Multiagent incident response planning with code models
File(s) GameSec2026_PaperID_22_Hammar.pdf (1.42 MB)
Accepted version
Author(s)
Hammar, Kim
Alpcan, Tansu
Lupu, Emil
Type
Conference Paper
Abstract
Incident response has traditionally been carried out by security operators who follow predefined playbooks. Although such playbooks can be effective against known threats, they are becoming increasingly difficult to maintain amid the rapid discovery of new vulnerabilities and the development of new attack techniques. As a consequence, there is a growing need for new decision-support systems that can assist operators by automating parts of the response process. In this paper, we address this need by presenting a multiagent system that autonomously investigates security incidents and recommends optimized response actions. The system decomposes incident response into subtasks that are managed by a hierarchy of agents, each using a large language model to process logs, generate outputs, and invoke external tools. Central to our system is an agent that generates a code model of the response process, which serves as a simulation engine for efficient response planning. We establish a theoretical lower bound on the quality of the response plan produced by the system and validate it through extensive experiments. For a multistage attack executed on our testbed, the system significantly
outperforms single-agent approaches in planning efficiency and precision.
outperforms single-agent approaches in planning efficiency and precision.
Date Acceptance
2026-07-24
Citation
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
ISSN
0302-9743
Publisher
Springer
Journal / Book Title
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Copyright Statement
Subject to copyright. This paper is embargoed until publication. Once published the author’s accepted manuscript will be made available under a CC-BY License in accordance with Imperial’s Research Publications Open Access policy (www.imperial.ac.uk/oa-policy).
License URL
Source
Conference on Game Theory and AI for Security (GameSec 2026)
Publication Status
Accepted
Start Date
2026-10-26
Finish Date
2026-10-28
Coverage Spatial
Ann Arbor, Michigan, USA
