KSKS Security Research
Learning map / Session 1 / Scenes 03–04

FOUNDATION 01 · THE MODEL

Prediction creates language.Evidence creates trust.

Understand what an LLM actually does, how context shapes a response, and why confident language is not the same as verified knowledge.

LLMtokenscontextgrounding
Learning guide
Level
Start here
Reading time
8 min
Presentation
Session 1
Progress
2 of 8

01 · Mental model

An LLM predicts a useful continuation

A large language model receives tokens representing the current context and estimates which tokens are useful to produce next. The result can be fluent, structured, and surprisingly capable without being a database lookup or a proof engine.

For cybersecurity work, separate three questions: what the model can infer, what evidence the application supplied, and what the control plane allows the system to do. A persuasive answer may still be unsupported; a grounded answer should carry inspectable evidence.

02 · Visual explanation

01Contextinstructions + data
02Tokensmodel representation
03Predictionnext-token probabilities
04Responsegenerated language
05Validationevidence + policy
From context to an answerThe model transforms supplied context into a continuation; validation happens outside that prediction step.

03 · Compare and decide

Fluent is not the same as grounded

Decision lensModel capabilitySystem assurance
Answer generationProduces a plausible continuationChecks the answer against trusted evidence
KnowledgePatterns learned plus current contextApproved sources, freshness, and citations
ConfidenceMay sound certainUses explicit uncertainty and verification
SecurityCan interpret untrusted textKeeps untrusted text outside the authority boundary

04 · Cybersecurity example

SOC example: explain an unfamiliar alert

An analyst pastes an alert payload and asks for a likely explanation.

01

The model interprets entities and sequence.

02

Retrieval supplies the current product documentation.

03

A tool checks asset and identity context.

04

The analyst validates the conclusion before action.

Outcome: The LLM accelerates interpretation; evidence and the analyst own the decision.

05 · What to remember

The 60-second recall

01

An LLM generates; it does not automatically verify.

02

Context quality changes the answer, not the model weights.

03

Grounding, policy, and review belong to the surrounding system.

Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.

06 · Questions people ask

FAQ

No. A model only receives internet or enterprise information when the application explicitly supplies it through retrieval, browsing, or tools.

07 · Primary sources

Continue with authoritative guidance