activity
20242026
collaborators

5 papers

cs.CR2026

Towards Agentic Investigation of Security Alerts

Even Eilertsen, Vasileios Mavroeidis, Gudmund Grov

Security analysts are overwhelmed by the volume of alerts and the low context provided by many detection systems. Early-stage investigations typically require manual correlation ac…

cs.CR2026

Detecting and Eliminating Neural Network Backdoors Through Active Paths with Application to Intrusion Detection

Eirik Høyheim, Magnus Wiik Eckhoff, Gudmund Grov +2

Machine learning backdoors have the property that the machine learning model should work as expected on normal inputs, but when the input contains a specific , it…

cs.CR2025

A Graph-Based Approach to Alert Contextualisation in Security Operations Centres

Magnus Wiik Eckhoff, Peter Marius Flydal, Siem Peters +4

Interpreting the massive volume of security alerts is a significant challenge in Security Operations Centres (SOCs). Effective contextualisation is important, enabling quick distin…

cs.CR2025

LLM-Powered Intent-Based Categorization of Phishing Emails

Even Eilertsen, Vasileios Mavroeidis, Gudmund Grov

Phishing attacks remain a significant threat to modern cybersecurity, as they successfully deceive both humans and the defense mechanisms intended to protect them. Traditional dete…

cs.CR2024

Exploring reinforcement learning for incident response in autonomous military vehicles

Henrik Madsen, Gudmund Grov, Federico Mancini +2

Unmanned vehicles able to conduct advanced operations without human intervention are being developed at a fast pace for many purposes. Not surprisingly, they are also expected to s…