Cyberdefense and LLMs in the Global South: governance, vulnerabilities, autonomy

Authors

DOI:

https://doi.org/10.5902/2357797597309

Keywords:

LLMs, Cyber defense, Strategic autonomy, Technological dependence, Global South

Abstract

This article investigates the extent to which the adoption of Large Language Models (LLMs) in cyber defense routines, particularly when consumed as a cloud service and integrated into sensitive data flows, amplifies vulnerabilities and compromises the strategic autonomy of Global South countries. It is argued that the structural dependence on proprietary LLMs and centralized cloud infrastructure creates three interconnected orders of risk: technical-operational (vulnerabilities in LLM-integrated systems), legal-institutional (issues of jurisdiction, data governance, and auditing in uncontrolled environments), and geopolitical-structural (conditioning or denial of access in crisis scenarios). Employing an analytical framework that combines technological dependence, digital sovereignty, and coloniality, alongside artifacts such as vulnerability matrices, the study corroborates the hypothesis that opacity, audit asymmetry, and the concentration of digital infrastructure exacerbate these risks. It concludes that the modernization of cyber defense in the Global South requires autonomy to be operationalized into objective governance requirements—such as auditability, update control, and access to logs—to prevent LLM adoption from translating into opaque operational dependence.

Downloads

Download data is not yet available.

Author Biographies

Onildo Ribeiro de Assis II, Universidade do Tocantins

Analista de Sistemas; Administrador; Professor, Universidade do Tocantins, Paraíso, TO, Brasil.

Ana Isabella Bezerra Lau Ribeiro, Universidade do Tocantins

Advogada; Mestre pela Universidade Federal da Paraíba; Professora, Universidade do Tocantins, Paraíso, TO, Brasil.

References

ACHARYA, Amitav. The End of American World Order. Cambridge: Polity Press, 2014.

BIGGIO, Battista; NELSON, Blaine; LASKOV, Klaus. Poisoning attacks against support vector machines. In: INTERNATIONAL CONFERENCE ON MACHINE LEARNING, 29., 2012, Edinburgh. Proceedings… New York: ACM, 2012. p. 1467-1474. Disponível em: https://dl.acm.org/doi/10.5555/3042573.3042724. Acesso em: 22 jun. 2026.

BIGGIO, Battista; ROLI, Fabio. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, Amsterdam, v. 84, p. 317-331, 2018. Disponível em: https://doi.org/10.1016/j.patcog.2018.07.023. Acesso em: 16 jun. 2026.

BRASIL. Decreto nº 12.573, de 4 de agosto de 2025. Institui a Estratégia Nacional de Cibersegurança. Diário Oficial da União: seção 1, Brasília, DF, 5 ago. 2025a. Disponível em: https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12573.htm. Acesso em: 18 jun. 2026.

BRASIL. Decreto nº 12.725, de 18 de novembro de 2025. Aprova a Política Nacional de Defesa, a Estratégia Nacional de Defesa e o Livro Branco de Defesa Nacional. Diário Oficial da União: seção 1, Brasília, DF, 18 nov. 2025b. Disponível em: https://www.planalto.gov.br/ccivil_03/_ ato2023-2026/2025/decreto/D12725.htm. Acesso em: 16 jun. 2026.

BRASIL. Lei nº 13.709, de 14 de agosto de 2018. Lei Geral de Proteção de Dados Pessoais (LGPD). Diário Oficial da União: seção 1, Brasília, DF, 15 ago. 2018. Disponível em: https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709.htm. Acesso em: 22 jun. 2026.

BRASIL. Ministério da Defesa. Doutrina Militar de Defesa: DMiD (MD51-M-04). 3. ed. Brasília, DF: Ministério da Defesa, 2025. Disponível em: https://www.gov.br/defesa/pt-br/assuntos/estado-maior-conjunto-das-forcas-armadas/doutrina-militar/publicacoes-1/publicacoes/md51-m-04-doutrina-militar-de-defesa-dmid-3a-ed-2025.pdf. Acesso em: 18 jun. 2026.

BRASIL. Ministério da Defesa. Livro Branco de Defesa Nacional. Brasília, DF: Ministério da Defesa, 2020b. Disponível em: https://www.gov.br/defesa/pt-br/assuntos/copy_of_estado-e-defesa/livro_branco_congresso_nacional.pdf. Acesso em: 05 jun. 2026.

BRASIL. Ministério da Defesa. Política Nacional de Defesa e Estratégia Nacional de Defesa. Brasília, DF: Ministério da Defesa, 2020a. Disponível em: https://www.gov.br/defesa/pt-br/assuntos/copy_of_estado-e-defesa/pnd_end_congressonacional_22_07_2020.pdf. Acesso em: 18 jun. 2026.

