An adaptive agentic AI framework for counterfactual validation and adversarial lookahead in automated incident response
Abstract
With rapid growth in AI research, particularly with the use of large language models (LLMs), there has been swift integration of LLMs into security orchestration, automation and response (SOAR) platforms. Nevertheless, all the current tools share a major flaw in the framework, which is to apply the solution from the LLM against the incident caused without considering the potential danger that solutions would bring to existing systems. Furthermore, the tendency of these frameworks to treat threats as static attacks rather than dynamic adversarial processes creates blind execution. The paper presents CIPHER-A (Counterfactual Incident Response Planning with Hallucination-Aware Evaluation and Reasoning — Adaptive), an agentic AI framework that resolves both deficiencies through a two-stage closed-loop pipeline. The first stage, Proposed Counterfactual Validation module will record each LLM-generated action plan against predicted outcome scenarios to produce a Counterfactual Validation Score (CVS) that determines whether to proceed with autonomous execution, a safer modification, or human escalation. The second stage, Adversarial Lookahead stage uses an Attacker Simulation Agent (ASA) to predict adversary state transitions after each executed action and re-validates remaining plan steps against the updated threat model. Evaluated on the DARPA OPTC, MITRE ATT&CK, and CTU-13 datasets, CIPHER-A achieves a 59.2% relative reduction in Response Plan Degradation Rate, a 3.2% false safety rate compared with the baseline SOAR rate of 22.7%, 91.7% escalation accuracy, and a 37.8% reduction in mean time to contain, demonstrating that adaptive sequential re-validation is essential for effective APT incident response.
// Source
Authors: Sheetal Prasad Kizhakel, Sagar Dhanraj Pande
Institutions: Vellore Institute of Technology University, Symbiosis International University