Article contents
Explainable and Risk-Aware AI for Autonomous Cyber Defense and Reliable Incident Response Across U.S. Public and Enterprise Digital Services: The XR-ACD Framework
Abstract
The scale, velocity and complexity of cyber threats are growing, and with them there are new challenges for security teams tasked with defending public and enterprise digital services. Artificial intelligence (AI) can speed up the discovery, investigation and response process to threats, but a second risk is often overlooked: autonomous response may disrupt service, impact critical dependencies, or have irreversible effects if the assessment is wrong. The paper presents a conceptual framework for an autonomous cyber defense process, Explainable and Risk-Aware Autonomous Cyber Defense (XR-ACD), which combines explainable threat assessment, explicit action-risk evaluation, risk-proportional autonomy, and continuous governance. While some methods rely mainly on the size of the threat or on the confidence of the model to trigger automatic responses, XR-ACD differentiates between the risk of the threat and the risk of responding to the threat and considers both risks before allowing autonomous action. Action risk is represented with asset criticality, blast radius, dependency impact, operational impact, uncertainty and reversibility. These factors are linked to four response modalities: autonomous execution, bounded or supervised autonomy, human-in-the-loop decision making and human authorization. The framework also includes user-friendly explanations, policy limitations, audit reports, outcome tracking, and feedback-driven risk reassessment. In a municipal water-treatment IT/OT scenario, the same detected threat can trigger various response authorities, depending on the operational consequences of candidate actions. The paper proposes a comparative evaluation methodology that includes threat-severity-only automation, human-led response, XR-ACD without explainability and the complete XR-ACD configuration, for future empirical validation. The criteria for evaluation are response latency, containment effectiveness, inappropriate high-impact action rate, disruption to operations, human intervention, quality of explanation, and trust calibration. The paper provides a structured framework for safer autonomous cyber defense and lays the groundwork for empirical analysis of risk-proportional autonomy in public and enterprise digital services.

Aims & scope
Call for Papers
Article Processing Charges
Publications Ethics
Google Scholar Citations
Recruitment