BURRELL, Jenna. How the machine ‘thinks’: Understanding opacity in machine learning algorithms. Big Data & Society, v. 3, n. 1, p. 1-12, 2016. Disponível em: https://doi. org/10.1177/2053951715622512. Acesso em: 17 jun. 2026.

CARDOSO, Fernando Henrique; FALETTO, Enzo. Dependência e desenvolvimento na América Latina: ensaio de interpretação sociológica. 2. ed. Rio de Janeiro: Zahar Editores, 1979.

CARLINI, Nicholas et al. Extracting Training Data from Large Language Models. In: USENIX SECURITY SYMPOSIUM, 30., 2021, Vancouver. Proceedings… Berkeley, CA: USENIX Association, 2021. Disponível em: https://www.usenix.org/conference/usenixsecurity21/presentation/carlini-extracting. Acesso em: 18 jun. 2026.

COULDRY, Nick; MEJIAS, Ulises A. The Costs of Connection: How Data Is Colonizing Human Life and Appropriating It for Capitalism. Stanford: Stanford University Press, 2019.

DOS SANTOS, Theotonio. The Structure of Dependence. The American Economic Review, Nashville, v. 60, n. 2, p. 231-236, 1970.

ESTADOS UNIDOS. Department of the Army. U.S. Army Training and Doctrine Command. TRADOC Pamphlet 525-3-1: The U.S. Army in Multi-Domain Operations 2028. Fort Eustis, VA: TRADOC, 2018. Disponível em: https://adminpubs.tradoc.army.mil/pamphlets/TP525-3-1.pdf. Acesso em: 02 jun. 2026.

ESTADOS UNIDOS. Department of Defense. Summary of the Joint All-Domain Command and Control (JADC2) Strategy. Washington, DC: DoD, 2022. Disponível em: https://media. defense.gov/2022/Mar/17/2002958406/-1/-1/1/SUMMARY-OF-THE-JOINT-ALL-DOMAIN-COMMAND-AND-CONTROL-STRATEGY.PDF. Acesso em: 18 jun. 2026.

FARRELL, Joseph; KLEMPERER, Paul. Coordination and Lock-In. In: ARMSTRONG, Mark; PORTER, Robert H. (ed.). Handbook of Industrial Organization. Amsterdam: Elsevier, 2007. v. 3, cap. 31, p. 1973-2025.

GEBRU, Timnit et al. Datasheets for Datasets. arXiv preprint arXiv:1803.09010, 2018. Disponível em: https://arxiv.org/abs/1803.09010. Acesso em: 02 jun. 2026.

GRESHAKE, Kai et al. Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. arXiv, 2023. Disponível em: https://arxiv.org/abs/2302.12173. Acesso em: 05 jun. 2026.

ISSMAEL JÚNIOR, Ali Kamel. Operações Multidomínio (MDO) no Sul Global: modelo mínimo viável para C2 e dados. InterAção, Santa Maria, v. 17, n. 2, e95275, p. 1-24, jun. 2026. DOI: https://doi.org/10.5902/2357797595275. Acesso em: 10 jun. 2026.

MITCHELL, Margaret et al. Model Cards for Model Reporting. In: CONFERENCE ON FAIRNESS, ACCOUNTABILITY, AND TRANSPARENCY, 2019, Atlanta. Proceedings… New York: ACM, 2019. p. 220-229. Disponível em: https://dl.acm.org/doi/10.1145/3287560.3287596. Acesso em: 05 jun. 2026.

NEIVA FILHO, Ivan Ferreira; SILVA, Karen Cristina Leal da. Base Industrial de Defesa Brasileira: vetor estruturante da soberania, da inovação tecnológica e do aumento da competitividade industrial. InterAção, Santa Maria, v. 17, n. 2, e96176, p. 1-30, jun. 2026. DOI: https://doi. org/10.5902/2357797596176. Acesso em: 09 jun. 2026.

NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0). Gaithersburg, MD: National Institute of Standards and Technology, 2023. Disponível em: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf. Acesso em: 08 jun. 2026.

NIST. Computer Security Incident Handling Guide (SP 800-61 Rev. 2). Gaithersburg, MD: National Institute of Standards and Technology, 2012. Disponível em: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf. Acesso em: 18 jun. 2026.

NIST. Contingency Planning Guide for Federal Information Systems (SP 800-34 Rev. 1). Gaithersburg, MD: National Institute of Standards and Technology, 2010. Disponível em: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf. Acesso em: 11 jun. 2026.

NIST. Guide to Computer Security Log Management (SP 800-92). Gaithersburg, MD: National Institute of Standards and Technology, 2006. Disponível em: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf. Acesso em: 18 jun. 2026.

