Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers
Research Paper Showcase 2026
Abstract
Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration offers a promising path to augment the capabilities of analysts while reducing cognitive overload. To this end, we introduce an AI-driven human-machine co-teaming paradigm that leverages large language models (LLMs) to support threat intelligence, alert triage, and incident response workflows. We present a vision in which LLM-based agents learn from human analysts the tacit knowledge embedded in SOC operations, enabling them to progressively improve their performance on operational tasks. Our approach involves close collaboration with SOCs to refine this process and identify replicable patterns where human-AI co-teaming improves operational efficiency. To illustrate the feasibility of this paradigm, we report lessons learned from a preliminary case study conducted in partnership with a real SOC.
Authors
- Massimiliano Albanese, professor, cybersecurity engineering, George Mason University
- Xinming Ou, professor, Bellini College of Artificial Intelligence, Cybersecurity and Computing, University of South Florida
- Kevin Lybarger, assistant professor, information sciences and technology, George Mason University
- Daniel Lende, associate professor, anthropology, University of South Florida
- Dmitry Goldgof, distinguished university professor, computer science and engineering, University of South Florida
- Faayed Al Faisal, Ph.D. student, computer science, University of South Florida
- Kritan Banstola, Ph.D. student, computer science, University of South Florida
- Arka Ghosh, Ph.D. student, information sciences and technology (cybersecurity concentration), George Mason University
Publication
- Venue: ACM Transactions on Internet Technology
- Date: June 2026