← Back to all articles
arXiv cs.AIAugust 18, 2026

Hierarchical Agentic Incident Response with Digital-Twin-Validated Attack Inference

Excerpt

arXiv:2608.15016v1 Announce Type: cross Abstract: Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands. Decision-theoretic planners provide principled optimization but typically rely on abstract states and predefined actions, while large language model (LLM) agents can reason over operational context but may hallucinate attacks and responses. Toward automa