Correlating Weak Signals Paged a Synthetic Agentic Intrusion Before Any Secret Was Read
Yassine Bentayfor · Team Signal Before Severity
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
AgentPage is an auditable, sequence aware paging detector for machine speed AI incidents. It correlates distinct suspicious telemetry categories on one host within a sliding window, allowing weak signals to trigger escalation before any single event becomes severe. I compared it with critical only, high severity, and rate only baselines across three canonical synthetic streams and 90 deterministic variants. AgentPage detected all 30 constructed intrusions and paged 106 seconds earlier on average than high severity paging, before secret access in every attack variant. This gain caused six false pages among 60 benign variants. Ablations showed that category deduplication prevents repeated alerts from impersonating independent evidence, while the diversity bonus creates both the earlier warning and its false page cost. The code, data, tests, figures, and results are fully reproducible.

Reviews
The main gap is positioning. This is risk-based alerting, and Splunk Enterprise Security ships both key mechanisms as default correlation searches — "ATT&CK Tactic Threshold Exceeded" fires on tactic_count >= 3 AND source_count >= 4, which is the diversity bonus, and dc(tactic) is category deduplication. Sentinel, Exabeam, and Chronicle have equivalents. No related work engages with any of it, so a reader from a SOC will see apparent reinvention.
Both headline metrics are constructed. TPR 1.000 is guaranteed by scenario design; FPR 0.100 is the fraction of benign variants deliberately built to be hard; the 106 seconds depends on where severity labels were placed. The limitations acknowledge the general problem but should connect it to these specific numbers.
The paper tackles the right gap: in the real incident the signals were correlated but nobody was paged. The ablations are honest and they show the diversity bonus causes both the 106-second gain and all six false pages, and that the rate bonus does nothing.
Cite this project
@misc{bentayfor2026correlating,
title = {{Correlating Weak Signals Paged a Synthetic Agentic Intrusion Before Any Secret Was Read}},
author = {Yassine Bentayfor},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/correlating-weak-signals-paged-a-synthetic-agentic-intrusion-before-any-secret-was-read-flwi}},
url = {https://apartresearch.com/sprints/projects/correlating-weak-signals-paged-a-synthetic-agentic-intrusion-before-any-secret-was-read-flwi}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …