D3CISIONProject file 05 of 10
back to library
05D3CISION

Security triage · evaluation · research

Role
Hackathon team contributor; research follow-on
2nd PlaceOpen team repository

Awarded team prototype · research follow-on

We shipped the prototype.
Then questioned the model.

I built the hackathon's data-to-investigation loop, then helped turn its weak evaluation into a stricter research question.

  1. Ship
  2. Correlate
  3. Score
  4. Stress test
  5. Explain
  6. Bound
Engineering evidence
Evidence receiptStress test
  • BASELINERandom rows
  • TIMEChronological
  • SENSORNew detector
  • ORGNew organization

Results held until artifacts are mapped

Draft research methodOpen team repository
Swipe through the evidence04 / 06
  1. Four contributors connected data, scoring, explanations, and a working dashboard during the hackathon.

    TEAMFour contributors
    DEMOWorking dashboard
    AWARD2nd Place
    Hackathon prototype
  2. The public prototype grouped nearby rows; the research design replaces that batch shortcut with bounded, past-only state.

    TOKENSEntity + context
    STATEActive stories
    BOUNDSExpiry + suppression
    Not in the public prototype
  3. A tree model ranks the queue; the interface keeps its grade, confidence, and local drivers visible.

    POLICYAllow / block fields
    MODELIncident grade
    QUEUEPriority + drivers
    Prototype metric is exploratory
  4. The research plan tests the same estimator across time, detector, and organization boundaries.

    BASELINERandom rows
    TIMEChronological
    SENSORNew detector
    ORGNew organization
    Results held until artifacts are mapped
  5. The research design tests whether SHAP drivers stay stable and actually affect the fitted model.

    STABILITYCompare driver ranks
    DELETERemove top drivers
    KEEPRetain top drivers
    Results held until artifacts are mapped
  6. A local LLM receives a selected evidence packet only after deterministic triage.

    PACKETPrediction + SHAP + story
    LOCALSelected cases only
    CHECKSchema + claim IDs
    No analyst-outcome claim
System viewThe evaluation boundary is chosen before the metricThe draft research plan keeps one model family fixed while changing only what the test set is allowed to share with training.
Fixed model familyEvaluation boundariesDeployment claimbounded usedo not assume
controlSame estimatorstrict feature policy
baselineRandom rowssame-population baseline
time shiftChronologicalfuture-window check
sensor shiftHeld-out detectornew sensor family
org shiftHeld-out organizationnew environment
allowedBounded claimname the tested setting
heldTransfer claimrequires new evidence