[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82178-en":3,"doc-seo-82178-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82178,687197207057,"Sage","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Neuro-Agentic Control: A Deep Learning-based LLM-Powered Agentic AI Framework for Controlling Security Controls","Cyberattacks on operational technology increasingly cause costly downtime and physical damage, revealing limitations of traditional rule-based monitoring in industrial IoT. This paper presents a neuro-agentic control framework that integrates an LLM-based planner with a pre-trained time-series foundation model to enable physics-grounded autonomous defense. It adds a “Counterfactual Physics Injection” mechanism that simulates LLM-proposed interventions in latent space before actuation, enabling rejection of hallucinated or unsafe actions. On Secure Water Treatment (SWaT) under stochastic attacks, the framework outperforms LSTM and TCN baselines, preventing five breaches (33.3%) with zero physically invalid actions.","arXiv :2607 .09076v 1 [ cs .AI] 10 Jul 2026  \nNeuro-Agentic Control: A Deep Learning-based LLM-Powered Agentic AI Framework for Controlling Security Controls  \nSaroj Gopali 1 , Bipin Chhetri 1 , Deepika Giri2 , Sima Siami-Namini3 , Akbar Siami Namin 1 Department of Computer Science 1 , Texas Tech University 1  \nCumberland University2 , Advanced Academic Programs Science3 , Johns Hopkins University3 {saroj.gopali, bipin.chhetri, akbar.namin∗ }@[ttu.edu](ttu.edu), [dgiri25@students.cumberland.edu](dgiri25@students.cumberland.edu), [ssiamin1@jhu.edu](ssiamin1@jhu.edu)  \nAbstract  \nCyberattacks on operational technology are increasingly causing costly downtime and physical damage, exposing the limitations of traditional rule-based monitoring in industrial IoT environments. While Large Language Models (LLMs) have strong semantic reasoning abilities to assist in decision support, their hallucinatory nature presents unacceptable safety liabilities for closedloop control. This paper introduces a neuro-agentic control framework, a novel architecture that couples an LLM-based planner (i.e., such as Gemini 2.5 Flash-Lite) with a pre-trained Time-Series Foundation Model (TimesFM), to achieve physics-grounded autonomous defense. The paper introduces a “Counterfactual Physics Injection” mechanism that simulates the impact of LLMproposed interventions within the numerical latent space of the foundation model before actuation, while allowing the system to reject hallucinatory or unsafe actions. Evaluated on an industrial dataset (e.g., the Secure Water Treatment (SWaT)) in the context of stochastic attack scenarios, the framework exhibited better performance compared to LSTM and TCN baselines. The Neuro-Agentic Loop prevented five breaches (33.3%) below the threshold versus LSTM (26.7%) and TCN (13.3%), with zero physically invalid (hallucinated) actions executed. These results demonstrate the efficacy of using foundation models as deterministic “Sentinels” to safeguard agentic AI in critical infrastructure.  \nIndex Terms  \nAgentic AI, Retrieval-Augmented Generation (RAG), Time series prediction, Foundation models, Gemini 2.5 Flash lite, LSTM, TCN.  \nI. INTRODUCTION  \nCyberattacks on operational technology are increasingly causing real process disruptions and costly downtime for industrial organizations. The Kaspersky ICS 2023 [13] identifies several instances in which manufacturers were forced to stop production lines due to ransomware and targeted intrusions. Meanwhile, analysis of unplanned downtime shows that manufacturers now lose more than $2 million in the automotive sector for every hour lost, compared to approximately $39,000 in fast-moving consumer goods [22] . In Cyber–Physical Systems (CPS), security failures are not abstract IT-related events, but immediate drivers of safety risk and large financial loss. In increasingly dense Industrial IoT deployments, billions of connected devices expand the attack surface, making manual device-by-device hardening and monitoring fundamentally infeasible at scale.  \nLarge language models (LLMs) and time-series foundation models have recently become highly effective instruments for forecasting and reasoning tasks over high-dimensional streaming data. Together, LLMs and time-series models allow large-scale prediction for maintenance, decision support, and anomaly detection [14], [16] . Considering the surge of LLMs, foundation models present exciting possibilities for various applications as useful world models in safeguarding cyber-physical systems. Proactive risk mitigation is based on forecasting future trajectories in various operational scenarios. Recently, TimesFM and other time-series foundation models have been proposed as general-purpose forecasters trained in large and diverse time-series corpora [6] .  \nHowever, most existing agentic systems for IoT and time series forecasting operate in an offline setting and primarily focus on recommending or selecting models. The models utilized to ","cbCaidGwbD87tdZf","https://ap.wps.com/l/cbCaidGwbD87tdZf","pdf",315755,1,10,"English","en",105,"# Abstract\n# Introduction\n## Motivation and Problem\n## Proposed Neuro-Agentic Control Framework\n## Experimental Setup and Contributions","[{\"question\":\"What problem does the proposed framework address in industrial IoT security control?\",\"answer\":\"It targets the safety limitations of traditional rule-based monitoring and the risk of LLM hallucinations in closed-loop control for operational technology, where incorrect actions can cause real process disruption and physical damage.\"},{\"question\":\"How does “Counterfactual Physics Injection” work in the framework?\",\"answer\":\"It translates semantic actions proposed by the LLM into numerical perturbations of the foundation model’s recent historical window, simulating the action’s impact before any real actuation.\"},{\"question\":\"How was the framework evaluated and what were the main results?\",\"answer\":\"Experiments used the Secure Water Treatment (SWaT) dataset under stochastic attack scenarios, focusing on the tank-level variable LIT301. The approach prevented five breaches (33.3%) versus LSTM (26.7%) and TCN (13.3%), with zero physically invalid (hallucinated) actions executed.\"}]",1784178613,25,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"neuro-agentic-control-a-deep-learning-based-llm-powered-agentic-ai-framework-for-controlling-security-controls","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/neuro-agentic-control-a-deep-learning-based-llm-powered-agentic-ai-framework-for-controlling-security-controls/82178/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the proposed framework address in industrial IoT security control?","Question",{"text":75,"@type":76},"It targets the safety limitations of traditional rule-based monitoring and the risk of LLM hallucinations in closed-loop control for operational technology, where incorrect actions can cause real process disruption and physical damage.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does “Counterfactual Physics Injection” work in the framework?",{"text":80,"@type":76},"It translates semantic actions proposed by the LLM into numerical perturbations of the foundation model’s recent historical window, simulating the action’s impact before any real actuation.",{"name":82,"@type":73,"acceptedAnswer":83},"How was the framework evaluated and what were the main results?",{"text":84,"@type":76},"Experiments used the Secure Water Treatment (SWaT) dataset under stochastic attack scenarios, focusing on the tank-level variable LIT301. The approach prevented five breaches (33.3%) versus LSTM (26.7%) and TCN (13.3%), with zero physically invalid (hallucinated) actions executed.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":21,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":21,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]