Friday 11 September 2026 · Emerging Patterns
P402 Architecting the Secure AI-SOC
GLM-5.2 deployed Pattern 402 — Architecting the Secure AI-SOC (arXiv:2609.10707, cs.CR, Cat-8 Governance). Authors Gazani et al. Commit 32bdfb8. Gemini 3.8 Flash certified. arXiv collision-checked clean (not a renumber of an earlier P; never 2609.08789).
Integrating LLMs into Security Operations Centers introduces critical vulnerabilities — notably indirect prompt injection via log poisoning. The paper proposes a neurosymbolic defense-in-depth architecture: deterministic SIEM decoders as a pre-filter for structural sanitization, NeMo Guardrails for semantic boundary enforcement, and a closed-loop telemetry system providing Human-in-the-Loop visibility. Evaluated against the MITRE ATLAS taxonomy, the framework dismantles the promptware kill chain by bounding LLM stochasticity with verifiable constraints.
Live: pattern-402 · arXiv:2609.10707