Knowledge-Graph-Constrained LLM Generation of SIEM Detection Rules
Conference contribution listed in HAL; proceedings publication details are not yet verified. LLM4Sec, ESORICS 2026
Tristan Madani; Yulliwas Ameur; Samia Bouzefrane. "Knowledge-Graph-Constrained LLM Generation of SIEM Detection Rules." LLM4Sec, ESORICS 2026. HAL: hal-05743336.
Status: Conference contribution listed in HAL; proceedings publication details are not yet verified.
Conference period: 2026-09. The page date records this listing; it is not a proceedings publication date.
Contribution in brief
The study uses a knowledge graph to supply valid fields, log sources and Sigma categories to a language model that generates detection rules. It evaluates structural dimensions separately: syntax and compilation, fields, log source, ATT&CK tags and agreement with reference rules.
The revised presentation distinguishes cloud-hosted inference from the possibility of a future self-hosted deployment. It also distinguishes structural agreement from operational detection effectiveness. The reference rules share provenance with the graph and the evaluation scenarios, so agreement with those rules does not provide an independent test of generalization.
This English summary is based on the authors’ revised LLM4Sec presentation dated 14 September 2026, prepared for ESORICS on 18 September. A permanent public URL for the presentation and the artifact has not yet been verified. It should be read alongside the final proceedings version when available.
Related methodology: Benchmarking Detection Engineering Improvements through Instrumented Adversary Emulation.
