AI-SOC-FL2: Artificial Intelligence-Enhanced Alert Screening at Security Operation Centers based on Focal Loss and Adaptive Feedback Loop
Tao Ban, Samuel Ndichu, Akira Yamada, Seiichi Ozawa, Takeshi Takahashi, Daisuke Inoue · 2025
Security Operation Center (SOC) analysts face substantial challenges in accurately distinguishing between genuine threats and overwhelming volumes of false positives, given the relative scarcity of malicious events. In this context, we introduce AI-SOC-FL2, an artificial intelligence-driven alert screening framework designed to address the aforementioned imbalance and adapt incrementally to evolving threats in SOC environments. AI-SOC-FL2 leverages focal loss (FL) and an adaptive feedback loop to prioritize rare, high-risk alerts. It employs incremental learning with customized classifiers optimized using FL to enhance sensitivity to hard-to-detect events, while also enhancing model robustness by tuning hyperparameters using Optuna. To preserve robustness over time, AI-SOC-FL2 incorporates the Adaptive Windowing drift detection algorithm to monitor concept drift dynamically. In addition, an active learning module is used to flag ambiguous cases for prioritized SOC analyst feedback. Using a rolling window-based incremental learning strategy, AI-SOC-FL2 updates and refines its threat-detection capabilities continuously. Extensive experiments on the UWF-ZeekData22 benchmark demonstrate that AI-SOC-FL2 achieves superior F1 scores and lower false-positive rates compared to existing approaches, significantly enhancing SOC operational efficiency and improving responses to genuine security threats.