acceptodds
Under review as a conference paper at ICLR 2027

Is a Screenshot Worth a Thousand Tokens? Learning Expert Workflows from SOC Investigations

Abstract

Expert computer workflows contain organizational knowledge that is difficult to preserve and reuse. We investigate whether reconstructing these workflows requires visual inputs or whether compact textual representations can support comparable understanding at lower inference cost. We introduce SOCBench, a benchmark of 86 recorded security operations center (SOC) investigations with paired visual and DOM-based textual representations. Our evaluation framework separately assesses procedural fidelity and summary quality, with reliability examined through cross-judge comparisons and domain-expert assessment. We compare two model families under visual and textual inputs, teacher-supervised fine-tuning, and alternative training-task mixtures. Fine-tuning improves both model families, Qwen-3.5 and Gemma-4, on held-out investigations. For the selected configurations, DOM provides similar observed summary quality while Frames achieves higher procedural fidelity. DOM also reduces mean report-generation latency by 59% on the validation cohort and consumes fewer input tokens. Compact text can therefore support efficient workflow documentation, while visual input retains value for preserving procedural detail.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.