(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations

πŸ“… 2026-07-28
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This work addresses the limitations of traditional anomaly detection systems, whose feature-level explanations often lack contextual relevance and actionable insights, thereby hindering efficient alert investigation by security analysts. To overcome this, the paper proposes an event-centric, detector-agnostic explainability framework that uniquely integrates multi-agent collaboration with large language models (LLMs). By orchestrating a structured, hypothesis-driven automated investigation process, the framework generates alert explanations grounded in verifiable evidence. This approach substantially enhances post-hoc analysis efficiency, delivers operationally meaningful interpretations, and significantly improves event classification accuracy.
πŸ“ Abstract
Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations grounded in verifiable evidence. Evaluation results show that the proposed framework improves post-detection analysis by generating operationally meaningful explanations, which also enhance event classification accuracy.
Problem

Research questions and friction points this paper is trying to address.

cybersecurity explainability
anomaly detection
event-centric explanation
security operations
contextual understanding
Innovation

Methods, ideas, or system contributions that make the work stand out.

event-centric explainability
multi-agent LLM
cybersecurity alert explanation
hypothesis-driven investigation
detector-agnostic