Multi-Agent LLM Framework for Cybersecurity Explainability
Researchers have developed (EC)2, a multi-agent framework that uses large language models to provide event-centric explanations for cybersecurity alerts. The system is designed for small- to medium-sized enterprise networks and operates independently of specific anomaly detectors. It conducts structured, hypothesis-driven investigations to generate explanations grounded in verifiable evidence. Evaluation results indicate that (EC)2 improves post-detection analysis by producing operationally meaningful explanations and enhancing event classification accuracy.
Key facts
- (EC)2 is a multi-agent framework for cybersecurity explainability.
- It uses large language models for hypothesis-driven investigations.
- The framework is detector-agnostic and event-centric.
- Targeted at small- to medium-sized enterprise networks.
- Explanations are grounded in verifiable evidence.
- Improves post-detection analysis and event classification accuracy.
- Addresses limitations of feature-level explanations in anomaly detection.
- Published on arXiv under Computer Science > Cryptography and Security.
Entities
Institutions
- arXiv