arXiv:2602.11897cs.CRcs.AI2026-02

用元认知框架让AI安全系统更懂自己,应对混乱信息做出可靠决策。

Agentic AI for Cybersecurity: A Meta-Cognitive Architecture for Governable Autonomy

  • 将安全任务拆解为检测、推理、解释等协作智能体,由元认知机制统一调度。
  • 在噪声和对抗环境下准确率更高,误报率降低,置信度估计更可信。
  • 适合需要可解释、可管控的自主决策的高风险安全场景。

网络安全决策常面临不确定性、观测不全和敌意干扰,多源信号往往不完整、模糊或矛盾。传统安全编排、自动化与响应(SOAR)系统依赖确定性流程和阈值触发,难以应对此类复杂环境。本文提出一种概率性、代理式的安全编排框架,将决策过程建模为元认知行为。该框架将安全功能分解为负责检测、假设生成、上下文构建、解释与治理的相互作用智能体,通过元认知判断机制进行协调。该机制评估不确定性、智能体分歧及操作约束,决定决策是否就绪,支持自动执行、升级、延迟或证据优化等自适应策略。在基准数据集CICIDS2017和NSL-KDD上,经对抗与不确定条件增强后评估显示,相比确定性与单智能体基线,该方法显著提升鲁棒性与决策质量:在噪声环境下准确率更高,误报率更低,置信度校准更优,且具备更强的自适应与情境感知能力。通过显式建模监控、评估、控制与反思等元认知过程,本方法将网络安全重构为人工智能辅助的认知问题求解范式,支持可问责的自主性与更有效的人机协同。

原文摘要 · Abstract (English)

Cybersecurity decision-making increasingly occurs in environments characterized by uncertainty, partial observability, and adversarial manipulation, where heterogeneous signals from multiple sources are often incomplete, ambiguous, or conflicting. Traditional Security Orchestration, Automation, and Response (SOAR) systems rely on deterministic pipelines and threshold-based triggers, limiting their ability to support reliable decision-making under such conditions. This paper proposes a probabilistic, agentic framework for cybersecurity orchestration that models decision-making as a meta-cognitive process. The framework decomposes cybersecurity functions into interacting agents responsible for detection, hypothesis formation, contextualization, explanation, and governance, coordinated through a meta-cognitive judgement mechanism. This mechanism evaluates uncertainty, agent disagreement, and operational constraints to determine decision readiness, enabling adaptive strategies including automated action, escalation, deferral, and evidence refinement. Empirical evaluation on benchmark datasets (CICIDS2017 and NSL-KDD), augmented with adversarial and uncertain conditions, demonstrates that the proposed approach improves robustness and decision quality compared to deterministic and single-agent baselines. The framework achieves higher accuracy under noise, reduces false positive rates, and produces better-calibrated confidence estimates, while enabling more adaptive and context-aware decision behavior. By explicitly modeling meta-cognitive processes - monitoring, evaluation, control, and reflection - the proposed approach reframes cybersecurity as an instance of AI-mediated cognitive problem solving, supporting accountable autonomy and more effective human-AI collaboration in adversarial environments.

AI安全元认知自主决策智能体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。