Agentic Incident Response through Digital Twin-Enhanced Multiscale Planning
The paper claims a two-level LLM incident-response system beats frontier LLM baselines in simulated attack recovery.
Its planner uses a digital twin to test high-level resource choices, then has a lightweight LLM turn the selected strategy into executable response commands. The authors frame this as a way around agentic systems that repeatedly ask an LLM to plan and drift into unreliable longer-horizon behavior. Across three attack scenarios, they report 15.1% faster recovery execution and a 33.6% higher recovery rate. ArXiv · AI/CL/LG's note
Its planner uses a digital twin to test high-level resource choices, then has a lightweight LLM turn the selected strategy into executable response commands. The authors frame this as a way around agentic systems that repeatedly ask an LLM to plan and drift into unreliable longer-horizon behavior. Across three attack scenarios, they report 15.1% faster recovery execution and a 33.6% higher recovery rate. ArXiv · AI/CL/LG's note
score 4