Detecting Cryptographically Relevant Software Packages with Collaborative LLMs

๐Ÿ“… 2026-03-07
๐Ÿ›๏ธ Proceedings of the 12th International Conference on Information Systems Security and Privacy
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This work addresses the critical challenge of efficiently identifying cryptography-related software packages in heterogeneous IT environmentsโ€”a key prerequisite for achieving cryptographic agility and enabling migration to post-quantum cryptography (PQC). The authors propose an automated preliminary screening framework that leverages locally deployed large language models (LLMs) in a collaborative manner. By aggregating predictions from multiple LLMs on package metadata through a majority voting mechanism, the approach enhances generalization and reliability across diverse software ecosystems while preserving data privacy. Experimental evaluation on over 65,000 Fedora packages demonstrates that the method substantially reduces manual auditing effort, offering a scalable and efficient tool for cryptographic asset discovery to support PQC transition initiatives.

Technology Category

Application Category

๐Ÿ“ Abstract
IT systems are facing an increasing number of security threats, including advanced persistent attacks and future quantum-computing vulnerabilities. The move towards crypto-agility and post-quantum cryptography (PQC) requires a reliable inventory of cryptographic assets across heterogeneous IT environments. Due to the sheer amount of packets, it is infeasible to manually detect cryptographically relevant software. Further, static code analysis pipelines often fail to address the diversity of modern ecosystems. Our research explores the use of large language models (LLMs) as heuristic tools for cryptographic asset discovery. We propose a collaborative framework that employs multiple LLMs to assess software relevance and aggregates their outputs through majority voting. To preserve data privacy, the approach operates on-premises without reliance on external servers. Using over 65,000 Fedora Linux packages, we evaluate the reliability of this method through statistical analysis, inter-model agreement, and manual validation. Preliminary results suggest that~LLM ensembles can serve as an efficient first-pass filter for identifying cryptographic software, resulting in reduced manual workload and assisting PQC transition. The study also compares on-premises and online LLM configurations, highlighting key advantages, limitations, and future directions for automated cryptographic asset discovery.
Problem

Research questions and friction points this paper is trying to address.

cryptographic asset discovery
crypto-agility
post-quantum cryptography
software package identification
IT security
Innovation

Methods, ideas, or system contributions that make the work stand out.

collaborative LLMs
cryptographic asset discovery
on-premises inference
post-quantum cryptography
majority voting
๐Ÿ’ผ Related Jobs
No related jobs found.
E
Eduard Hirsch
Ostbayerische Technische Hochschule (OTH), Amberg 92224, Germany
K
Kristina Raab
Fraunhofer AISEC, Garching 85748, Germany
T
Tobias J. Bauer
Fraunhofer AISEC, Garching 85748, Germany
D
Daniel Loebenberger
Fraunhofer AISEC, Garching 85748, Germany