From Hardware to Semantic Intelligence: LLM-Enhanced Ontology Engineering and Agentic Maintenance for Explainable Cybersecurity
This paper presents an LLM-enhanced ontology framework for explainable hardware-assisted cybersecurity in IoT/IoMT systems. The proposed framework integrates processor-level hardware features, including hardware performance counters (HPCs), device metadata, and CVE/CWE knowledge to support reasoning-driven malware detection and vulnerability contextualization. A hybrid human-LLM ontology engineering workflow is introduced to enhance ontology construction and refinement while preserving semantic consistency and reasoning quality. Using a top-2 AND SWRL rule over normalized HPC features, the proposed ontology achieves nearly 85% malware classification accuracy while linking anomalous readings to relevant vulnerabilities and device-context concepts. To support continuously evolving cybersecurity knowledge, we further introduce an Agentic Ontology Maintenance (AOM) framework that updates the ontology in response to newly disclosed vulnerabilities and hardware features threshold drift through a three-agent ReAct architecture with retrieval-augmented generation and automated validation. Results demonstrate that LLM-assisted ontology engineering enhances semantic reasoning and explainability, while AOM preserves logical consistency, competency-question coverage, and semantic quality across the evaluated maintenance scenarios.
Authors
- Zhangying He (ORCID: https://orcid.org/0000-0002-5072-2955)
- Hossein Sayadi (ORCID: https://orcid.org/0000-0001-6423-0145)
- Thrity Golzari
Publication Details
- Journal
- International Journal of Semantic Computing
- Published
- 2026-09-25
- DOI
- https://doi.org/10.1142/s1793351x26450078
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00