SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations Center
Sentinel-RL keeps the LLM out of the topology problem and makes a separate RL policy choose from constrained SOC actions.
The paper says the architecture uses a graph attention encoder and PPO policy to summarize live authentication graphs before the LLM writes analyst-facing narratives. On LANL and Indiana University Quartz data, it reports loading a 24M-edge subgraph into Neo4j in 14.2 minutes and completing a detect-investigate-recommend-human-approve loop in a median 6.3 seconds. Held-out red-team results are reported at 0.91 precision and 0.87 recall. Source: ArXiv · AI/CL/LG's note.
The paper says the architecture uses a graph attention encoder and PPO policy to summarize live authentication graphs before the LLM writes analyst-facing narratives. On LANL and Indiana University Quartz data, it reports loading a 24M-edge subgraph into Neo4j in 14.2 minutes and completing a detect-investigate-recommend-human-approve loop in a median 6.3 seconds. Held-out red-team results are reported at 0.91 precision and 0.87 recall. Source: ArXiv · AI/CL/LG's note.
score 4