A team led by Saimon Amanuel Tsegai released a preprint describing AIDA, a multi‑agent system for security operations centers. AIDA forces agents to propose a decision, let a separate agent challenge it, and require stronger evidence before dismissing alerts. On a benchmark of 1,247 alerts from a staged attack, AIDA reached an F1 score of 0.958 and lowered the false‑negative rate to 3.1%, compared with 40.4% for five earlier methods.
Why it matters
SOC teams could rely more on automated triage, letting analysts focus on the 18% of alerts that still need human review.