Toward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration
Researchers formalize AI-augmented defense-in-depth and show full review of AI alerts can lower detection rates.
The paper proposes a falsifiable model connecting defense-in-depth, AI pattern recognition, and human-AI collaboration in security operations. It treats layered defense as a Bernoulli detection cascade, each layer as a Neyman-Pearson detector with a closed-form threshold, and triage as a capacity-constrained cascade. A Monte Carlo simulation finds AI augmentation compounds most where traditional layering saturates. Reviewing every AI-flagged alert cut false alarms roughly 20-fold but lowered system detection because imperfect analyst judgment was applied to every alert.
- Models layered defense as a Bernoulli detection cascade.
- Derives a closed-form Neyman-Pearson detection threshold per layer.
- Full alert review cut false alarms about 20-fold but lowered detection.
- Suggests an interior-optimum analyst capacity ratio for SOCs.
Full article235 words · extracted from arxiv.org · click to collapse
Cybersecurity literature has extensively documented the operational benefits of artificial intelligence (AI) for threat detection, incident response, and prevention, while raising qualitative concerns about over-automation, algorithmic bias, and analyst-skill erosion. What remains largely absent is a formal, falsifiable model connecting three constructs that recur across this literature: Defense-in-Depth Theory, the Artificial Intelligence Theory of Pattern Recognition, and human-AI collaboration in security operations. This paper develops such a model. We formalize layered defense as a Bernoulli detection cascade in which AI augmentation enters multiplicatively across layers; we formalize each layer's pattern-recognition behavior as a Neyman-Pearson/Bayesian detector with a derived closed-form optimal threshold; and we formalize human-AI triage as a capacity-constrained cascade with an explicit, quantifiable trade-off between detection probability and false-alarm ("alert fatigue") rate. A Monte Carlo/analytical simulation evaluated at illustrative but realistic operating points shows that (i) AI augmentation compounds across defense layers, delivering its largest marginal gains exactly where traditional layering saturates, and (ii) full human review of AI-flagged alerts is not optimal: increasing analyst capacity toward 100% coverage cuts false alarms by roughly 20-fold but simultaneously lowers system-level detection probability, because imperfect analyst accuracy is then applied to every alert rather than a filtered subset. These results give the widely repeated qualitative recommendation of "balanced human-AI collaboration" a precise, testable form and suggest an interior-optimum capacity ratio as a concrete design target for security operations centers (SOCs), including those securing IT/OT-converged critical infrastructure.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.25921