Survey of trustworthy threat intelligence information extraction based on large models
Received date: 2025-10-10
Online published: 2026-05-06
Copyright
Cyber Threat Intelligence (CTI) analysis techniques can reduce information asymmetry and enhance proactive defense capabilities. Currently, threat intelligence analysis relies primarily on manual expert interpretation, with limited automation and intelligence analysis. This survey systematically reviews research advances in trustworthy threat intelligence information extraction based on large models. First, a comprehensive task framework for trustworthy CTI information extraction is established, followed by an in-depth analysis of core components in the task framework, including data, extraction models, trustworthiness control, and applications. Regarding data, CTI data sources and datasets are categorized and summarized, with an emphasis on novel dataset construction methodologies applicable to large models. For extraction models, research on entity and relation extraction, as well as event and relation extraction, is synthesized, with a focus on advances leveraging large models. Given that trustworthiness directly impacts CTI applications, trustworthiness analysis of large model-based information extraction is further conducted, followed by a systematic review of CTI applications. Drawing on these analyses, challenges are identified and future research directions are proposed. This survey aims to provide a reference framework and research roadmap for large model applications in CTI and advance research on threat intelligence information extraction.
Zhang Yangsen , Xiang Ga , Sun Lu , Qi Rui , Tan Zicheng , Cao Jun , Li Shenghao , Yuan Xiangxiang . Survey of trustworthy threat intelligence information extraction based on large models[J]. Journal of Cybersecurity, 2025 , 3(6) : 2 -18 . DOI: 10.20172/j.issn.2097-3136.250601
表 1 常用CTI数据源信息与分类Table 1 Information and classification of commonly used CTI data sources |
| 结构类型 | 情报内容 | 载体模态特征 | URL示例 | URL描述 |
| 结构化 | 漏洞和缺陷 | 文本/代码片段 | https://nvd.nist.gov/ | 美国国家漏洞数据库 |
| https://cve.mitre.org/ | 通用漏洞披露数据库 | |||
| IoC数据库 | 文本/代码片段 | https://whois.whoisxmlapi.com/ | 域名查询和IP地理定位服务 | |
| https://www.farsightsecurity.com/ | DNS和网络流量分析数据库 | |||
