LATIDIA · Ciberseguridad
HESP: Separar qué sondear de cuándo detenerse en agentes locales de LLM Alert-Triage
arXiv: 2609.33446v1Tipo de anuncio: nuevo Resumen: Los centros de operaciones de seguridad reciben muchas más alertas de las que los analistas pueden investigar, y las organizaciones que no pueden enviar su telemetría a los modelos alojados deben automatizar el triaje
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.33446v1 Announce Type: new Abstract: Security operations centers receive far more alerts than analysts can investigate, and organizations that cannot send their telemetry to hosted models must automate triage with small open-weight LLMs on their own hardware. Current LLM agents leave the investigation procedure to the model, and small local models fail at it: they probe without converging, never commit to a verdict, or dismiss real attacks. In this paper, we present HESP, a controller that holds the investigation procedure outside the model. HESP keeps a ledger of competing explanations, selects read-only probes by expected information gain per cost, accepts only verdicts backed by current evidence, can end an investigation