Get Started
Home
Topics
Search
Library
Research questionHow can LLM-based SOC agents reason over large authentication graphs while keeping containment actions topology-consistent?Enterprise authentication graphs can contain millions of relationships, exceeding an LLM’s context window. Free-form recommendations may also conflict with the relationships represented in the graph, making investigations and containment unreliable.
AI
AI Agents
Reasoning
Reinforcement Learning
Research Paper
Technology
Latest papersRecent research connected to this question, newest first.SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations CenterThe evidence concerns the Sentinel-RL SOC architecture, evaluated with the LANL Comprehensive Multi-Source Cyber-Security Events dataset and the Indiana University Quartz HPC cluster. It uses graph-based state encoding, constrained policy-selected actions, LLM-generated analyst narratives, critic gating, and human approval; reported evidence is limited to the described datasets, environments, and metrics.research paper · Sep 3, 2026
Related questions
How can composable LLM agents preserve authorization and provenance across component boundaries before external effects?How can autonomous LLM agents detect attacks whose evidence accumulates across loop iterations?How can LLM agents stay safe during multi-step execution when both policy and runtime harness shape behavior?How can LLM-agent systems prevent safety compromises from propagating across workflow boundaries?