Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study

arXiv 2604.22001•1f6e07a98e28ed5fd901446a69674f4e80df1bf4de25e812ef665a13b52ae2f1
CVE-CWE-mappingIoT-threat-modellingLLM-safetyNLP-privacy-policyRL-auditingSOCagent-architectureauditabilityblockchaincode-modelsdataset-poisoningexplainable-mlintrusion-detectionoffensive-securitypolicy-enforcementprivacysecurity-operationsside-channel-attacksvulnerability-management

Paper metadata

arXiv ID
2604.22001
Version
Not specified by this published record
Category
Computer Science — Cryptography and Security (cs.CR)

The PDF link points to arxiv.org. Baitaphish does not expose a private stored PDF.

Evidence and limitations

Source ID
arxiv_cs_cr
Record identifier
1f6e07a98e28ed5fd901446a69674f4e80df1bf4de25e812ef665a13b52ae2f1
Enrichment time
2026-04-27T07:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study · Baitaphish