Skip to content
Cyber Science Lab

Unlocking Security Insights Through Log Analysis in LLM-Powered Applications

A secure, end-to-end threat-intelligence pipeline turning raw LLM invocation logs into real-time, graph-aware defenses for Canadian security-operations centres.

2025–2027Natural Sciences and Engineering Research Council of Canada (NSERC)PI: Dr. Fattane Zarrinkalam · Co-Applicant: Dr. Ali Dehghantanha

This project aims to develop a secure, end-to-end threat-intelligence pipeline that transforms raw LLM invocation logs into real-time, graph-aware defenses for deployment in Canadian security-operations centres (SOCs). It unfolds across four main objectives: (1) secure ingestion and hybrid parsing of unstructured logs; (2) real-time anomaly detection and interactive dashboards; (3) development of an ontology of LLM-specific threats, and training of graph-based classifiers; and (4) system-wide evaluation using red-team self-play and deployment-ready continuous integration/continuous deployment (CI/CD) tools.

Related publications