Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study
2026-04-27T07:23:36Z•1f6e07a98e28ed5fd901446a69674f4e80df1bf4de25e812ef665a13b52ae2f1
CVE-CWE-mappingIoT-threat-modellingLLM-safetyNLP-privacy-policyRL-auditingSOCagent-architectureauditabilityblockchaincode-modelsdataset-poisoningexplainable-mlintrusion-detectionoffensive-securitypolicy-enforcementprivacysecurity-operationsside-channel-attacksvulnerability-management
What happened
Collection of recent arXiv papers (Apr 27, 2026) on security, privacy, and trustworthy ML/AI systems. Key contributions include: an empirical SOC study showing analysts make correct triage decisions in 83% of cases but provide correct justifications only 39%; a blockchain-anchored, tamper-evident fraud-detection system with cryptographically verifiable decision trails (F1=0.895, sub-25 ms inference, <$0.01/tx on L2); Sovereign Agentic Loops (SAL) architecture that emits structured intents and an Evidence Chain to prevent unsafe LLM-driven executions (blocks 93% of unsafe intents, adds ~12.4 ms
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_cr
- Record identifier
- 1f6e07a98e28ed5fd901446a69674f4e80df1bf4de25e812ef665a13b52ae2f1
- Enrichment time
- 2026-04-27T07:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.