HESP: Separating What to Probe from When to Stop in Local LLM Alert-Triage Agents
cs.CR, cs.AI
Submitted: 2026-09-27
Updated: 2026-09-27
Code: https://github.com/lzwhehe/HESP
Terminology
Sources
- ExCyTIn-Bench: Evaluating LLM agents on Cyber Threat Investigation
- AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security
- Progent: Securing AI Agents with Privilege Control
- Language Models (Mostly) Know What They Know
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs