Tinakaran Chinnachamy · · 2026
DOI: 10.34218/ijaiml_05_02_007
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Today's Security Operations Centers (SOCs) need to process vast amounts of complex and diverse security data from endpoints, cloud, identity and network systems in a timely manner.Large Language Models (LLMs) have been shown to have a good performance in reasoning but are not widely used in automated incident response for the following reasons: Lack of explainability: LLM outputs are often hard to interpret; Decision validation is inconsistent: Not every decision made by LLM is verified; Evidence correlation is poor: LLM fails to correlate evidence in fragments; Collaborative reasoning is also limited: LLM is not good at reasoning together.To tackle these problems, this paper introduces a novel framework for AI-enabled cyber defense, X-MASIR (Explainable Multi-Agent Security Incident Response).X-MASIR is a platform that uses specialized agents based on LLMs, each dedicated to a specific task, such as evidence collection, threat intelligence correlation, attack-path reconstruction, risk assessment, response planning, policy verification and explanation generation.
No comments yet — start the discussion below.