Your Monitor Will Explain the Breach and Not Wake You Bimodal failure and systematic under-escalation in LLM incident triage
Amirtha Yazhini M, Praneeth Reddy Yeddula
We rebuilt the July 2026 Hugging Face agent-intrusion as a replayable 17,613-action stream from the two published post-mortems, paired with a validated size-matched benign control, and tested 15 LLMs across 3 providers as automated SOC triage monitors. We find that models fail bimodally: some achieve high recall only by paging on nearly every benign window (worthless, alert-fatigue-inducing), while others page on almost nothing, missing an active intrusion entirely — the useful "high recall, low false-page" region is essentially empty, and model scale does not fix it. A second experiment holding evidence byte-identical across a "monitor" vs. "assistant" frame found the expected failure (refusal) never occurred — but revealed a one-directional asymmetry instead: models assisted with analysis in 228/228 moments while escalating in only 83/228. The risk in AI-assisted SOC monitoring is not that models refuse to help — it's that they analyze fluently while the pager stays silent. All code, the corpus generator, ground truth, pre-registration, and raw decision records are public and regenerable.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Your Monitor Will Explain the Breach and Not Wake You Bimodal failure and systematic under-escalation in LLM incident triage
},
author={
Amirtha Yazhini M, Praneeth Reddy Yeddula
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


