Skip to main content

Lund University Publications

LUND UNIVERSITY LIBRARIES

Designing an AI-Assisted cyber threat intelligence framework for Industry 4.0 : a human-in-the-loop design science approach

Albarrak, Majed and Jagtap, Sandeep LU orcid (2026) In Applied Sciences (Switzerland) 16(15).
Abstract
The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit... (More)
The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate. Following a Design Science Research approach, the framework was evaluated through expert assessment involving twelve cybersecurity practitioners with experience in industrial and Security Operations Centre (SOC) environments and complemented by a proof-of-concept artefact instantiation based on the APT41 DUST campaign. The prototype integrated five heterogeneous CTI evidence sources and executed the automated analytical workflow in approximately 25 s (25.29 s) while illustrating evidence-grounded retrieval, specialized agent orchestration, and human-supervised intelligence generation. Practitioner feedback indicated that AI-assisted contextual intelligence and agent-based reasoning were perceived as valuable, while successful adoption depends primarily on governance, explainability, trust, and alignment with existing operational workflows rather than algorithmic sophistication alone. The study contributes a design-science artefact that combines retrieval-augmented intelligence, modular AI agents, and human oversight, providing practical design guidance for trustworthy AI-assisted CTI deployment in safety-critical Industry 4.0 environments. (Less)
Please use this url to cite or link to this publication:
author
and
organization
publishing date
type
Contribution to journal
publication status
published
subject
in
Applied Sciences (Switzerland)
volume
16
issue
15
article number
7646
pages
29 pages
publisher
MDPI AG
external identifiers
  • scopus:105047049029
ISSN
2076-3417
DOI
10.3390/app16157646
language
English
LU publication?
yes
id
c745638c-a8cb-41d6-a16a-aff31b10f14c
date added to LUP
2026-08-01 15:53:16
date last changed
2026-09-09 04:01:18
@article{c745638c-a8cb-41d6-a16a-aff31b10f14c,
  abstract     = {{The convergence of Information Technology (IT) and Operational Technology (OT) in Industry 4.0 has intensified the need for timely, trustworthy, and explainable cyber threat intelligence (CTI) for Industrial Control Systems (ICS). However, existing AI-enabled and Large Language Model (LLM)-based CTI solutions are predominantly designed for conventional IT environments and do not adequately address the safety, latency, governance, and operational constraints of industrial settings. This paper presents an AI-assisted CTI framework tailored to ICS and Industry 4.0 environments, integrating multi-source data ingestion, a Retrieval-Augmented Generation (RAG) knowledge store, a modular chain-of-agents architecture, and an explicit human-in-the-loop verification gate. Following a Design Science Research approach, the framework was evaluated through expert assessment involving twelve cybersecurity practitioners with experience in industrial and Security Operations Centre (SOC) environments and complemented by a proof-of-concept artefact instantiation based on the APT41 DUST campaign. The prototype integrated five heterogeneous CTI evidence sources and executed the automated analytical workflow in approximately 25 s (25.29 s) while illustrating evidence-grounded retrieval, specialized agent orchestration, and human-supervised intelligence generation. Practitioner feedback indicated that AI-assisted contextual intelligence and agent-based reasoning were perceived as valuable, while successful adoption depends primarily on governance, explainability, trust, and alignment with existing operational workflows rather than algorithmic sophistication alone. The study contributes a design-science artefact that combines retrieval-augmented intelligence, modular AI agents, and human oversight, providing practical design guidance for trustworthy AI-assisted CTI deployment in safety-critical Industry 4.0 environments.}},
  author       = {{Albarrak, Majed and Jagtap, Sandeep}},
  issn         = {{2076-3417}},
  language     = {{eng}},
  month        = {{08}},
  number       = {{15}},
  publisher    = {{MDPI AG}},
  series       = {{Applied Sciences (Switzerland)}},
  title        = {{Designing an AI-Assisted cyber threat intelligence framework for Industry 4.0 : a human-in-the-loop design science approach}},
  url          = {{https://lup.lub.lu.se/search/files/256954259/applsci-16-07646.pdf}},
  doi          = {{10.3390/app16157646}},
  volume       = {{16}},
  year         = {{2026}},
}