AI RESEARCH

Stable Agentic Control: Tool-Mediated LLM Architecture for Autonomous Cyber Defense

arXiv CS.AI

ArXi:2605.03034v1 Announce Type: new Agentic systems involved in high-stake decision-making under adversarial pressure need formal guarantees not offered by existing approaches. Motivated by the operational needs of security operations centers (SOCs) that must configure endpoint detection and response (EDR) policies under adversarial pressure, we present a tool-mediated architecture: LLM agents use deterministic tools (Stackelberg best-response, Bayesian observer updates, attack-graph primitives) and select from finite action catalogs enforced at the tool-output interface.