Designing an LLM-augmented framework for security evaluation and policy recommendation
Loading...
Date
Publisher
BRAC University
Citation
Abstract
As organizations continue to accumulate more data in the digital platforms, it becomes
difficult to safeguard sensitive data. The authorization and authentication
factors restrict the use of critical systems, but traditional IAM can’t scale with the
new breed of cyber-threats like credential theft, phishing and AI attacks. The motive
of this paper is in building security systems more resilient and intelligent to deal
with any kind of malicious attacks and generating decisions with the application of
Large Language Models (LLMs) augmented with advanced AI driven techniques.
The project was initially focused on the specified access control factors of Identity
and Access Management (IAM) and evaluating policies with providing security
scores connected to web interfaces to analyze vulnerable factors beforehand. This
was incorporated to a hybrid AI architecture consisting of a small BERT-tiny model
optimized to detect security anomalies quickly and larger transformer based models
LLMs (Mistral-7B and Gemma3-270M) that can be deployed to explain problems
in fine detail and generate remediation strategies that can be executed. Experiments
on larger actual datasets showed BERT-tiny achieved a remarkable accuracy
of 90.12% for detection and 82.45% for malicious type differentiation. The focus
applied on hyperparameter tuning, multi layer approach optimization, and class imbalance
adjustments ensured robustness and generalization. Although certain limitations
remain, especially in aspects of response latencies and the computational
overhead, the present work is a step towards demonstrating the radical potential of
an LLM approach in building systems that think faster, explain better, and adapt
smarter to emerging digital threats.
Description
Cataloged from PDF version of thesis.
Includes bibliographical references (pages 52-54).
This thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2025.
Includes bibliographical references (pages 52-54).
This thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2025.
Publisher Link
Type
Thesis