| 半结构化 | 威胁描述平台 | 文本/代码片段 | https://otx.alienvault.com/ | 开放的威胁情报共享平台 |
| https://exchange.xforce.ibmcloud.com/ | IBM威胁情报和漏洞研究平台 | |||
| ATT&CK知识库 | 文本/代码片段 | https://attack.mitre.org/ | 网络攻击战术、技术和过程知识库 | |
| 非结构化 | 政府综合情报报告 | 文本/图像 | https://www.cisa.gov/ | 美国网络安全与基础设施安全公告 |
| https://www.cnnvd.org.cn/ | 中国国家信息安全漏洞库公告 | |||
| https://www.jpcert.or.jp/ | 日本计算机应急响应协调中心公告 | |||
| https://www.cirt.gov.bd/ | 孟加拉国政府计算机事件响应公告 | |||
| 威胁警告和博客等 | 文本/图像 | https://press.kaspersky.com/ | 卡巴斯基网络安全威胁情报 | |
| https://www.trellix.com/ | McAfee和FireEye威胁情报 | |||
| https://www.security.com/ | 博通安全新闻和资源平台 | |||
| https://ti.qianxin.com/ | 奇安信威胁情报中心 | |||
| https://x.threatbook.com/ | 微步在线中文威胁情报社区 |
表 3 基于任务类型的CTI数据集信息与分类Table 3 Information and classification of CTI datasets based on task types |
| 数据集类型 | 任务子类 | 数据集研究 | ||||
| 文献 | 语言 | 偏向主题 | 截止时间 | 数据规模 | ||
| 实体及关系 抽取 | 实体 | [24] | 英文 | — | 2020.8 | 3.6万+实体 |
| [25] | 英文 | APT | 2020.12 | 3.9万+实体 | ||
| [26] | 英文 | — | 2022.12 | 0.45万+实体 | ||
| [27] | 英文 | — | 2023.3 | 0.2万+实体 | ||
| [28] | 中文 | APT工具 | 未开源 | 3.1万+实体 | ||
| 三元组 | [8] | 英文 | APT | 2021.6 | 0.29万+实体 | |
| [29] | 英文 | IoV | 2024.3 | 0.7万+实体和2.3万+三元组 | ||
| [30] | 英文 | IoV | 2025.3 | 0.36万+句问答,0.81万和0.48万三元组 | ||
| [31] | 中文 | — | 2022.10 | 0.42万+实体和0.25万+三元组 | ||
| 事件及关系 抽取 | 事件类型 | [13] | 英文 | — | 2023.5 | 0.1万标注数据和17万+无标注数据 |
| [32] | 英文 | APT | 未开源 | 2阶段,9种事件类型,7种论元,130条实例 | ||
| [33] | 中文 | APT | 未开源 | 3阶段,13种事件类型,5种论元, | ||
| 事件关系 | [34] | 英文 | APT | 未开源 | 14项战术,4种论元,92种规则下的1种事件关系 | |
| TTPs类别 | [35] | 英文 | — | 2022.5 | 1.2万+句子,含188种技术 | |
| [36] | 中英文 | — | 2023.3 | 0.65万+句子,含12战术和184技术 | ||
| [37] | 英文 | — | 2019.9 | 0.17万+样本,12种战术,215技术 | ||
| 多任务融合 分析 | IoC&TTPs | [17] | 英文 | — | 2021.10 | 12种IoC类型,6种技术和6k+TTPs描述 |
| 图谱&TTPs | [18] | 英文 | — | 2023.5 | 58篇报告,179 技术类型, 6类实体和1种依赖关系 | |
| IoC &事件 | [19] | 英文 | — | 2021.1 | 0.4万+句子,7种活动阶段,6种IoC实体,0.3万+触发词 | |
| 面向LLM的 新型数据集 | 大模型标注数据集 | [22] | 英文 | APT | 未开源 | 0.3万+句问答,包含1.2万+实体,1万+关系 |
| 构造指令微调数据集 | [21] | 英文 | — | 2024.7(仅开源人工 校验数据) | 1.5万条主题分类,0.5万条实体关系抽取和6万条 TTPs分类数据集 | |
表 4 基于大模型的CTI实体及关系抽取研究Table 4 Research on entity and relation extraction for CTI based on large models |
| 主流技术 | 概述 | 限制 | 文献 |
| 提示工程 | CRUSH框架采用GPT-3.5/GPT-4等大模型自动生成威胁情报知识图谱(TIG),通过提示工程与RAG增强实现实体抽取、意图识别与TTPs映射,结合语义超网络提升图谱推理能力 | 方法依赖大模型提示质量与上下文长度,存在幻觉与推理偏差风险 | [52] |
| 基于GLM-4大模型,通过指令提示与上下文学习实现CTI报告的重写、实体关系抽取、TTPs识别与状态总结,构建多层耦合的攻击知识图谱 | 仅处理文本,忽略图像等多元信息;LLM在复杂语境下仍存在误判与输出不稳定的问题,影响图谱准确性 | [54] | |
| 通过提示工程引导LLM完成元数据抽取与SPO三元组选择,无需训练即可实现实体与关系抽取 | 关系抽取准确率受限于NER误差累积与LLM生成偏差;三元组质量高度依赖预定义本体,泛化能力有限 | [50] | |
| 采用 GPT-4 的 in-context learning 范式,一次性端到端抽取实体—关系三元组,通过 kNN 检索最优示例并固化在提示中,无需微调即可适配不同本体 | 依赖高质量示范示例,示例错误或格式偏差会显著降低性能;仍需约百级标注样本,零样本下幻觉问题严重 | [49] | |
| 以 GPT-4 为底座,通过双语提示工程将STIX实体/关系模板固化成角色指令,一次性完成零样本三元组抽取 | 目前仅给出少量手工样例,缺乏公开评测集与基线对比;GPT-4 的生成结果未经验证,存在幻觉风险 | [51] | |
| 微调+提示工程 | AECR采用P-Tuning v2微调ChatGLM3-6B,结合词级情报增强与句子级过滤策略,实现CTI报告中攻击技术的精准抽取 | 模型在低样本AT类别上召回率极低,且解释策略粒度较粗,难以处理多义词或同类实体共现的复杂语境 | [53] |
| 采用GPT-3.5进行少样本数据标注与增强,并结合LoRA指令微调Llama2-7B,实现威胁情报的实体抽取、关系抽取与TTPs分类 | 模型在处理长文本和非自然语言内容(如表格)时存在信息遗漏,生成数据存在幻觉,需人工修正提升质量 | [21] |
表 5 基于LLM的威胁情报事件、关系抽取研究Table 5 Research on threat intelligence event and relation extraction based on LLM |
| 主流技术 | 概述 | 限制 | 文献 |
| 提示工程 | 将事件抽取重构为问答任务,采用QA式提示/问题模板,采用预训练的问答模型完成触发词与论元识别(以自然语言问题引导模型直接输出事件要素) | 依赖问题/提示设计与模板工程,对隐式论元与跨句推理能力有限,且对提示敏感,易受wording影响 | [59] |
| 把事件抽取形式化为机器阅读理解(MRC)任务,通过构造问题—上下文对,并采用MRC模型进行触发词与论元抽取 | MRC需要大量任务特定的问答对标注或转换策略,文档级跨句依赖处理能力受限 | [60] | |
| 以 DEGREE 模型为代表,将事件抽取建模为问答对生成任务,结合生成式提示以增强跨域泛化能力(以生成问答对作为输出结构) | 输出需解析为结构化条目,模板/解析管线脆弱;大模型生成的幻觉与不一致性仍是隐患 | [61] | |
| 提出启发式驱动的提示策略,通过示例筛选与结构化提示设计,提升LLM在文档级事件论元抽取中的 in-context 学习效果 | 启发式选择方法通常对语料与领域敏感,缺乏普适性,且缺少对提示鲁棒性的系统性保障 | [62] | |
| 提出QAEVENT框架,将事件抽取建模为问题—答案对生成过程,从提示设计角度强化模型任务对齐能力,提升开放域下的抽取效果 | 需设计高质量示例与提示模板,跨域迁移仍受语义漂移影响 | [63] | |
| 利用大模型的上下文总结与链式推理能力,引入上下文压缩与推理提示机制,在长文本与跨句依赖场景下提升抽取性能 | 依赖高质量演示与推理提示,推理式提示计算代价高,且更易产生不可控的推断或幻觉 | [64] | |
| 微调+提示工程 | 基于条件生成的生成式范式(seq2seq模型,如BART/T5微调),在解码过程中引入条件约束以显式学习跨句依赖,提升文档级论元抽取性能 | 虽提高了样本效率,但仍需一定标注样本与模板设计;对超长文档和复杂跨事件链的建模能力有限 | [65] |
| 引入动态全局记忆机制,将上下文信息存储为可学习参数,以增强文档级跨句建模能力,在长文本条件下提升论元召回率 | 全局记忆带来计算开销与存储开销,记忆管理复杂,长文档中仍可能漏记隐式信息 | [66] | |
| 通过多层信息交互建模策略,构建事件关系图与论元相关图以强化事件与论元的语义耦合性,实现联合抽取与错误传播抑制 | 交互式结构复杂、参数量大,训练与标注成本较高,对稀疏标签与长尾事件泛化有限 | [67] | |
| 提出ADELIE框架,从指令对齐视角构建抽取语料,并采用参数高效微调与偏好优化(SFT与DPO)策略,使大模型在跨域任务中保持稳定的收敛性与鲁棒性 | 指令对齐语料构建成本高且依赖特定指令风格,跨域泛化仍受限 | [68] | |
| 将事件关系预测视为生成/问答式任务,在训练过程中引入逻辑约束优化,以提高结果一致性与可解释性 | 虽可减少流水线误差,但约束化方法在精度与召回间存在权衡,对复杂逻辑关系仍可能不足 | [69] |
| 1 |
冯嘉琦, 高见. 面向网络威胁情报领域的信息抽取综述[J/OL]. 计算机工程[2025-05-23]. https://doi.org/10.19678/j.issn.1000-3428.0070621.
Feng J Q, Gao J. A review of information extraction in the field of cyber threat intelligence [J/OL]. Computer Engineering [2025-05-23]. https://doi.org/10.19678/j.issn.1000-3428.0070621.
|
| 2 |
董聪, 姜波, 卢志刚, 等. 面向网络空间安全情报的知识图谱综述[J]. 信息安全学报, 2020, 5 (5): 56- 76.
Dong C, Jiang B, Lu Z G, et al. Knowledge graph for cyberspace security intelligence: a survey[J]. Journal of Cyber Security, 2020, 5 (5): 56- 76.
|
| 3 |
吴沛颖, 王俊峰, 崔泽源, 等. 网络威胁情报处理方法综述[J]. 四川大学学报(自然科学版), 2023, 60 (5): 7- 24.
Wu P Y, Wang J F, Cui Z Y, et al. A survey of cyber threat intelligence processing method[J]. Journal of Sichuan University (Natural Science Edition), 2023, 60 (5): 7- 24.
|
| 4 |
Jurafsky D, Martin J. Speech and language processing(3rd ed. draft)[M/OL]. Stanford: Stanford University, 2023[2025-09-27]. https://web.stanford.edu/~jurafsky/slp3/.
|
| 5 |
Zhang Y, Zhao X, Ma Y, et al. MM-AttacKG: a multimodal approach to attack graph construction with large language models[J]. arxiv preprint arXiv:, 2506, 16968, 2025.
|
| 6 |
Gao Y, Li X, Peng H, et al. Hincti: a cyber threat intelligence modeling and identification system based on heterogeneous information network[J]. IEEE Transactions on Knowledge and Data Engineering, 2020, 34 (2): 708- 722.
|
| 7 |
Xiao N, Lang B, Wang T, et al. APT-MMF: an advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion[J]. Computers & Security, 2024, 144, 103960.
|
| 8 |
Sarhan I, Spruit M. Open-cykg: an open cyber threat intelligence knowledge graph[J]. Knowledge-based Systems, 2021, 233, 107524.
|
| 9 |
Yan J, Du Z, Li J, et al. A threat intelligence analysis method based on feature weighting and BERT-BiGRU for industrial internet of things[J]. Security and Communication Networks, 2022 (1): 7729456.
|
| 10 |
Ren Y, Xiao Y, Zhou Y, et al. Cskg4apt: a cybersecurity knowledge graph for advanced persistent threat organization attribution[J]. IEEE Transactions on Knowledge and Data Engineering, 2022, 35 (6): 5695- 5709.
|
| 11 |
Piplai A, Mittal S, Joshi A, et al. Creating cybersecurity knowledge graphs from malware after action reports[J]. IEEE Access, 2020, 8, 211691- 211703.
|
| 12 |
Irshad E, Siddiqui A. Cyber threat attribution using unstructured reports in cyber threat intelligence[J]. Egyptian Informatics Journal, 2023, 24 (1): 43- 59.
|
| 13 |
Tang M, Guo Y, Bai Q, et al. Trigger-free cybersecurity event detection based on contrastive learning[J]. The Journal of Supercomputing, 2023, 79 (18): 20984- 21007.
|
| 14 |
Alaeifar P, Pal S, Jadidi Z, et al. Current approaches and future directions for cyber threat intelligence sharing: a survey[J]. Journal of Information Security and Applications, 2024, 83, 103786.
|
| 15 |
Ramsdale A, Shiaeles S, Kolokotronis N. A comparative analysis of cyber-threat intelligence sources, formats and languages[J]. Electronics, 2020, 9 (5): 824.
|
| 16 |
Ai-sada B, Sadighian A, Oligeri G. MITRE ATT&CK: state of the art and way forward[J]. ACM Computing Surveys, 2024, 57 (1): 1- 37.
|
| 17 |
You Y, Jiang J, Jiang Z, et al. TIM: threat context-enhanced TTPs intelligence mining on unstructured threat data[J]. Cybersecurity, 2022, 5 (1): 3.
|
| 18 |
Li Z, Zeng J, Chen Y, et al. AttacKG: constructing technique knowledge graph from cyber threat intelligence reports[C]//European Symposium on Research in Computer Security. Cham. Springer International Publishing, 2022: 589-609.
|
| 19 |
Liu J, Yan J, Jiang J, et al. TriCTI: an actionable cyber threat intelligence discovery system via trigger-enhanced neural network[J]. Cybersecurity, 2022, 5 (1): 8.
|
| 20 |
刘晓明, 李丞正旭, 吴少聪, 等. 文本分类算法及其应用场景研究综述[J]. 计算机学报, 2024, 47 (6): 1244- 1287.
Liu X, Li C, Wu S, et al. A survey of text classification algorithms and application scenarios[J]. Chinese Journal of Computers, 2024, 47 (6): 1244- 1287.
|
| 21 |
Hu Y, Zou F, Han J, et al. LLM-tikg: threat intelligence knowledge graph construction utilizing large language model[J]. Computers & Security, 2024, 145, 103999.
|
| 22 |
Qi R, Xiang G, Zhang Y, et al. A Trustworthy dataset for APT intelligence with an auto-annotation framework[J]. Electronics, 2025, 14 (16): 3251.
|
| 23 |
Kim H. Comparative experiment on TTPs classification with class imbalance using oversampling from CTI dataset[J]. Security and Communication Networks, 2022 (1): 5021125.
|
| 24 |
Wang X, Liu X, Ao S, et al. Dnrti: a large-scale dataset for named entity recognition in threat intelligence[C]//2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, 2020: 1842-1848.
|
| 25 |
Wang X, He S, Xiong Z, et al. Aptner: a specific dataset for ner missions in cyber threat intelligence field[C]//2022 IEEE 25th International Conference on Computer Supported Cooperative Work in Design (CSCWD). IEEE, 2022: 1233-1238.
|
| 26 |
Tanvirul M, Bhusal D, Park Y, et al. Cyner: a python library for cybersecurity named entity recognition[J]. arxiv preprint arXiv:, 2204, 05754, 2022.
|
| 27 |
Marchiori F, Conti M, Verde N, et al. Stixnet: a novel and modular solution for extracting all stix objects in CTI reports[C]//Proceedings of the 18th International Conference on Availability, Reliability and Security. 2023: 1-11.
|
| 28 |
Liu Y, Shi R, Chen Y, et al. APTTOOLNER: a Chinese dataset of cyber security tool for NER task[C]//2023 3rd Asia-Pacific Conference on Communications Technology and Computer Science (ACCTCS). IEEE, 2023: 368-373.
|
| 29 |
Shang W, Wang B, Zhu P, et al. A span-based multivariate information-aware embedding network for joint relational triplet extraction of threat intelligence[J]. Knowledge-Based Systems, 2024, 295, 111829.
|
| 30 |
Wang Y, Ren Y, Qin H, et al. A dataset for cyber threat intelligence modeling of connected autonomous vehicles[J]. Scientific Data, 2025, 12 (1): 366.
|
| 31 |
Zhou Y, Ren Y, Yi M, et al. Cdtier: a Chinese dataset of threat intelligence entity relationships[J]. IEEE Transactions on Sustainable Computing, 2023, 8 (4): 627- 638.
|
| 32 |
Xiang G, Shi C, Zhang Y. An APT event extraction method based on BERT-BiGRU-CRF for APT attack detection[J]. Electronics, 2023, 12 (15): 3349.
|
| 33 |
曹骏, 向尕, 任亚唯, 等. 基于大模型的少样本APT攻击事件抽取方法[J]. 信息网络安全, 2025, 25 (9): 1338- 1347.
Cao J, Xiang G, Ren Y W, et al. Small-sample APT attack event extraction method based on large model[J]. Netinfo Security, 2025, 25 (9): 1338- 1347.
|
| 34 |
张宇翔, 韩久江, 刘建, 等. ATT&CK框架下基于事件序列关联的网络高级威胁检测系统[J]. 计算机科学, 2023, 50 (S1): 710- 716.
Zhang Y X, Han J J, Liu J, et al. Network advanced threat detection system based on event sequence correlation under ATT&CK framework[J]. Computer Science, 2023, 50 (S1): 710- 716.
|
| 35 |
Orbinato V, Barbaraci M, Natella R, et al. Automatic maping of unstructured cyber threat intelligence: an experimental study: (practical experience report)[C]//2022 IEEE 33rd International Symposium on Software Reliability Engineering (ISSRE). IEEE, 2022: 181-192.
|
| 36 |
Ge W, Wang J. SeqMask: behavior extraction over cyber threat intelligence via multi-instance learning[J]. The Computer Journal, 2024, 67 (1): 253- 273.
|
| 37 |
Legoy V, Caselli M, Seifert C, et al. Automated retrieval of att&ck tactics and techniques for cyber threat reports[J]. arxiv preprint arXiv:, 2004, 14322, 2020.
|
| 38 |
Luo Y, Ao S, Luo N, et al. Extracting threat intelligence relations using distant supervision and neural networks[C]//Advances in Digital Forensics XVII: 17th IFIP WG 11.9 International Conference, Virtual Event, Springer International Publishing, 2021: 193-211.
|
| 39 |
葛文翰, 王俊峰, 唐宾徽, 等. 基于关联增强的网络威胁情报技战术分类[J]. 四川大学学报(自然科学版), 2022, 59 (2): 100- 108.
Ge W, Wang J, Tang B, et al. RENet: tactics and techniques classifications for cyber threat intelligence with relevance enhancement[J]. Journal of Sichuan University (Natural Science Edition), 2022, 59 (2): 100- 108.
|
| 40 |
Ge W, Wang J, Lin T, et al. Explainable cyber threat behavior identification based on self-adversarial topic generation[J]. Computers & Security, 2023, 132, 103369.
|
| 41 |
李冬梅, 张扬, 李东远, 等. 实体关系抽取方法研究综述[J]. 计算机研究与发展, 2020, 57 (7): 1424- 1448.
Li D M, Zhang Y, Li D Y, et al. Review of entity relation extraction methods[J]. Journal of Computer Research and Development, 2020, 57 (7): 1424- 1448.
|
| 42 |
Yi F, Jiang B, Wang L, et al. Cybersecurity named entity recognition using multi-modal ensemble learning[J]. IEEE Access, 2020, 8, 63214- 63224.
|
| 43 |
ZHANG S, CHEN P, BAI G, et al. An automatic assessment method of cyber threat intelligence combined with ATT&CK matrix[J]. Wireless Communications and Mobile Computing, 2022, 2022 (1): 7875910.
|
| 44 |
Shafiq M, Tian Z, Bashir A, et al. CorrAUC: a malicious bot-IoT traffic detection method in IoT network using machine-learning techniques[J]. IEEE Internet of Things Journal, 2020, 8 (5): 3242- 3254.
|
| 45 |
Kim G, Lee C, Jo J, et al. Automatic extraction of named entities of cyber threats using a deep Bi-LSTM-CRF network[J]. International Journal of Machine Learning and Cybernetics, 2020, 11 (10): 2341- 2355.
|
| 46 |
Jo H, Lee Y, Shin S. Vulcan: automatic extraction and analysis of cyber threat intelligence from unstructured text[J]. Computers & Security, 2022, 120, 102763.
|
| 47 |
Zhou Y, Tang Y, Yi M, et al. CTI view: APT threat intelligence analysis system[J]. Security and Communication Networks, 2022 (1): 9875199.
|
| 48 |
Zhen Z, Gao J. Chinese cyber threat intelligence named entity recognition via RoBERTa-wwm-RDCNN-CRF[J]. Computers, Materials & Continua, 2023, 77(1).
|
| 49 |
Cheng Y, Bajaber O, Tsegai S A, et al. Ctinexus: automatic cyber threat intelligence knowledge graph construction using large language models[C]//2025 IEEE 10th European Symposium on Security and Privacy (EuroS&P). IEEE, 2025: 923-938.
|
| 50 |
Liu J, Zhan J. Constructing knowledge graph from cyber threat intelligence using large language model[C]//2023 IEEE International Conference on Big Data (BigData). IEEE, 2023: 516-521.
|
| 51 |
马冰琦, 周盈海, 王梓宇, 等. 一种基于大语言模型的威胁情报信息抽取方法[J]. 网络空间安全科学学报, 2024, 2 (2): 36- 46.
Ma B Q, Zhou Y H, Wang Z Y, et al. A LLMs-based method for threat intelligence information extraction[J]. Journal of Cybersecurity, 2024, 2 (2): 36- 46.
|
| 52 |
Sewak M, Emani V, Naresh A. CRUSH: cybersecurity research using universal LLMs and semantic hypernetworks[C]//EKG-LLM@ CIKM. 2023. Birmingham: ACM, 2023:1172-1179.
|
| 53 |
Chen M, Zhu K, Lu B, et al. AECR: Automatic attack technique intelligence extraction based on fine-tuned large language model[J]. Computers & Security, 2025, 150, 104213.
|
| 54 |
Zhang Y, Du T, Ma Y, et al. AttacKG+: Boosting attack graph construction with large language models[J]. Computers & Security, 2025, 150, 104220.
|
| 55 |
Gao J, Luo X, Wang H. Chinese causal event extraction using causality-associated graph neural network[J]. Concurrency and Computation: Practice and Experience, 2022, 34 (3): e6572.
|
| 56 |
Huang H, Chen Y, Lin C, et al. A multi-graph representation for event extraction[J]. Artificial Intelligence, 2024, 332, 104144.
|
| 57 |
Zhuang L, Fei H, Hu P. Syntax-based dynamic latent graph for event relation extraction[J]. Information Processing & Management, 2023, 60 (5): 103469.
|
| 58 |
Li H, Geng D. GraphERE: jointly multiple event-event relation extraction via graph-enhanced event embeddings[J]. arXiv preprint arXiv:, 2403, 12523, 2024.
|
| 59 |
Du X, Cardie C. Event extraction by answering (almost) natural questions[J]. arXiv preprint arXiv:, 2004, 13625, 2020.
|
| 60 |
Liu J, Chen Y, Liu K, et al. Event extraction as machine reading comprehension[C]//Proceedings of the 2020 conference on Empirical Methods in Natural Language Processing (EMNLP), Association for Computational Linguistics, 2020: 1641-1651.
|
| 61 |
Hsu I, Huang K , Boschee E, et al. DEGREE: a data-efficient generation-based event extraction model[J]. arXiv preprint arXiv:, 2108, 12724, 2021.
|
| 62 |
Zhou H, Qian J, Feng Z, et al. LLMs learn task heuristics from demonstrations: a heuristic-driven prompting strategy for document-level event argument extraction[J]. arXiv preprint arXiv:, 2311, 06555, 2023.
|
| 63 |
Choudhary M, Du X. Qaevent: Event extraction as question-answer pairs generation[C]//European Chapter of the Association for Computational Linguistics(EACL), Association for Computational Linguistics, 2024: 1860-1873.
|
| 64 |
Shuang K, Zhou J, Wang Q, et al. Utilizing contextual summarizing and reasoning for enhancing document-level event argument extraction[J]. Expert Systems with Applications, 2025: 128075.
|
| 65 |
Li S, Ji H, Han J. Document-level event argument extraction by conditional generation[J]. arXiv preprint arXiv:, 2104, 05919, 2021.
|
| 66 |
Du X, Li S, Ji H. Dynamic global memory for document-level argument extraction[J]. arXiv preprint arXiv:, 2209, 08679, 2022.
|
| 67 |
Pan B, Li Y, Wang S, et al. Document-level event extraction via information interaction based on event relation and argument correlation[C]//Proceedings of the 2024 Joint International Conference on Computational Linguistics, Language Resources and Evaluation. 2024: 5156-5166.
|
| 68 |
Qi Y, Peng H, Wang X, et al. Adelie: Aligning large language models on information extraction[J]. arXiv preprint arXiv:, 2405, 05008, 2024.
|
| 69 |
Chen M, Ma Y, Song K, et al. Improving large language models in event relation logical prediction[J]. arXiv preprint arXiv:, 2310, 09158, 2023.
|
| 70 |
Han Y, Han W, Li A, et al. Cyberattack event and arguments extraction based on feature interaction and few-shot learning[J]. Scientific Reports, 2025, 15 (1): 31808.
|
| 71 |
Chatziamanetoglou D, Rantos K. Weighted quality criteria for cyber threat intelligence: assessment and prioritisation in the MISP data model[J]. International Journal of Information Security, 2025, 24 (4): 160.
|
| 72 |
Dimitriadis A, Papoutsis A, Kavalieros D, et al. EVACTI: evaluating the actionability of cyber threat intelligence[J]. International Journal of Information Security, 2025, 24 (3): 123.
|
| 73 |
Ainslie S, Thompson D, Maynard S, et al. Cyber threat intelligence for security decision-making: a review and research agenda for practice[J]. Computers & Security, 2023, 132, 103352.
|
| 74 |
Rajapaksha S, Rani R, Karafili E. A RAG-based question-answering solution for cyber-attack investigation and attribution[C]//European Symposium on Research in Computer Security. Cham: Springer Nature Switzerland, 2024: 238-256.
|
| 75 |
Shah S, Madisetti V. MAD-CTI: cyber threat intelligence analysis of the dark web using a multi-agent framework[J]. IEEE Access, 2025, 13, 40158- 40168.
|
| 76 |
Loevenich J, Adler E, Huerten T, et al. Design and evaluation of an autonomous cyber defence agent using DRL and an augmented LLM[J]. Computer Networks, 2025, 262, 111162.
|
| 77 |
Guan Y, Peng H, Hou L, et al. MMD-ERE: multi-agent multi-sided debate for event relation extraction[C]//Proceedings of the 31st International Conference on Computational Linguistics, Association for Computational Linguistics. 2025: 6889-6896.
|
| 78 |
Dunnett K, Pal S, Jadidi Z, et al. Priv-share: a privacy-preserving framework for differential and trustless delegation of cyber threat intelligence using blockchain[J]. Computer Networks, 2024, 252, 110686.
|
| 79 |
Riesco R, Larriva-Novo X, Villagra V. Cybersecurity threat intelligence knowledge exchange based on blockchain: proposal of a new incentive model based on blockchain and smart contracts to foster the cyber threat and risk intelligence exchange of information[J]. Telecommunication Systems, 2020, 73 (2): 259- 288.
|
| 80 |
Chatziamanetoglou D, Rantos K. Cyber threat intelligence on blockchain: a systematic literature review[J]. Computers, 2024, 13 (3): 60.
|
| 81 |
Gao P, Liu X, Choi E, et al. A system for automated open-source threat intelligence gathering and management[C]//Proceedings of the 2021 International Conference on Management of Data. Association for Computing Machinery, 2021: 2716-2720.
|
| 82 |
Fieblinger R, Alam M, Rastogi N. Actionable cyber threat intelligence using knowledge graphs and large language models[C]//2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW). IEEE, 2024: 100-111.
|
| 83 |
Huang L, Xiao X. Ctikg: LLM-powered knowledge graph construction from cyber threat intelligence[C]//First Conference on Language Modeling. 2024.
|
| 84 |
Pan S, Luo L, Wang Y, et al. Unifying large language models and knowledge graphs: a roadmap[J]. IEEE Transactions on Knowledge and Data Engineering, 2024, 36 (7): 3580- 3599.
|
/
| 〈 |
|
〉 |