Privacy-Aware Data-Model Dual-Driven Decision Analysis for Data Security in Distributed Multi-Agent Operations
DOI:
https://doi.org/10.4108/eetsis.13943Keywords:
data-model dual-driven, privacy-aware data security, decision analysis, distributed multi-agent operations, SOAR, tool-call evaluationAbstract
INTRODUCTION: Distributed networks generate heterogeneous security telemetry while moving data across endpoints, users, services, and operational domains. SOCs need methods that protect data assets, preserve auditability, and avoid unsafe tool calls.
OBJECTIVES: This paper proposes a data-model dual-driven method, in which incident and execution data constrain LLM-based reasoning while model outputs generate auditable process data, for privacy-aware data security decision analysis in multi-agent security operations.
METHODS: The method combines LLM-based role agents, SOAR playbook orchestration, persistent message state, and a virtual security capability layer. Incidents are transformed into data-aware tasks, actions, commands, execution records, and summaries.
RESULTS: On 83 labeled incident samples, tool-call evaluation achieved 0.9684 precision, 0.4742 recall, 0.6367 F1-score, and 76.45 s average handling time.
CONCLUSION: The method supports auditable data security monitoring and controlled response, while complex multi-step planning remains the main improvement target.
References
[1] Verizon Business. 2026 Data Breach Investigations Report. Verizon Business; 2026. Available from: https://www.verizon.com/business/resources/ reports/dbir/.
[2] Tariq S, Chhetri MB, Nepal S, Paris C. Alert Fatigue in Security Operations Centres: Research Challenges and Opportunities. ACM Computing Surveys. 2025;57(9):224.
[3] Cichonski P, Millar T, Grance T, Scarfone K. Computer Security Incident Handling Guide. National Institute of Standards and Technology; 2012. Available from: https://doi.org/10.6028/NIST.SP.800-61r2.
[4] Cybersecurity and Infrastructure Security Agency. Federal Government Cybersecurity Incident and Vulnerability Response Playbooks. CISA; 2021.
[5] OASIS. CACAO Security Playbooks Version 2.0; 2023. Available from: https://docs.oasis-open.org/cacao/security-playbooks/v2.0/security-playbooks-v2.0.html.
[6] Hu H, Zhang L, Zhang Z, Yao X, Wu X. An Intelligent Playbook Recommendation Algorithm Based on Dynamic Interest Modeling for SOAR. Symmetry. 2025;17(11):1851.
[7] Habibzadeh A, Feyzi F, Atani RE. Large Language Models for Security Operations Centers: A Comprehensive Survey; 2025. arXiv preprint arXiv:2509.10858. Available from: https://arxiv.org/abs/2509.10858.
[8] Jaffal NO, Alkhanafseh M, Mohaisen D. Large Language Models in Cybersecurity: A Survey of Applications, Vulnerabilities, and Defense Techniques; 2025. arXiv preprint arXiv:2507.13629. Available from: https://arxiv.org/abs/2507.13629.
[9] Xu H, et al. Large Language Models for Cyber Security: A Systematic Literature Review. ACM Transactions on Software Engineering and Methodology. 2025.
[10] OWASP Foundation. OWASP Top 10 for Large Language Model Applications 2025; 2025. Available from: https://genai.owasp.org/llm-top-10/.
[11] Yu M, Meng F, Zhou X, Wang S, et al. A Survey on Trustworthy LLM Agents: Threats and Countermeasures; 2025. arXiv preprint arXiv:2503.09648. Available from: https://arxiv.org/abs/2503.09648.
[12] Akbari Gurabi M, Fysarakis K, Mavroeidis V, et al. From Legacy to Standard: LLM Assisted Transformation of Cybersecurity Playbooks into CACAO Format. In: Computer Security. ESORICS 2025 International Workshops. Springer Nature Switzerland; 2026. p. 491-510.
[13] Xi Z, Chen W, Guo X, et al. The Rise and Potential of Large Language Model Based Agents: A Survey. Science China Information Sciences. 2025;68(2):121101.
[14] Wu Q, Bansal G, Zhang J, et al. AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation Framework; 2023. arXiv preprint arXiv:2308.08155. Available from: https://arxiv.org/abs/2308.08155.
[15] Yao S, Zhao J, Yu D, et al. ReAct: Synergizing Reasoning and Acting in Language Models. In: International Conference on Learning Representations; 2023. Available from: https://arxiv.org/abs/2210.03629.
[16] Liu Z. Multi-Agent Collaboration in Incident Response with Large Language Models; 2024. arXiv preprint arXiv:2412.00652. Available from: https://arxiv.org/abs/2412.00652.
[17] Li M, Zhao Y, Yu B, et al. API-Bank: A Comprehensive Benchmark for Tool-Augmented LLMs; 2023. arXiv preprint arXiv:2304.08244. Available from: https://arxiv.org/abs/2304.08244.
[18] Qin Y, Liang S, Ye Y, et al. ToolLLM: Facilitating Large Language Models to Master 16000+ Real-World APIs. In: International Conference on Learning Representations; 2024. Available from: https://arxiv.org/abs/2307.16789.
[19] Wang J, Zhou J, Wen M, et al. HammerBench: Fine-Grained Function-Calling Evaluation in Real Mobile Device Scenarios; 2024. arXiv preprint arXiv:2412.16516. Available from: https://arxiv.org/abs/2412.1
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Yunxiao Wang, Haizhuang Liu, Zihan Liu, Haobo Zhao, Fuyang Wei

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.