Jul 2026· 2026 International Conference on Emerging Trends in Information, Communication & Systems (ICETICS)· pp. 1-6· 0 citations· 24 references
Abstract
A multi-agent GenAI architecture is introduced to support the automation of ethical cloud security, solving the problem of scalability or adaptability, and compliance in dynamic cloud environments. This framework combines dedicated generative agents such as policy analysts, threat detectors, remediation organizers, and auditor agents which interact via common knowledge graph and can be explained by a decision log. The agents utilize context-based prompt generation, generation constraints, provenance management, and generation to generate security policies, anomaly detection, provide automated mitigation, and maintain human-in-the-loop control. Some of the ethical protections are bias audits, privacy-sensitive learning, least-privilege enforcement, and policy verifiability, to warrant the correctness of the decisions taken in compliance with regulatory or organizational limits. Testing with representative cloud work lines shows that there is shorter energy on discerning and correcting occurrences, elevated coverage of controls and signs when the automated actions are traced. The framework enables adjustable levels of trust and escalation measures to accommodate the autonomy versus governance. The method fosters usage of GenAI to deal with cloud security by offering modular agents, verifiable ethics controls, metrics-based assessment, hence fostering responsible automation that is also transparent, auditable, and considers changing threats.
CyberLLM is presented, a multi-agent, LLM-orchestrated framework that autonomously detects vulnerabilities and executes remediations under a formal, runtime safety guard, and indicates that LLM agents can perform useful autonomous cyber-defense when wrapped in a deterministic, auditable safety envelope.
Nenad Petrovic, Oussama Jeddou, Feres Ben Fraj et al.· 0 citations
The paradigm shift toward AI-driven autonomous network orchestration has precipitated a critical strategic vulnerability: the paradox of opaque autonomy. In mission-critical defense environments, the deployment of opaque models for intrusion detection and traffic management poses a severe risk to national security and decision-making accountability. This paper presents a systematic literature review (SLR) of eXplainable Artificial Intelligence (XAI) within the Intelligent and Secure SD-WAN (ISD-WAN) framework, adhering to the PRISMA 2020 guidelines. Through a rigorous analysis of thirty-two primary studies (2020-2026), we identified an architectural transition from post-hoc, management-plane explanations toward intrinsic, real-time interpretability within control and data planes. Our synthesis characterizes a fundamental trilemma between security enforcement, network performance, and computational overhead, highlighting the pivotal role of neuro-symbolic AI and blockchain as anchors for auditability and non-repudiation. We propose a multi-tiered interpretability roadmap thatAn analysis of the surveyed literature suggests a transition toward a multi-tiered interpretability roadmap, where the depth of the explanation is calibrated to the plane’s processing budget, whitch empowers sovereign entities to exercise verifiable control over autonomous information flows. By bridging the gap between algorithmic performance and strategic governance, this study establishes a structured survey and conceptual integration of emerging research framework for resilient, transparent, and technologically sovereign network infrastructures.
Igor David Brito Caldeira, Ricardo Choren, R. Salles· IEEE Access· 1 citation
Autonomous multi-agent systems nowadays act in finance, software supply chains, and security operations. Already, the first largely AI-orchestrated intrusion campaigns have been reported. Yet, when such a system causes harm, no method can robustly establish what happened, what caused it, or who is accountable. This is because provenance forensics works at the wrong abstraction, formal causality assumes the causal model, and agent auditing trusts self-recording. The target failure mode is, thus, attribution laundering, i.e., spreading an act across redundant agents until none is a but-for cause. Worse, the record is produced by the suspects, which comprises the assumption adopted throughout this work. Agents may therefore anticipate the investigation and the part of logging infrastructure may itself collude. In this paper, HANSARD is proposed, a reference architecture treating accountability as a life-cycle property. First, a readiness profile sealed before operation bounds what later findings may claim. Second, capturing at five choke points beyond the agents'reach makes omissions detectable, not only tampering. Third, a typed PROV-DM-aligned causal graph accrues as the system runs, and three indicators read it live to gate oversight without adjudicating. Fourth, post-incident replay yields contingent effects under the modified Halpern-Pearl definition, together with a compensation-set size. Finally, a synergy residual measures harm due to the combination rather than to individuals, making laundering visible. Cause, responsibility and accountability are then reported separately, each capped by an evidentiary tier, while a future research agenda is also provided.
Christos Sardianos, Iliana Pla, Vasilis Efthymiou et al.· 0 citations
The convergence of the Internet of Things (IoT) with Web3 ecosystems introduces new opportunities for automation, trust, and decentralized coordination. However, the same decentralized nature also amplifies security vulnerabilities, as conventional centralized intrusion detection and response systems are unable to provide real-time, tamper-proof protection at scale. This paper presents the Smart Contract-Based Automated Response System (SC-ARS), a novel framework that integrates blockchain smart contracts, machine learning (ML)-based anomaly detection, and automated mitigation policies. SC-ARS leverages lightweight consensus mechanisms and decentralized storage to ensure resilience against single points of failure, while smart contracts provide transparent and auditable enforcement of security actions. The ML pipeline, implemented using Random Forest, XGBoost, and LSTM models, is trained on benchmark datasets (NSL-KDD and CICIDS2017) to enable accurate anomaly detection. Experimental evaluation demonstrates up to 95% detection accuracy, a 50% reduction in response latency, and scalability to over 100,000 IoT devices without performance degradation. These results highlight the suitability of SC-ARS for deployment in smart cities, industrial IoT, and decentralized critical infrastructures where trust, transparency, and real-time responsiveness are essential.
S. Bassey, B. Stephen, Emediong Bassey Obot et al.· E3S Web of Conferences· 0 citations
The rapid proliferation of artificial intelligence (AI) systems across critical sectors has introduced significant security, privacy, and ethical challenges. Traditional information security audit frameworks remain insufficient to address the unique risks associated with AI technologies, particularly in areas such as data integrity, model robustness, and algorithmic transparency. This study proposes a comprehensive and risk-based AI audit methodology that integrates governance, data security, model security, and application security dimensions into a unified control framework. The proposed methodology is structured around key control domains, including documentation, compliance, access control, application security, and model security, supported by representative control considerations. The proposed methodology supports systematic evaluation of AI audit controls through a structured assurance-oriented framework. Additionally, a risk prioritization approach is introduced to classify controls into different criticality levels, enabling organizations to focus on high-impact vulnerabilities such as data poisoning, model inversion, prompt injection, and sensitive data leakage. The methodology is designed as a step-by-step audit process, including scope definition, control mapping, evidence collection, evaluation, and reporting. This structured approach ensures both technical and organizational aspects of AI systems are systematically assessed. The study contributes to the literature by providing a practical, measurable, and adaptable framework that aligns with regulatory requirements such as data protection laws and ethical AI principles. Overall, the proposed AI audit framework enhances the auditability, transparency, and security of AI systems, offering organizations a robust tool to manage emerging AI-related risks effectively.
Osman Turan, Z. Müftüoğlu, Tolga Özbilge· Denetişim· 0 citations