Large Language Models in Cybersecurity: A PRISMA-ScR-Guided Scoping Review of Threats, Defenses, and Emerging Applications
Abstract
Large Language Models (LLMs) have rapidly evolved into powerful general-purpose systems with advanced natural language processing, code generation, and reasoning capabilities, leading to their increasing adoption in cybersecurity. However, their dual-use nature introduces both significant defensive opportunities and emerging offensive threats. This study presents a PRISMA-ScR-guided scoping review to systematically map the current landscape of LLM applications in cybersecurity, addressing their roles as both threat enablers and defensive tools while identifying key governance challenges and future research directions. Literature published between January 2017 and December 2024 was identified through structured searches of IEEE Xplore, ACM Digital Library, Scopus, Web of Science, and arXiv, supplemented by grey literature and citation snowballing. Studies were screened using predefined inclusion and exclusion criteria, and relevant information was extracted using a standardized data-charting framework followed by thematic narrative synthesis. The review synthesizes evidence from 153 eligible studies, demonstrating that LLMs substantially enhance offensive capabilities such as phishing, malware generation, vulnerability discovery, and adversarial attacks, while simultaneously improving defensive functions including threat detection, vulnerability management, incident response, security automation, and analyst support. The review further identifies critical limitations related to hallucinations, model reliability, privacy, misuse, and governance, highlighting the need for trustworthy deployment frameworks, standardized evaluation benchmarks, and robust regulatory safeguards. By integrating evidence across technical, operational, and governance perspectives, this scoping review provides a comprehensive evidence-based synthesis of the evolving role of LLMs in cybersecurity and outlines priorities for future research and responsible deployment.