Skip to content
Search
paperMay 2026Unreviewed

Stable Agentic Control: Tool-Mediated LLM Architecture for Autonomous Cyber Defense

Kerri Prinos, Lilianne Brush, C. Denton, Zhanqiang Wang, Joshua Knox, Snehal S. Antani, A. Foltz, Amy Villasenor

arXiv.org

Abstract

Agentic systems involved in high-stake decision-making under adversarial pressure need formal guarantees not offered by existing approaches. Motivated by the operational needs of security operations centers (SOCs) that must configure endpoint detection and response (EDR) policies under adversarial pressure, we present a tool-mediated architecture: LLM agents use deterministic tools (Stackelberg best-response, Bayesian observer updates, attack-graph primitives) and select from finite action catal

Categories

Cite

@misc{prinos2026stable,
  title = {{Stable Agentic Control: Tool-Mediated LLM Architecture for Autonomous Cyber Defense}},
  author = {Kerri Prinos and Lilianne Brush and C. Denton and Zhanqiang Wang and Joshua Knox and Snehal S. Antani and A. Foltz and Amy Villasenor},
  year = {2026},
  month = may,
  eprint = {2605.03034},
  archivePrefix = {arXiv},
  doi = {10.48550/arXiv.2605.03034},
  url = {https://www.semanticscholar.org/paper/7ca2bbdc56f4102275222deee1f3a60eb34b486a}
}