Research & Papers

Neuro-Agentic Control Framework Uses LLM + Time-Series Model to Secure Critical Infrastructure

Zero hallucinated actions executed in industrial IoT security tests

Deep Dive

Cyberattacks on operational technology (OT) are causing costly downtime and physical damage, exposing the limits of traditional rule-based monitoring. To address this, researchers from Texas Tech University propose a neuro-agentic control framework that pairs an LLM-based planner, Gemini 2.5 Flash-Lite, with a pre-trained Time-Series Foundation Model (TimesFM) from Google. The core innovation is 'Counterfactual Physics Injection': before executing any LLM-proposed intervention, the system simulates its impact within the numerical latent space of TimesFM. This allows the framework to reject hallucinatory or physically unsafe actions, ensuring safety in closed-loop autonomous defense. The LLM handles high-level semantic reasoning about threats, while the foundation model grounds decisions in real physics.

The framework was evaluated on the public Secure Water Treatment (SWaT) dataset under stochastic cyberattack scenarios. Results show the Neuro-Agentic Loop prevented 33.3% of breaches below a critical threshold, compared to 26.7% for LSTM and 13.3% for TCN baselines. Most importantly, zero physically invalid (hallucinated) actions were executed, solving a key safety liability of using LLMs in critical infrastructure. The authors frame this as using foundation models as deterministic 'Sentinels' to safeguard agentic AI. This work demonstrates a practical path to autonomous defense for power plants, water systems, and other industrial environments where mistakes can cause real-world damage.

Key Points
  • Couples Gemini 2.5 Flash-Lite LLM with Google's TimesFM time-series foundation model for physics-grounded defense
  • Counterfactual Physics Injection simulates interventions in latent space, rejecting hallucinated unsafe actions before execution
  • On SWaT dataset, framework prevented 33.3% of critical breaches with zero hallucination-induced failures

Why It Matters

Enables safe autonomous defense for power plants, water systems, and other critical OT infrastructure.

📬 Get the top 10 AI stories daily