A Unified Framework for Human–AI Collaboration in Security Operations Centers with Trusted Autonomy
Единая концепция взаимодействия человека и искусственного интеллекта в центрах мониторинга и реагирования на инциденты информационной безопасности с использованием доверенной автономности
2026-07-30
SCID: 54.1/2yr6b8sz
Discuss with AI
Human-in-the-Loop decision makingHuman–AI collaborationRAG-augmented LLM SOC assistantSecurity Operations CentersTrusted autonomy
Figures from the paper
Abstract (AI)
This article presents a structured framework for Human-AI collaboration in Security Operations Centers (SOCs), integrating AI autonomy, trust calibration, and Human-in-the-Loop decision making. Existing frameworks in SOCs often focus narrowly on automation, lacking systematic structures to manage human oversight, trust calibration, and scalable autonomy with AI. Many assume static or binary autonomy settings, failing to account for the varied complexity, criticality, and risk across SOC tasks, considering human and AI collaboration. To address these limitations, we propose a novel autonomy tiered framework grounded in five levels of AI autonomy, from manual to fully autonomous, mapped to Human-in-the-Loop (HITL) roles and task-specific trust thresholds. This enables adaptive and explainable AI integration across core SOC functions, including monitoring, protection, threat detection, alert triage, and incident response. The proposed framework differentiates itself from previous research by creating formal connections between autonomy, trust, and HITL across various SOC levels, which allows for adaptive task distribution according to operational complexity and associated risks. The framework is exemplified through a simulated cyber range that features the cybersecurity AI Avatar, a RAG augmented LLM-based SOC assistant. The AI Avatar case study illustrates Human-AI collaboration for SOC tasks, reducing alert fatigue, enhancing response coordination, and strategically calibrating trust. This research systematically presents both the theoretical and practical aspects, as well as the feasibility of designing next-generation cognitive SOCs that leverage AI not to replace, but to enhance human decision-making.
Key Findings
1
A simulated cyber range featuring a retrieval-augmented LLM-based cybersecurity AI Avatar demonstrates reduced alert fatigue, improved response coordination, and strategic trust calibration.
2
It addresses limitations of static or binary autonomy models by integrating human oversight, trust calibration, and explainable AI across core SOC functions.
3
The framework enables adaptive autonomy and task allocation according to operational complexity, criticality, and associated cybersecurity risks.
4
The framework positions AI as an enhancement to human decision-making rather than a replacement, supporting the design of next-generation cognitive SOCs.
5
The paper introduces a unified SOC framework linking five AI autonomy levels, Human-in-the-Loop roles, and task-specific trust thresholds.
Research Object
Human–AI collaboration in Security Operations Centers (SOCs), including AI-assisted SOC functions and decision-making
Research Subject
Trusted, adaptive, and explainable allocation of SOC tasks between humans and AI through calibrated trust, tiered autonomy, and Human-in-the-Loop roles across varying operational complexity and risk
Publication Details
Publication Date
2026-07-30
Journal
Publisher
ISSN
Cited by
5
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest