
We are happy to introduce a new study exploring how large language models can support threat hunting in IoT environments. Security analysts investigating IoT networks are often overwhelmed by large volumes of raw telemetry and alerts, making it time-consuming to identify which signals point to genuine, evolving threats.
The paper proposes a method that leverages LLMs to generate context-aware threat hypotheses directly from network and device context, helping analysts move faster from raw data to actionable insight. By reasoning over contextual information rather than isolated indicators, the approach aims to surface more relevant hypotheses earlier in the investigation process, supporting more proactive threat hunting in IoT networks.
The work was authored by Abderrahman Elhajjout, Zahi Jarir, Hajar Moudoud, Alan Davoust, and Zakaria Abou El Houda, and was presented at the 2026 IEEE International Conference on Consumer Electronics (ICCE).
Congratulations to the authors for this strong contribution to the field!