Skip to content
Search
paperSeptember 2026Unreviewed

SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations Center

Uday Vallabhaneni, Cassie L. Cagwin, David J. Wild

Abstract

Large language model (LLM) agents are increasingly proposed as autonomous SOC analysts, but two limitations make them unreliable at enterprise scale: a finite context window cannot hold a multi-thousand-host authentication graph, and free-form generation offers no guarantee that a recommended containment action is consistent with the topology it operates on. We present Sentinel-RL, an agentic-SOC architecture that decouples topological reasoning from semantic reasoning: a heterogeneous graph att

Categories

Cite

@misc{vallabhaneni2026sentinelrl,
  title = {{SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations Center}},
  author = {Uday Vallabhaneni and Cassie L. Cagwin and David J. Wild},
  year = {2026},
  month = sep,
  eprint = {2609.04159},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.04159}
}