AI improves layered cyber defense but full human review reduces accuracy

Toward Responsible AI-Augmented Cyber Defense: Pattern Recognition, Defense-in-Depth, and the Case for Human-AI Collaboration

Cryptography and SecurityArtificial Intelligence

Summary

Detecting and stopping cyber attacks is hard and often uses multiple layers of security. This paper shows how using AI in these layers can multiply the chances of catching threats, especially where traditional defenses stop improving. However, having humans review every AI alert can actually lower overall detection because humans make mistakes, and reviewing fewer, filtered alerts strikes a better balance. The authors provide a clear model to find the best mix of AI and human effort in cybersecurity teams.

What this means in practice

  • For security operations teams: Optimize the balance between AI alerts and human analyst review to improve cyber threat detection and reduce false alarms in layered defense systems.
  • For industrial control system security teams: Apply modeled human-AI collaboration to secure IT/OT convergence with quantifiable trade-offs to better protect critical infrastructure environments.

Authors

Mustafa S. Aljumaily, Hayder Kareem Abed, Nawar S. Alseelawi

Abstract

Cybersecurity literature has extensively documented the operational benefits of artificial intelligence (AI) for threat detection, incident response, and prevention, while raising qualitative concerns about over-automation, algorithmic bias, and analyst-skill erosion. What remains largely absent is a formal, falsifiable model connecting three constructs that recur across this literature: Defense-in-Depth Theory, the Artificial Intelligence Theory of Pattern Recognition, and human-AI collaboration in security operations. This paper develops such a model. We formalize layered defense as a Bernoulli detection cascade in which AI augmentation enters multiplicatively across layers; we formalize each layer's pattern-recognition behavior as a Neyman-Pearson/Bayesian detector with a derived closed-form optimal threshold; and we formalize human-AI triage as a capacity-constrained cascade with an explicit, quantifiable trade-off between detection probability and false-alarm ("alert fatigue") rate. A Monte Carlo/analytical simulation evaluated at illustrative but realistic operating points shows that (i) AI augmentation compounds across defense layers, delivering its largest marginal gains exactly where traditional layering saturates, and (ii) full human review of AI-flagged alerts is not optimal: increasing analyst capacity toward 100% coverage cuts false alarms by roughly 20-fold but simultaneously lowers system-level detection probability, because imperfect analyst accuracy is then applied to every alert rather than a filtered subset. These results give the widely repeated qualitative recommendation of "balanced human-AI collaboration" a precise, testable form and suggest an interior-optimum capacity ratio as a concrete design target for security operations centers (SOCs), including those securing IT/OT-converged critical infrastructure.