Análisis del uso de herramientas basadas en Procesamiento del lenguaje natural (NLP) y Grandes modelos de lenguaje (LLM) en la reducción de complejidad técnica de ciberataques ejecutados por actores con conocimientos limitados
DOI:
https://doi.org/10.69639/arandu.v13i3.2533Palabras clave:
inteligencia artificial, procesamiento de lenguaje natural, modelos de lenguaje de gran escala, ciberataques, phishingResumen
El avance de las tecnologías basadas en inteligencia artificial y de los modelos de Natural Language Processing (NLP) y Large Language Models (LLM), han generado oportunidades y desafíos en el ámbito de la ciberseguridad, sobre todo en su utilización con fines ofensivos. El objetivo de esta investigación es analizar como los modelos NLP y LLM están siendo usados como herramientas en actividades ofensivas y determinar su impacto en la reducción de la complejidad técnica para le ejecución de ciberataques. Para el estudio se desarrolló una revisión sistemática de literatura mediante la recopilación y análisis de artículos científicos publicados entre 2023 y 2026. Los resultados evidenciaron el uso de modelos GPT, LLaMA, Gemini, Claude y DeepSeek en actividades ofensiva, se identificó que estas tecnologías reducen significativamente la barrear técnica para ejecutar determinadas actividades ofensivas, incrementado la automatización, personalización y escalabilidad. El estudio llega a tener conclusiones muy acetadas sobre el trasfondo de uso de NLP y LLM y como estas están transformando el panorama de la ciberseguridad ofensiva facilitando las capacidades avanzadas de ataque para el uso de actores con conocimientos limitados.
Descargas
Citas
Albarrak, M., Salonitis, K., & Jagtap, S. (2026). Natural Language Processing (NLP)-Based Frameworks for Cyber Threat Intelligence and Early Prediction of Cyberattacks in Industry 4.0: A Systematic Literature Review. Applied Sciences, 16(2), 619. https://doi.org/10.3390/app16020619
Alqahtani, H., & Kumar, G. (2026). Large Language Models for Cybersecurity Intelligence: A Systematic Review of Emerging Threats, Defensive Capabilities, and Security Evaluation Frameworks. Computers, Materials & Continua, 87(3). https://doi.org/10.32604/cmc.2026.077367
Anis, F., & Hammoudeh, M. (2025). Weaponizing AI in Cyberattacks A Comparative Study of AI powered Tools for Offensive Security. Proceedings of the 8th International Conference on Future Networks & Distributed Systems, ICFNDS ’24, 283–290. https://doi.org/10.1145/3726122.3726164
Czaja, P., Gdowski, B., Niemiec, M., Mees, W., Stoianov, N., Votis, K., Kharchenko, V., Katos, V., & Merialdo, M. (2025). Cybersecurity challenges and opportunities of machine learning-based artificial intelligence. Neural Computing and Applications, 37(33), 27931–27956. https://doi.org/10.1007/s00521-025-11604-9
El yagouby, M. A., Lahmadi, A., Zakroum, M., Festor, O., & Ghogho, M. (2026). LLM-CVX: A Benchmarking Framework for Assessing the Offensive Potential of LLMs in Exploiting CVEs. Proceedings of the 18th ACM Workshop on Artificial Intelligence and Security, AISec ’25, 194–205. https://doi.org/10.1145/3733799.3762978
Happe, A., Kaplan, A., & Cito, J. (2026). LLMs as Hackers: Autonomous Linux Privilege Escalation Attacks. Empirical Software Engineering, 31(3), 70. https://doi.org/10.1007/s10664-025-10758-3
Isozaki, I., Shrestha, M., Console, R., & Kim, E. (2025). Towards Automated Penetration Testing: Introducing LLM Benchmark, Analysis, and Improvements. Adjunct Proceedings of the 33rd ACM Conference on User Modeling, Adaptation and Personalization, UMAP Adjunct ’25, 404–419. https://doi.org/10.1145/3708319.3733804
Jiménez, C. B. (2025). Inteligencia Artificial y Cibercrimen: Amenazas cibernéticas contemporáneas. Estudios en Seguridad y Defensa, 20(40), 199–220. https://doi.org/10.25062/1900-8325.5074
Jones, G., Kasimatis, D., Pitropakis, N., Macfarlane, R., & Buchanan, W. J. (2025). Analysing the role of LLMs in cybersecurity incident management. International Journal of Information Security, 24(6), 228. https://doi.org/10.1007/s10207-025-01144-7
Landeta-López, P., García, J. M., Guevara-Vega, C., & Ruiz-Cortés, A. (2026). LLMs applied to web scraping and web crawling: A systematic review. Computing, 108(6), 78. https://doi.org/10.1007/s00607-026-01666-5
Sivaneswaran, D., Hewage, C. T. E. R., Herath, H. M. K. K. M. B., Rathore, R. S., Singh, V. K., & Jiang, W. (2026). A systematic literature review of large language models in phishing attack generation and detection. Array, 30, 100775. https://doi.org/10.1016/j.array.2026.100775
Webb, J., Abri, F., & Akther, S. (2025). Synthetic Social Engineering Scenario Generation Using LLMs for Awareness-Based Attack Resilience. IEEE Access, 13, 174831–174856. https://doi.org/10.1109/ACCESS.2025.3614550
Weinz, M., Zannone, N., Allodi, L., & Apruzzese, G. (2025). The Impact of Emerging Phishing Threats: Assessing Quishing and LLM-generated Phishing Emails against Organizations. Proceedings of the 20th ACM Asia Conference on Computer and Communications Security, ASIA CCS ’25, 1550–1566. https://doi.org/10.1145/3708821.3736195
Wondimu, H., Alfatemi, A., Rahouti, M., Chehri, A., Weichbroth, P., & Ghani, N. (2025). Enabling Real-Time, Explainable DDoS Mitigation via On-Premise Large Language Models and Flow Analysis. Procedia Computer Science, 270, 1390–1399. https://doi.org/10.1016/j.procs.2025.09.260
Yigit, Y., Buchanan, W. J., Tehrani, M. G., & Maglaras, L. (2025). Review of Generative AI methods in cybersecurity. Internet of Things and Cyber-Physical Systems, 5, 241–261. https://doi.org/10.1016/j.iotcps.2026.04.001
Publicado
Cómo citar
Número
Sección
Licencia
Derechos de autor 2026 Cristhian Oswaldo Vera Segarra, Juan Joel Caillagua Taco, Elian Ricardo Farinango Cevallos

Esta obra está bajo una licencia internacional Creative Commons Atribución 4.0.














