International Journal For Multidisciplinary Research

E-ISSN: 2582-2160     Impact Factor: 9.24

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 8, Issue 4 (July-August 2026) Submit your research before last 3 days of August to publish your research paper in the issue of July-August.

Retrieval-Augmented Detection: Grounding Intrusion Analysis in Historical Incident Corpora

Author(s) Vishal B, Neha Patil
Country India
Abstract Modern security operations centers (SOCs) are saturated with alerts whose disposition depends less on the alert itself than on institutional memory: whether a comparable pattern has been seen before, what it was found to mean, and how it was resolved. That memory exists — in closed tickets, investigation notes, and analyst dispositions — but it is unstructured, weakly indexed, and effectively unavailable at triage time. This paper introduces Retrieval-Augmented Detection (RAD), an architecture in which retrieval over a historical incident corpus participates in the detection decision itself rather than only in post-hoc
narration. RAD contributes four mechanisms: (i) a normalization stage that maps heterogeneous detector output into a common schema suitable for embedding; (ii) hybrid dense–sparse retrieval over analyst-adjudicated incident records with an explicit temporal-decay weighting that discounts precedent drawn from superseded infrastructure; (iii) an evidence-conditioned scoring function in which retrieved precedent modulates detection confidence and every generated assertion carries a provenance link to a specific incident identifier; and (iv) a retrieval-support threshold below which the system abstains rather than emitting an unsupported verdict. We distinguish RAD from prior retrieval-augmented work in IT operations, which applies retrieval after an incident is declared in order to explain it; RAD applies retrieval before disposition in order to decide it. We identify abstention calibration as the central open problem for safe deployment, together with the failure surface a precedent-based architecture inherits — corpus poisoning, precedent staleness, and the systematic bias of a corpus that records only what was previously detected. This paper presents the architecture and formal problem definition; empirical validation is left to future work.
Keywords Intrusion detection, retrieval-augmented generation, security operations, alert triage, large language models, incident response, hallucination, provenance, abstention.
Field Engineering
Published In Volume 8, Issue 4, July-August 2026
Published On 2026-08-05
DOI https://doi.org/10.36948/ijfmr.2026.v08i04.85144

Share this