Dependable systems require continuous assurance across distributed infrastructures to validate their non-functional properties. Yet selecting and configuring assurance probes remains complex, demanding expert knowledge of standards and mechanisms, and is difficult to scale across the cloud continuum. This paper proposes a methodology that leverages lightweight Large Language Models (LLMs) and a Retrieval-Augmented Generation (RAG) approach to help operators identify and configure suitable assurance probes. We introduce an architecture that enriches operator queries with evidence and compliance context before processing them through an LLM-based assistant. Evaluation, including an LLM-as-a-Judge analysis, shows that this approach reduces operator effort while preserving oversight, strengthening assurance processes in dynamic, distributed environments.
Security Assurance Based on Large Language Models / T. Radicchi, M.L. (LECTURE NOTES ON DATA ENGINEERING AND COMMUNICATIONS TECHNOLOGIES). - In: Complex, Intelligent and Software Intensive Systems / [a cura di] L. Barolli, I. Chihi, T. Enokido. - [s.l] : Springer Nature, 2026 Sep 04. - ISBN 978-3-032-29430-2. - pp. 255-267 (( 20. CISIS Proceedings of the International Conference : July, 1st - 3rd Luxembourg 2026 [10.1007/978-3-032-30573-2_23].
Security Assurance Based on Large Language Models
M. Luzzara
Secondo
;C.A. ArdagnaPenultimo
;M. AnisettiUltimo
2026
Abstract
Dependable systems require continuous assurance across distributed infrastructures to validate their non-functional properties. Yet selecting and configuring assurance probes remains complex, demanding expert knowledge of standards and mechanisms, and is difficult to scale across the cloud continuum. This paper proposes a methodology that leverages lightweight Large Language Models (LLMs) and a Retrieval-Augmented Generation (RAG) approach to help operators identify and configure suitable assurance probes. We introduce an architecture that enriches operator queries with evidence and compliance context before processing them through an LLM-based assistant. Evaluation, including an LLM-as-a-Judge analysis, shows that this approach reduces operator effort while preserving oversight, strengthening assurance processes in dynamic, distributed environments.| File | Dimensione | Formato | |
|---|---|---|---|
|
paper.pdf
embargo fino al 04/09/2027
Tipologia:
Post-print, accepted manuscript ecc. (versione accettata dall'editore)
Licenza:
Publisher
Dimensione
164.54 kB
Formato
Adobe PDF
|
164.54 kB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.




