Jul 2026· 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET)· pp. 1-7· 0 citations· 6 references
Abstract
Auditability in high-risk AI requires more than explanation narratives: reviewers must be able to retrieve and verify decision-bound evidence, including the decision record, model/configuration state, explanation artefact, and audit-log event. We propose a lightweight engineering pattern for auditready Explainable AI (XAI) that (i) packages each decision into a compact evidence bundle, (ii) exposes resolvable trace-links to an evidence store, and (iii) validates structural audit readiness through objective, tool-agnostic checks. The check suite covers both run- and decision-level properties, such as evidence presence, bundle completeness, decision coverage, pinning/provenance coverage, trace-link resolution, and audit-log soundness, and can be layered on top of standard Machine Learning Operations (MLOps) tooling. We demonstrate feasibility on a reproducible mini-case (seed-controlled synthetic intrusion detection system (IDS) anomaly detection) and show how the checks support fast localisation of common audit gaps, including missing bindings, stale links, inconsistent pins, and auditor role-based access control (RBAC) resolution failures. In an audited scope of $N=30$ decisions, all required artefacts were present and independently retrievable under an auditor-equivalent access profile, enabling verifiable navigation from decisions to evidence.
Freshness-constrained audit capacity (FCAC) is developed, a decision-support framework that treats automation as an authorization decision constrained by action risk, evidence freshness, and shared review capacity.
Results show that evidence-grounded detection can assess both execution-related and semantic risks in MCP interactions, and compared with existing dynamic scanners, FlowGuard reduces end-to-end latency by up to 2.23x.
Baichao An, Pei Chen, Geng Hong et al.· arXiv.org· 0 citations
An auditability discipline built at production time is specified: git sealing with an anchor lineage, hash-bound provenance, red-line gates that refuse non-compliant artifacts and log every refusal, cross-model role separation, and programmatic assembly from registered sources.
Large language model (LLM) agents can now carry out long-horizon technical workflows involving complex tool use, code execution, file edits, and generated artifacts. As agents do more work faster, the productivity bottleneck shifts from producing outputs to auditing whether those outputs are correct and trustworthy. Agent observability systems make fine-grained execution events visible, but visibility alone still leaves reviewers to reconstruct which actions, artifacts, and validation steps matter for a particular conclusion. We introduce LEDGER - Layered Evidence and Decision Graphs for Execution Review, a tracing and review system that builds layered trace graphs over observed agent sessions. LEDGER preserves Trace Records while grouping them into Evidence Nodes and Workflow Nodes, representing artifacts as evidence anchors, and adding typed semantic edges that connect claims to supporting actions, artifacts, and checks. Through data-analysis and coding examples, we show how the resulting traces expose workflow decisions, artifact lineage, repair steps, validation coverage, and claim-support paths for evidence-centered audit.
Daehong Kim, Hai-Chao Miao, Shusen Liu· 2 citations
Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation history needed to decide whether an individual mapping should be trusted. We present TRACE- CTI, a post-extraction claim-governance framework that preserves run-level Predictions, aggregates them into configuration-level GraphAssertions, materializes setup-deduplicated corroboration as ConsensusAssertions, and exposes only GraphAssertions backed by policy-compliant validation grounds. The framework retains native evidence granularity, complete extraction provenance, versioned trust decisions, and non-destructive revocation history. We evaluate TRACE-CTI on two public CTI corpora comprising 65 reports and 5,303 sentences, using a controlled 2 x 3 matrix of retrievers and generator families, incrementally ingested across six GraphVersions. All setups are incorporated without schema modification; provenance paths remain complete, operational scopes remain disjoint, and every trusted GraphAssertion has an active qualifying validation ground. Cross-generator-family setup pairs exhibit greater output diversity than same-family pairs. At the final graph state, increasing setup support from k>= 1 to six-setup unanimity raises gold-aligned precision from 25.3% to 90.6%, while recall decreases from 88.2% to 16.3%. The graph also directly answers seven questions about provenance, trust, versioning, dependency, disagreement, and review-queue that the evaluated minimal flat output cannot fully answer without enrichment or reprocessing. These results support explicit, auditable governance of extracted TTP claims; the observed corroboration trajectory is descriptive and does not establish statistical independence or a causal model-family effect.
Federico Valletta, G. Longo, E. Russo et al.· arXiv.org· 1 citation
D-RELLM is presented, a defensive reverse-engineering framework for black-box security assessment of deployed LLM applications that treats the deployed application as a socio-technical system whose risk depends on instruction hierarchy, retrieval trust, authorization, tool agency, output handling, monitoring, and operational controls.
Bhavesh B. Prajapati, Bhavya Shah· International journal of com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.