[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83167-en":3,"doc-seo-83167-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83167,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies","Large Language Models (LLMs) and generative AI systems are reshaping cybersecurity by enabling real-time defense and enabling more scalable, sophisticated attacks. The survey analyzes beneficial and malicious uses, including zero-day detection, DevSecOps, federated learning, synthetic content analysis, explainable AI (XAI), and the threat posed by AI-generated malware. Drawing on 70+ academic papers, industry reports, and technical documents across major platforms, it synthesizes real-world case insights and proposes practical, governance-oriented defensive recommendations.","Large Language Models (LLMs) and Generative AI in Cybersecurity and Privacy: A Survey of Dual-Use Risks, AI-Generated Malware, Explainability, and Defensive Strategies  \nKiarash Ahi 1 and Saeed Valizadeh2  \n1Virelya Intelligence Research Labs, San Francisco Bay Area, California  \n2 Google, Mountain View, California  \n[1](1{ahi@virelya.org)[{](1{ahi@virelya.org)[ahi@virelya.org](1{ahi@virelya.org), [kiarash.ahi@uconn.edu](kiarash.ahi@uconn.edu})[}](kiarash.ahi@uconn.edu}), [2](2{svalizadeh@google.com)[{](2{svalizadeh@google.com)[svalizadeh@google.com](2{svalizadeh@google.com), [saeed.valizadeh@uconn.edu](saeed.valizadeh@uconn.edu})[}](saeed.valizadeh@uconn.edu})  \nThis paper has been accepted as an invited paper.  \narXiv :2607 .06963v 1 [ cs .CR] 8 Jul 2026  \nAbstract—Large Language Models (LLMs) and generative AI (GenAI) systems, such as ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion by OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, respectively, are revolutionizing cybersecurity, enabling both automated defense and sophisticated attacks. These technologies power real-time threat detection, phishing defense, secure code generation, and vulnerability exploitation at unprecedented scales. LLM-generated malware alone is projected to account for 50% of detected threats in 2025, up from just 2% in 2021, emphasizing the need for nextgeneration security frameworks. This paper presents a comprehensive survey of the beneficial and malicious applications of LLMs in cybersecurity, including zero-day detection, DevSecOps, federated learning, synthetic content analysis, and explainable AI (XAI). Drawing on a review of over 70 academic papers, industry reports, and technical documents, this work synthesizes insights from real-world case studies across platforms like Google Play Protect, Microsoft Defender, Amazon Web Services (AWS), Apple’s App Store, OpenAI Plugin Stores, Hugging Face Spaces, and GitHub, alongside emerging initiatives like the SAFE Framework and AI-driven anomaly detection. We conclude with practical recommendations for responsible and transparent LLM deployment and trustworthy AI, including model watermarking, adversarial defense, and cross-industry collaboration—setting anew benchmark for rigorous, holistic cybersecurity research at the intersection of AI and threat defense—and offering aroadmap for secure, scalable LLM systems that serves as a critical reference for researchers, engineers, and security leaders navigating the complex challenges of AI-driven cybersecurity.  \nIndex Terms—Large Language Models (LLMs), Generative AI, Cybersecurity, Dual-Use AI, AI-Driven Malware, Explainable AI (XAI), Zero-Day Detection, Federated Learning, Platform Integrity, ChatGPT, Claude, Gemini, LLaMA, Copilot, Stable Diffusion, OpenAI, Anthropic, Google, Meta, Microsoft, Stability AI, Amazon Web Services (AWS), Apple App Store, OpenAI Plugin Stores, Microsoft Defender, Google Play Protect, GitHub, AI Governance, Deepfakes, Synthetic Content, AI Security, Threat Detection, Anomaly Detection  \nI. INTRODUCTION  \nThe rapid evolution of artificial intelligence has placed Large Language Models (LLMs) and generative AI at the  \nforefront of software innovation and cybersecurity transformation. Originally developed to enhance natural language understanding, LLMs such as GPT-4, PaLM, and Gemini are now widely adopted across industries to automate code generation, accelerate development workflows, and enable intelligent decision-making [1], [2], [3] . However, this widespread adoption has created a double-edged sword: LLMs empower defenders—especially platform administrators like Google Play, Apple App Store, and other enterprise app platforms—to perform static code scanning, automate threat detection, and improve code quality in real time. Yet simultaneously, those same models are exploited by attackers to generate malware, obfuscate code, and discover vulnerabilities at scale. This duality introduces complex security and","cbCaipp432rAeQrn","https://ap.wps.com/l/cbCaipp432rAeQrn","pdf",1844475,4,1,10,"English","en",105,"# Introduction\n# Background and Literature Review\n## Evolution and Capabilities of LLMs\n## LLM Applicability in Security\n## Future Research Directions\n# Conclusion","[{\"question\":\"What dual-use roles do LLMs play in cybersecurity and privacy?\",\"answer\":\"LLMs support defenders by automating threat detection, static code scanning, and code-quality improvements, while adversaries use them to generate malware, obfuscate code, and discover vulnerabilities at scale.\"},{\"question\":\"Which cyber threat and defense areas does the survey cover?\",\"answer\":\"The document covers AI-generated malware risks and defense strategies including zero-day detection, DevSecOps, federated learning, synthetic content analysis, and explainability-driven approaches (XAI).\"},{\"question\":\"What sources and platforms does the survey rely on?\",\"answer\":\"It synthesizes insights from a review of 70+ academic papers, industry reports, and technical documents, using case studies across platforms such as Google Play Protect, Microsoft Defender, AWS, Apple’s App Store, OpenAI Plugin Stores, Hugging Face Spaces, and GitHub.\"}]",1784185714,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"large-language-models-llms-and-generative-ai-in-cybersecurity-and-privacy-a-survey-of-dual-use-risks-ai-generated-malware-explainability-and-defensive-strategies","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/large-language-models-llms-and-generative-ai-in-cybersecurity-and-privacy-a-survey-of-dual-use-risks-ai-generated-malware-explainability-and-defensive-strategies/83167/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What dual-use roles do LLMs play in cybersecurity and privacy?","Question",{"text":75,"@type":76},"LLMs support defenders by automating threat detection, static code scanning, and code-quality improvements, while adversaries use them to generate malware, obfuscate code, and discover vulnerabilities at scale.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which cyber threat and defense areas does the survey cover?",{"text":80,"@type":76},"The document covers AI-generated malware risks and defense strategies including zero-day detection, DevSecOps, federated learning, synthetic content analysis, and explainability-driven approaches (XAI).",{"name":82,"@type":73,"acceptedAnswer":83},"What sources and platforms does the survey rely on?",{"text":84,"@type":76},"It synthesizes insights from a review of 70+ academic papers, industry reports, and technical documents, using case studies across platforms such as Google Play Protect, Microsoft Defender, AWS, Apple’s App Store, OpenAI Plugin Stores, Hugging Face Spaces, and GitHub.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":22,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]