Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:
ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Back to Paper
cs.CR

Local ID: 2605.08316v2

AI Summary: gemma4:e4b

AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Survey

By Samuel Ndichu, Tao Ban, Seiichi Ozawa, Takeshi Takahashi, Daisuke Inoue

Revision History Timeline

v15/8/2026
5/8/2026

“35 pages, 5 figures, 9 tables. Submitted to ACM Computing Surveys. Supplementary material (11 pages) and artifact bundle available as ancillary files”

v25/18/2026
5/18/2026

“34 pages, 3 figures, 12 tables. Submitted to ACM Computing Surveys. v2: title shortened to "A Survey"; restructured taxonomy section; captions and acronym handling aligned with ACM CSUR style; bibliography updated to 174 entries”

★ Version indexed in Explorer

Comparing v1 vs v2

Green = Added • Red = Removed

Title Comparison

AI-Driven Security Alert Screening and Alert Fatigue Mitigation in Security Operations Centers: A Comprehensive Survey

Authors Comparison

Removed:Akira Yamada
Unchanged:Samuel Ndichu, Tao Ban, Seiichi Ozawa, Takeshi Takahashi, Daisuke Inoue

v1 Comment

“35 pages, 5 figures, 9 tables. Submitted to ACM Computing Surveys. Supplementary material (11 pages) and artifact bundle available as ancillary files”

v2 Comment

“34 pages, 3 figures, 12 tables. Submitted to ACM Computing Surveys. v2: title shortened to "A Survey"; restructured taxonomy section; captions and acronym handling aligned with ACM CSUR style; bibliography updated to 174 entries”

Abstract Word Diff

Security alert screening is the downstream task of filtering, prioritizing, correlating, and contextualizing alerts for analyst attention in Security Operations Centers. This survey reviews artificial-intelligence-driven alert screening and alert-fatigue mitigation from 2015 to 2026. We synthesize 119 records, including 87 core studies, into a four-stage workflow taxonomy covering filtering, triage, correlation, and generative augmentation. We find persistent gaps in deploymentoperational realism,validation, adversarial robustness, cross-environment validation,generalization, and evaluation practice. The survey concludes with a research agenda toward trustworthy Cognitive Security Operations Centers.
View Full Version History on arXiv