into executable, data-aware business process models, a bottleneck in simulation-based policy evaluation. The authors propose an end-to-end pipeline that leverages large language models to convert clinical guidelines into executable BPMN (Business Process Model and Notation) models. The approach introduces four key innovations: data-driven BPMN generation, automatic syntactic correction, enhanced executability, and embedded KPIs, complemented by entropy-based uncertainty detection to flag complex clauses requiring human review. Experimental results demonstrate 100% decision consistency on well-structured guidelines and over 92% accuracy in patient-level decision modeling, confirming the method’s effectiveness and practical applicability.
To address the error-proneness and analytical intractability of manually authored access control policies in cloud environments, this paper proposes an automated policy generation and semantic-level request summarization framework integrating large language models (LLMs) with symbolic techniques. Methodologically, it introduces a semantics-driven request abstraction mechanism, augmented by an inference-enhancement module and symbolic execution–based verification, to construct an interpretable and verifiable policy analysis pipeline. Key contributions include: (i) the first synergistic use of symbolic execution and LLM-based reasoning to ensure semantic consistency of access policies; and (ii) a novel bidirectional request–policy summarization paradigm that significantly improves policy comprehensibility and behavioral predictability. Experimental results show that inference-capable LLMs achieve 93.7% accuracy in generating compliant policies—substantially outperforming non-inference LLMs (45.8%)—and symbolic augmentation reduces false positives by 62% in complex policy scenarios.
This work addresses the challenges of deploying large language models (LLMs) in mission-critical environments such as the Internet of Battlefield Things (IoBT), where safety, reliability, and policy compliance are paramount. The authors propose a Policy-Aware Edge LLM-RAG framework (PA-LLM-RAG) that integrates policy- and telemetry-informed retrieval-augmented reasoning, lightweight local LLM-based task planning, and a dual-instruction verification mechanism powered by an independent JudgeLLM. By synergistically combining deterministic policy constraints with semantic-level instruction validation, the framework effectively blocks non-compliant actions while maintaining low-latency operation. Experimental evaluation in a RoboDK simulation environment demonstrates that a Gemma-2B–based implementation achieves 100% task success rate with an average response latency of 4.17 seconds, confirming its efficacy in balancing real-time performance and strict policy adherence in complex, high-risk scenarios.
Manually authoring access control policies is error-prone and costly, particularly in security-critical systems. Method: This work proposes a zero-shot large language model (LLM)-based automated policy synthesis method, centered on a fine-grained prompt template grounded in AWS IAM policy syntax. The template accommodates two input modalities: structured request lists and natural language descriptions—requiring neither fine-tuning nor in-context examples. Contribution/Results: Experimental evaluation demonstrates that the structured prompting significantly improves policy correctness over generic zero-shot baselines, achieving 100% compliance with syntactic validity and fundamental semantic constraints (e.g., action-resource alignment and permission minimality). The approach enables scalable, low-barrier policy engineering for security-sensitive applications, establishing a novel paradigm for LLM-driven access control automation.
This work addresses the need for automated digital rights policy generation in multi-institutional, culturally oriented trusted data spaces. We propose a large language model (LLM)-based natural language-to-ODRL policy mapping method. Our approach uniquely integrates the W3C ODRL ontology and its structured documentation as core components of prompt engineering to guide GPT-4 in generating high-fidelity, standards-compliant policies. Additionally, we introduce an ontology-adaptation heuristic tailored for knowledge graph construction to enhance semantic alignment. Evaluated on 12 culturally diverse use cases spanning varying complexity levels, our method achieves a policy generation accuracy of 91.95%, significantly outperforming existing baselines. The contribution lies in establishing a scalable, interpretable, and standards-aligned automation paradigm for open digital rights management—bridging natural language requirements with formal, machine-processable ODRL policies.
为解决规范性规则生成中的操作可行性问题,提出GNRS-Search框架,利用MCMC采样优化And-Or图,提高规则的可执行性和合规性。
This work addresses critical challenges faced by large language models in real-time, regulated environments—namely outdated knowledge, catastrophic forgetting, hallucination, and weak feedback loops—by proposing a unified pattern-driven LLMOps architecture that enables an end-to-end operational pipeline. The core innovations include an Adaptive Ingestion and Pipeline Orchestrator (AIPO), a STAR+FAR continual learning mechanism, an SLO-aware adaptive retrieval strategy (SAGE), and an RLHF triggering phase that automatically converges based on feedback. By integrating real-time data ingestion, sparse temporal adapter routing, freshness-aware replay, and retrieval-augmented generation, the architecture substantially mitigates the trade-offs among latency, cost, and accuracy while providing the auditability and rollback capabilities required in high-stakes domains such as healthcare and finance.
This work addresses the critical need for policy enforcement mechanisms in high-stakes domains that simultaneously offer scalability and formal safety guarantees. Existing approaches either lack formal verification or rely on handcrafted rules that do not scale. To bridge this gap, the authors propose a novel generate-and-critic loop framework grounded in large language models, which for the first time enables fully automated translation from natural language policy documents, agent prompts, and MCP tool descriptions into the formally verifiable Cedar policy language. The method preserves rigorous formal guarantees while substantially expanding policy coverage and scalability. Evaluated on the MedAgentBench benchmark, the automatically generated policies capture a more comprehensive subset of the original specifications than manually encoded counterparts.
This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.
This work addresses the limitation of existing text-to-process modeling approaches, which predominantly focus on control flow while neglecting resource and collaboration perspectives, thereby struggling to generate complete multi-party models. To overcome this, the authors propose a resource-aware generative pipeline that systematically incorporates the resource dimension into large language model (LLM)-driven process modeling for the first time. The method automatically constructs BPMN 2.0 collaboration diagrams from natural language descriptions, explicitly capturing organizational pools, role-based lanes, and inter-organizational message events, and employs an orthogonal layout algorithm for automated diagram arrangement. Experimental results across ten business processes and nine LLMs demonstrate that the approach accurately extracts resource-related information, maintains high control-flow quality, and incurs only minimal runtime overhead, advancing generative process modeling toward more collaborative and resource-complete representations.