Skip to main navigation Skip to search Skip to main content

Large Language Models in Cybersecurity: A PRISMA-ScR Guided Scoping Review of Threats, Defenses, and Emerging Applications

  • Srinivas Jangirala
  • , Vedika Gupta
  • , Anandadeep Mandal*
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

5 Downloads (Pure)

Abstract

Large Language Models (LLMs) have rapidly evolved into powerful general-purpose systems with advanced natural language processing, code generation, and reasoning capabilities, leading to their increasing adoption in cybersecurity. However, their dual-use nature introduces both significant defensive opportunities and emerging offensive threats. This study presents a PRISMA-ScR-guided scoping review to systematically map the current landscape of LLM applications in cybersecurity, addressing their roles as both threat enablers and defensive tools while identifying key governance challenges and future research directions. Literature published between January 2017 and December 2024 was identified through structured searches of IEEE Xplore, ACM Digital Library, Scopus,Web of Science, and arXiv, supplemented by grey literature and citation snowballing. Studies were screened using predefined inclusion and exclusion criteria, and relevant information was extracted using a standardized data-charting framework followed by thematic narrative synthesis. The review synthesizes evidence from 153 eligible studies, demonstrating that LLMs substantially enhance offensive capabilities such as phishing, malware generation, vulnerability discovery, and adversarial attacks, while simultaneously improving defensive functions including threat detection, vulnerability management, incident response, security automation, and analyst support. The review further identifies critical limitations related to hallucinations, model reliability, privacy, misuse, and governance, highlighting the need for trustworthy deployment frameworks, standardized evaluation benchmarks, and robust regulatory safeguards. By integrating evidence across technical, operational, and governance perspectives, this scoping review provides a comprehensive evidence-based synthesis of the evolving role of LLMs in cybersecurity and outlines priorities for future research and responsible deployment.
Original languageEnglish
Number of pages32
JournalIEEE Access
Early online date31 Jul 2026
DOIs
Publication statusE-pub ahead of print - 31 Jul 2026

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure
  2. SDG 16 - Peace, Justice and Strong Institutions
    SDG 16 Peace, Justice and Strong Institutions

Keywords

  • Large Language Model
  • Threat Intelligence
  • Cybersecurity
  • Adversarial Attacks
  • Responsible AI
  • Security Operations

Fingerprint

Dive into the research topics of 'Large Language Models in Cybersecurity: A PRISMA-ScR Guided Scoping Review of Threats, Defenses, and Emerging Applications'. Together they form a unique fingerprint.

Cite this