Seek and You Shall SOC: Blending Human Expertise with Multimodal Generative AI for Scalable Threat Prevention
Loading...
Date
DOI
Open Access Location
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Association for Computing Machinery (ACM)
Rights
(c) The author/s
CC BY-NC-ND 4.0
CC BY-NC-ND 4.0
Abstract
Large language models (LLMs) are increasingly employed within Security Operations Centres (SOCs), including SOC for Digital Risk Protection (DRP), yet their outputs often exhibit partial coverage, hallucinations, verbosity, and lack of localized insights. This article proposes a hybrid reasoning pipeline that combines multimodal LLMs with stable human-curated references to mitigate these issues, and is distinct from standard retrieval-augmented generation because offline, human-curated references are applied as an explicit decision-time override rather than used solely as supportive retrieved context. We introduce a step-by-step process that incorporates multi-vantage crawling for evasive content, deterministic prompts to manage inconsistency, and a structured approach to override or refine the model’s classifications when local brand knowledge contradicts global assumptions, together with an analyst-governed escalation loop that records when and why overrides occur in external-SOC DRP settings. Empirical evaluations with multiple commercial and open-source model providers show that this method significantly boosts scam detection accuracy, lowers token costs through caching, and reduces misleading outputs by adopting curated domain data, including comparisons against a RAG-only configuration and classical non-LLM baselines. Results underline how offline reference injection fosters a reliable collaboration pattern that harmonizes automated tasks with human expertise, thereby enhancing scalability and trust in real-world SOC environments.
Description
Keywords
Citation
Xu D, Gondal I, Yi X, Susnjak T, McIntosh T. (2026). Seek and You Shall SOC: Blending Human Expertise with Multimodal Generative AI for Scalable Threat Prevention. ACM Transactions on Internet Technology. Accepted Manuscript.
Collections
Endorsement
Review
Supplemented By
Referenced By
Creative Commons license
Except where otherwised noted, this item's license is described as (c) The author/s

