From Detection to Attribution: Forensic Linguistics and Adversarial Red Teaming as Complementary Responses to LLM Misuse Rui Sousa-Silva, in a paper presented at the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security (NLPAICS) in Alicante, Spain, in June 2026, found that forensic linguistic analysis based on idiolect theory can distinguish genuine authorship from LLM-generated impersonation even when surface features are manipulated, though stylometric methods alone fall short of legal admissibility standards. The study used red teaming to generate synthetic toxic texts and found moderate evidence for stylometric authorship discrimination, concluding that interpretable, theory-based analysis is needed over black-box classifiers in legal contexts. Abstract The proliferation of Large Language Models LLMs has enabled the automation of cyber-attacks including phishing, social engineering, and impersonation at unprecedented scale, while existing safeguards remain routinely circumvented. Current detection approaches, predominantly based on stylometric and machine learning methods, face fundamental limitations against adaptive adversaries and struggle with the implicit, contextual, and pragmatic dimensions of language. This article proposes forensic linguistic analysis grounded in the theory of idiolect as a complementary approach to LLM-generated text detection and attribution. We adopt a red teaming methodology to generate synthetic toxic texts that bypass model guardrails to create controlled conditions for testing whether qualitative forensic analysis can succeed where quantitative approaches falter. The findings of our stylometric, character n-gram, and cluster analysis converge to provide moderate evidence that stylometric approaches succeed in discriminating authorship. However, they are not conclusive and hence fall short of current admissibility criteria across diverse jurisdictions. The article thus concludes that idiolect-based forensic analysis can distinguish genuine authorship from LLM-generated impersonation, even when surface features are manipulated. We discuss implications for legal and investigative contexts, where interpretable, theoretically-grounded expert analysis is required over black-box classifier outputs.- Anthology ID: - 2026.nlpaics-1.13 - Volume: Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security /volumes/2026.nlpaics-1/ - Month: - June - Year: - 2026 - Address: - Alicante, Spain - Editors: Ruslan Mitkov /people/ruslan-mitkov/ , Rafael Muñoz /people/rafael-munoz/ , Elena Lloret /people/elena-lloret/unverified/ , Tharindu Ranasinghe /people/tharindu-ranasinghe/ , Ernesto L. Estevanell-Valladares /people/ernesto-luis-estevanell-valladares/ , Salima Lamsiyah /people/salima-lamsiyah/unverified/ , Andrés Montoyo /people/andres-montoyo/ , Saad Ezzini /people/saad-ezzini/ - Venue: NLPAICS /venues/nlpaics/ - SIG: - Publisher: - Department of Languages and Information Systems, University of Alicante - Note: - Pages: - 122–133 - Language: - URL: https://aclanthology.org/2026.nlpaics-1.13/ https://aclanthology.org/2026.nlpaics-1.13/ - DOI: - Cite ACL : - Rui Sousa-Silva. 2026. From Detection to Attribution: Forensic Linguistics and Adversarial Red Teaming as Complementary Responses to LLM Misuse https://aclanthology.org/2026.nlpaics-1.13/ . In Proceedings of the Second International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security , pages 122–133, Alicante, Spain. Department of Languages and Information Systems, University of Alicante. - Cite Informal : From Detection to Attribution: Forensic Linguistics and Adversarial Red Teaming as Complementary Responses to LLM Misuse https://aclanthology.org/2026.nlpaics-1.13/ Sousa-Silva, NLPAICS 2026 - PDF: https://aclanthology.org/2026.nlpaics-1.13.pdf https://aclanthology.org/2026.nlpaics-1.13.pdf