September 2026Unreviewed
SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations Center
Uday Vallabhaneni, Cassie L. Cagwin, David J. Wild
Abstract
Large language model (LLM) agents are increasingly proposed as autonomous SOC analysts, but two limitations make them unreliable at enterprise scale: a finite context window cannot hold a multi-thousand-host authentication graph, and free-form generation offers no guarantee that a recommended containment action is consistent with the topology it operates on. We present Sentinel-RL, an agentic-SOC architecture that decouples topological reasoning from semantic reasoning: a heterogeneous graph att
Categories
Cite
@misc{vallabhaneni2026sentinelrl,
title = {{SENTINEL-RL: Offloading Topological Reasoning from LLM Agents in the Security Operations Center}},
author = {Uday Vallabhaneni and Cassie L. Cagwin and David J. Wild},
year = {2026},
month = sep,
eprint = {2609.04159},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.04159}
}