International Journal For Multidisciplinary Research
E-ISSN: 2582-2160
•
Impact Factor: 9.24
A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal
Home
Research Paper
Submit Research Paper
Publication Guidelines
Publication Charges
Upload Documents
Track Status / Pay Fees / Download Publication Certi.
Editors & Reviewers
View All
Join as a Reviewer
Get Membership Certificate
Current Issue
Publication Archive
Conference
Publishing Conf. with IJFMR
Upcoming Conference(s) ↓
Conferences Published ↓
DePaul-2026
IC-AIRCM-T3-2026
NSSFIGTMA-2025
SPHERE-2025
AIMAR-2025
SVGASCA-2025
ICCE-2025
Chinai-2023
PIPRDA-2023
ICMRS'23
Contact Us
Plagiarism is checked by the leading plagiarism checker
Call for Paper
Volume 8 Issue 4
July-August 2026
Indexing Partners
Retrieval-Augmented Detection: Grounding Intrusion Analysis in Historical Incident Corpora
| Author(s) | Vishal B, Neha Patil |
|---|---|
| Country | India |
| Abstract | Modern security operations centers (SOCs) are saturated with alerts whose disposition depends less on the alert itself than on institutional memory: whether a comparable pattern has been seen before, what it was found to mean, and how it was resolved. That memory exists — in closed tickets, investigation notes, and analyst dispositions — but it is unstructured, weakly indexed, and effectively unavailable at triage time. This paper introduces Retrieval-Augmented Detection (RAD), an architecture in which retrieval over a historical incident corpus participates in the detection decision itself rather than only in post-hoc narration. RAD contributes four mechanisms: (i) a normalization stage that maps heterogeneous detector output into a common schema suitable for embedding; (ii) hybrid dense–sparse retrieval over analyst-adjudicated incident records with an explicit temporal-decay weighting that discounts precedent drawn from superseded infrastructure; (iii) an evidence-conditioned scoring function in which retrieved precedent modulates detection confidence and every generated assertion carries a provenance link to a specific incident identifier; and (iv) a retrieval-support threshold below which the system abstains rather than emitting an unsupported verdict. We distinguish RAD from prior retrieval-augmented work in IT operations, which applies retrieval after an incident is declared in order to explain it; RAD applies retrieval before disposition in order to decide it. We identify abstention calibration as the central open problem for safe deployment, together with the failure surface a precedent-based architecture inherits — corpus poisoning, precedent staleness, and the systematic bias of a corpus that records only what was previously detected. This paper presents the architecture and formal problem definition; empirical validation is left to future work. |
| Keywords | Intrusion detection, retrieval-augmented generation, security operations, alert triage, large language models, incident response, hallucination, provenance, abstention. |
| Field | Engineering |
| Published In | Volume 8, Issue 4, July-August 2026 |
| Published On | 2026-08-05 |
| DOI | https://doi.org/10.36948/ijfmr.2026.v08i04.85144 |
Share this

E-ISSN 2582-2160
CrossRef DOI prefix of IJFMR is 10.36948/ijfmr
All research papers published on this website are licensed under Creative Commons Attribution-ShareAlike 4.0 International License, and all rights belong to their respective authors/researchers.
Powered by Sky Research Publication and Journals