Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study

2026-04-27T07:23:36Z1f6e07a98e28ed5fd901446a69674f4e80df1bf4de25e812ef665a13b52ae2f1
CVE-CWE-mappingIoT-threat-modellingLLM-safetyNLP-privacy-policyRL-auditingSOCagent-architectureauditabilityblockchaincode-modelsdataset-poisoningexplainable-mlintrusion-detectionoffensive-securitypolicy-enforcementprivacysecurity-operationsside-channel-attacksvulnerability-management

What happened

Collection of recent arXiv papers (Apr 27, 2026) on security, privacy, and trustworthy ML/AI systems. Key contributions include: an empirical SOC study showing analysts make correct triage decisions in 83% of cases but provide correct justifications only 39%; a blockchain-anchored, tamper-evident fraud-detection system with cryptographically verifiable decision trails (F1=0.895, sub-25 ms inference, <$0.01/tx on L2); Sovereign Agentic Loops (SAL) architecture that emits structured intents and an Evidence Chain to prevent unsafe LLM-driven executions (blocks 93% of unsafe intents, adds ~12.4 ms

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_cr
Record identifier
1f6e07a98e28ed5fd901446a69674f4e80df1bf4de25e812ef665a13b52ae2f1
Enrichment time
2026-04-27T07:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.