From Chasing Ghosts to Missed Attacks: Perspectives and Perceptions of SOC Practitioners on LLM Integration, Risks, and Readiness
Jonas Thurner, Nadine Jost, Stefan Albert Horstmann, Fabian Ising, Lea Groeber, Alena Naiakshina, Sebastian Schinzel
cs.CR, cs.AI, cs.HC
Submitted: 2026-08-01
Code: https://github.com/openai/whisper
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security
- Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers
- Large Language Models Are Unreliable for Cyber Threat Intelligence
- Towards Characterizing Cyber Networks with Large Language Models
- A Comprehensive Overview of Large Language Models (LLMs) for Cyber Defences: Opportunities and Directions
- Large Language Models for Cyber Security: A Systematic Literature Review
- Cognitive Bias in Decision-Making with LLMs
- LessLeak-Bench: A First Investigation of Data Leakage in LLMs Across 83 Software Engineering Benchmarks
- LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs