ARTFEED — Contemporary Art Intelligence

New Framework for Human-AI Collaboration in Security Operations Centers

ai-technology · 2026-08-06

A new study has outlined a detailed approach to improving how humans and AI work together in Security Operations Centers (SOCs). It addresses the limitations of existing systems that mainly focus on automation and fixed autonomy levels. The study introduces five levels of AI autonomy, ranging from total manual control to full automation, which correspond to Human-in-the-Loop roles and trust requirements for different tasks. This framework supports the use of flexible and clear AI across key SOC functions like monitoring, defense, threat identification, alert prioritization, and incident management. You can check out the revised paper on arXiv under the ID 2505.23397, as it seeks to enhance human oversight and trust while managing varying task complexities in cybersecurity.

Key facts

  • The paper proposes a framework for Human-AI collaboration in Security Operations Centers (SOCs).
  • The framework integrates AI autonomy, trust calibration, and Human-in-the-loop decision making.
  • Existing frameworks in SOCs often focus narrowly on automation and lack systematic structures for human oversight.
  • The proposed framework uses five levels of AI autonomy, from manual to fully autonomous.
  • The levels are mapped to Human-in-the-Loop (HITL) roles and task-specific trust thresholds.
  • The framework enables adaptive and explainable AI integration across SOC functions: monitoring, protection, threat detection, alert triage, and incident response.
  • The paper is available on arXiv with identifier 2505.23397.
  • The announcement type is 'replace', indicating a revised version.

Entities

Sources