A Unified Framework for Human AI Collaboration in Security Operations Centers with Trusted Autonomy
Ahmad Mohsin, Helge Janicke, Ahmed Ibrahim, Iqbal H. Sarker, Seyit Camtepe
Why It Matters
What makes this one worth your time
This framework could improve the efficiency and effectiveness of SOCs by optimizing human-AI interactions, potentially reducing alert fatigue and enhancing incident response.
A framework for adaptive human-AI collaboration in SOCs to improve decision-making and trust calibration.
Summary
The paper proposes a structured framework for integrating human-AI collaboration in Security Operations Centers (SOCs), focusing on trust calibration and adaptive autonomy levels to enhance decision-making processes.
Key contributions
- A novel autonomy tiered framework for SOCs integrating human-in-the-loop roles.
- Mapping of AI autonomy levels to task-specific trust thresholds.
- A case study using a cybersecurity AI-Avatar to illustrate framework application.
Notable insights
- The framework introduces a tiered autonomy model that adapts to task complexity and risk, which is not commonly addressed in existing SOC frameworks.
- The use of a simulated cyber range to demonstrate the framework's application provides a practical example of its potential benefits.
Possible limitations
- Not stated in the abstract
Abstract
arXiv:2505.23397v3 Announce Type: replace Abstract: This article presents a structured framework for Human-AI collaboration in Security Operations Centers (SOCs), integrating AI autonomy, trust calibration, and Human-in-the-loop decision making. Existing frameworks in SOCs often focus narrowly on automation, lacking systematic structures to manage human oversight, trust calibration, and scalable autonomy with AI. Many assume static or binary autonomy settings, failing to account for the varied complexity, criticality, and risk across SOC tasks considering Humans and AI collaboration. To address these limitations, we propose a novel autonomy tiered framework grounded in five levels of AI autonomy from manual to fully autonomous, mapped to Human-in-the-Loop (HITL) roles and task-specific trust thresholds. This enables adaptive and explainable AI integration across core SOC functions, including monitoring, protection, threat detection, alert triage, and incident response. The proposed framework differentiates itself from previous research by creating formal connections between autonomy, trust, and HITL across various SOC levels, which allows for adaptive task distribution according to operational complexity and associated risks. The framework is exemplified through a simulated cyber range that features the cybersecurity AI-Avatar, a fine-tuned LLM-based SOC assistant. The AI-Avatar case study illustrates human-AI collaboration for SOC tasks, reducing alert fatigue, enhancing response coordination, and strategically calibrating trust. This research systematically presents both the theoretical and practical aspects and feasibility of designing next-generation cognitive SOCs that leverage AI not to replace but to enhance human decision-making.