(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations
Neta Kirmayer, David Tayouri, Andrés Murillo, Motoyoshi Sekiya, Asaf Shabtai, Rami Puzis
cs.CR, cs.AI
Submitted: 2026-07-28
Comments: 21 pages
Code: https://github.com/jetlime/eX-NIDS
License: http://creativecommons.org/licenses/by-nc-sa/4.0/
The gist: Security operations centers rely on anomaly detection systems to flag suspicious events.
Terminology
Abstract
Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations grounded in verifiable evidence. Evaluation results show that the proposed framework improves post-detection analysis by generating operationally meaningful explanations, which also enhance event classification accuracy.
Sources
- HuntGPT: Integrating Machine Learning-Based Anomaly Detection and Explainable AI with Large Language Models (LLMs)
- AnomalyExplainer Explainable AI for LLM-based anomaly detection using BERTViz and Captum
- Thinking Machines: A Survey of LLM based Reasoning Strategies
- Interpretable Anomaly-Based DDoS Detection in AI-RAN with XAI and LLMs
- Opportunities and Challenges in Explainable Artificial Intelligence (XAI): A Survey
- Towards Explainable Network Intrusion Detection using Large Language Models
- EXPLICATE: Enhancing Phishing Detection through Explainable AI and LLM-Powered Interpretability
- LLM-driven Provenance Forensics for Threat Investigation and Detection
- Gemini: A Family of Highly Capable Multimodal Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs