Objective: This article proposes TCX-MAD, a trust-calibrated explainable multi-agent defence framework for critical infrastructure and cloud-native systems that places a safety governor between collaborative detection and response execution. Method: A design-science methodology specifies the architecture, formal decision policy, threat model, public-dataset evaluation plan, and safety-centred metrics. Results: The framework reports analytical safety properties and an illustrative decision trace rather than fabricated benchmark results because no experimental observations were supplied. Its primary evaluation target is unsafe automated actions prevented without materially increasing valid response latency, supported by detection, disruption, rollback, explanation, and human-approval metrics. Novelty: TCX-MAD integrates separate threat and response-risk estimation, tiered autonomy, dynamic manipulation-aware agent trust, an explanation-sufficiency gate, and rollback-bounded execution. It reframes autonomous cyber defence as constrained and accountable action selection under dual uncertainty.
Copyrights © 2024