KIT | KIT-Bibliothek | Impressum | Datenschutz

GridStratLLM: Agent Framework for Coordinated Cyberattacks on the Smart Grid with Large Language Models

Kellerer, Nicolai ORCID iD icon 1; Hagenmeyer, Veit ORCID iD icon 1
1 Institut für Automation und angewandte Informatik (IAI), Karlsruher Institut für Technologie (KIT)

Abstract (englisch):

A new cybersecurity threat emerges: Recent Large Language Models (LLMs) with advanced reasoning and tool calling enable even attackers lacking expert knowledge to coordinate large-scale attacks on Smart Grids (SG). These LLMs can orchestrate multiple malware instances, select appropriate signals and deltas, and execute data-modification attacks on the S7 and Modbus protocols. Thereby, the automatically generated attack progresses towards the targeted unsafe state and evades detection by the Intrusion Detection System (IDS). To assess this emerging threat, we introduce GridStratLLM, a novel agent framework for coordinated attacks on industrial networks. Furthermore, we evaluate attack plans generated by four frontier Large Language Models using the open-source Network Security Monitor (NSM) Zeek and a commercial NSM. Finally, we contribute a dataset recorded in a Hardware-in-the-Loop (HIL) testbed to support the training of IDS solutions against these attacks. The dataset is 24 hours and 11 minutes long, containing 436 attacks with 212 coordinated attacks.


Verlagsausgabe §
DOI: 10.5445/IR/1000194714
Veröffentlicht am 25.06.2026
Originalveröffentlichung
DOI: 10.1145/3765611.3815147
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Automation und angewandte Informatik (IAI)
Publikationstyp Proceedingsbeitrag
Publikationsdatum 22.06.2026
Sprache Englisch
Identifikator ISBN: 979-8-4007-2199-1
KITopen-ID: 1000194714
HGF-Programm 46.23.02 (POF IV, LK 01) Engineering Security for Energy Systems
Erschienen in ACM Sustainability Week '26: Proceedings of the 2026 ACM Sustainability Week
Veranstaltung ACM Sustainability Week (2026), Banff, Kanada, 22.06.2026 – 25.06.2026
Verlag Association for Computing Machinery (ACM)
Seiten 110–123
Schlagwörter Attack Plan, LLM, Smart Grid, Modbus, S7, Data Modification
Nachgewiesen in OpenAlex
Relationen in KITopen
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page