NIST. Guide to Industrial Control Systems (ICS) Security (SP 800-82 Rev. 2). Gaithersburg, MD: National Institute of Standards and Technology, 2015. Disponível em: https://nvlpubs.nist. gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf. Acesso em: 22 jun. 2026.

NIST. Managing Information Security Risk: Organization, Mission, and Information System View (SP 800-39). Gaithersburg, MD: National Institute of Standards and Technology, 2013. Disponível em: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf. Acesso em: 22 jun. 2026.

NIST. Secure Software Development Framework (SSDF) Version 1.1 (SP 800-218). Gaithersburg, MD: National Institute of Standards and Technology, 2022. Disponível em: https://csrc.nist.gov/pubs/sp/800/218/final. Acesso em: 10 jun. 2026.

ORGANIZAÇÃO DO TRATADO DO ATLÂNTICO NORTE (OTAN). AJP-3.10: Allied Joint Doctrine for Electronic Warfare. Bruxelas: OTAN, 2015. Disponível em: https://mpsotc.army.gr/wp-content/uploads/2024/03/2.-AJP-3.10-EDA-V1-E.pdf. Acesso em: 18 jun. 2026.

ORGANIZAÇÃO DO TRATADO DO ATLÂNTICO NORTE (OTAN). AJP-3.20: Allied Joint Doctrine for Cyberspace Operations. Bruxelas: OTAN, 2018. Disponível em: https://iwar.org.uk/wp-content/uploads/2021/06/AJP-3.20-EDA-V1-E.pdf. Acesso em: 10 jun. 2026.

OWASP. OWASP Top 10 for Large Language Model Applications. OWASP Foundation, 2024. Disponível em: https://owasp.org/www-project-top-10-for-large-language-model-applications/. Acesso em: 02 jun. 2026.

PASQUALE, Frank. The Black Box Society: The Secret Algorithms That Control Money and Information. Cambridge, MA: Harvard University Press, 2015.

POCHMANN, Pablo Gustavo Cogo. A revolução da simulação construtiva no Sul Global: comparativo do uso do software SWORD. InterAção, Santa Maria, v. 17, n. 2, e96435, p. 1-15, jun. 2026. DOI: https://doi.org/10.5902/2357797596435. Acesso em: 18 jun. 2026.

PREBISCH, Raúl. The Economic Development of Latin America and Its Principal Problems. New York: United Nations, 1950. Disponível em: https://repositorio.cepal.org/handle/11362/29973. Acesso em: 18 jun. 2026.

QUIJANO, Aníbal. Coloniality of Power, Eurocentrism, and Latin America. Nepantla: Views from South, Durham, v. 1, n. 3, p. 533-580, 2000. Disponível em: https://doi.org/10.1215/15314201-1-3-533. Acesso em: 09 jun. 2026.

SHOKRI, Reza et al. Membership Inference Attacks Against Machine Learning Models. In: IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 38., 2017, San Jose. Proceedings… Piscataway, NJ: IEEE, 2017. p. 3-18. Disponível em: https://ieeexplore.ieee.org/document/7958568. Acesso em: 22 jun. 2026.

STEINHARDT, Jacob; KOH, Pang Wei; LIANG, Percy. Certified defenses for data poisoning attacks. In: ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS (NEURIPS), 2017. Proceedings… 2017. Disponível em: https://arxiv.org/abs/1706.03691. Acesso em: 18 jun. 2026.

TOUVRON, Hugo et al. Llama 2: Open Foundation and Fine-Tuned Chat Models. arXiv preprint arXiv:2307.09288, 2023. Disponível em: https://arxiv.org/abs/2307.09288. Acesso em: 22 jun. 2026.

TRAMÈR, Florian et al. Stealing Machine Learning Models via Prediction APIs. In: USENIX SECURITY SYMPOSIUM, 25., 2016, Austin. Proceedings… Berkeley, CA: USENIX Association, 2016. p. 601-614. Disponível em: https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/tramer. Acesso em: 22 jun. 2026.

UNCTAD. Digital Economy Report 2021: Cross-border Data Flows and Development: For whom the data flow. Geneva: United Nations Conference on Trade and Development, 2021. Disponível em: https://unctad.org/publication/digital-economy-report-2021. Acesso em: 18 jun. 2026.

UNITED STATES. Clarifying Lawful Overseas Use of Data Act (CLOUD Act). Washington, DC: U.S. Congress, 2018. Disponível em: https://www.congress.gov/bill/115th-congress/house-bill/4943. Acesso em: 20 jun. 2026.

ZOU, Andy et al. Universal and Transferable Adversarial Attacks on Aligned Language Models. arXiv preprint arXiv:2307.15043, 2023. Disponível em: https://arxiv.org/abs/2307.15043. Acesso em: 22 jun. 2026.

Published

2026-10-02