The authors built ALERT-BENCH, an interactive benchmark that replays enterprise telemetry (from AIT-LDSv2) through a live SIEM, requiring each system to retrieve evidence before triaging an alert.
Multi-agent adversarial review boosts LLM-based SOC alert triage accuracy
A new framework, AIDA, uses structured evidence retrieval and independent challenge to cut missed attacks from 40% to 3% while escalating 18% of alerts to analysts.
Big Tech
Saimon Amanuel Tsegai (Daphne) · Alex Kantchelian (Daphne) · Danfeng (Daphne) · Yao · Peng Gao
Research Digest··3 min read
4% of attack-related alerts.
Why this paper
From Google and 2 others
In one line
Structuring LLM agent evidence retrieval and adversarial review substantially improves SOC alert triage, raising F1 from at most 0.744 to 0.958.
What we could check
- ·No code link found
- ·No weights link found
- ·No dataset link found
- ·No compute details found
- ·No stated limitations found
- ✓Reports numbers on named benchmarks
Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.
§