arXiv:2601.04486cs.CRcs.AI2026-01

让安全告警的可信度显示更符合决策需求,减少误判负担。

Decision-Aware Trust Signal Alignment for SOC Alert Triage

  • 将校准后的置信度与不确定性提示结合,动态调整决策阈值。
  • 在UNSW-NB15数据集上,决策对齐后误报率显著降低,成本损失下降数量级。
  • 适用于需要高可靠性判断的安全分析场景,尤其适合压力下的分析师。

利用机器学习的安全检测系统在安全运营中心(SOC)中日益普及,帮助分析师处理海量安全告警。然而,这些系统常输出未经校准的概率结果或置信度分数,在高压环境下难以解读。已有研究发现,告警质量差和告警过载会显著增加分析师负担,尤其当工具输出与实际决策需求不一致时。一个重要问题是:模型置信度通常未考虑决策的非对称代价——漏报攻击的危害远高于误报。本文提出一种面向决策的可信度信号对齐框架,通过校准置信度、引入轻量级不确定性提示以及成本敏感的决策阈值,构建统一的决策支持层,无需修改检测模型。采用后处理校准方法提升概率一致性,不确定性提示在模型置信度低时提供保守保护。在UNSW-NB15入侵检测基准上,使用逻辑回归与随机森林分类器进行测试。模拟结果显示,置信度显示错位会导致漏报大幅增加;而采用决策对齐的信任信号后,成本加权损失下降一个数量级以上。最后,论文设计了人机协同实验方案,以实证评估分析师在对齐与错位信任界面下的决策表现。

原文摘要 · Abstract (English)

Detection systems that utilize machine learning are progressively implemented at Security Operations Centers (SOCs) to help an analyst to filter through high volumes of security alerts. Practically, such systems tend to reveal probabilistic results or confidence scores which are ill-calibrated and hard to read when under pressure. Qualitative and survey based studies of SOC practice done before reveal that poor alert quality and alert overload greatly augment the burden on the analyst, especially when tool outputs are not coherent with decision requirements, or signal noise. One of the most significant limitations is that model confidence is usually shown without expressing that there are asymmetric costs in decision making where false alarms are much less harmful than missed attacks. The present paper presents a decision-sensitive trust signal correspondence scheme of SOC alert triage. The framework combines confidence that has been calibrated, lightweight uncertainty cues, and cost-sensitive decision thresholds into coherent decision-support layer, instead of making changes to detection models. To enhance probabilistic consistency, the calibration is done using the known post-hoc methods and the uncertainty cues give conservative protection in situations where model certainty is low. To measure the model-independent performance of the suggested model, we apply the Logistic Regression and the Random Forest classifiers to the UNSW-NB15 intrusion detection benchmark. According to simulation findings, false negatives are greatly amplified by the presence of misaligned displays of confidence, whereas cost weighted loss decreases by orders of magnitude between models with decision aligned trust signals. Lastly, we describe a human-in-the-loop study plan that would allow empirically assessing the decision-making of the analysts with aligned and misaligned trust interfaces.

安全告警可信度对齐决策支持

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。