arXiv:2510.14670cs.AIcs.CL2025-10

让自然语言威胁查询在知识图谱中自动推理,精准定位攻击路径

TITAN: Graph-Executable Reasoning for Cyber Threat Intelligence

  • 用路径规划模型将文本问题转为可执行的逻辑链
  • 在MITRE知识图谱上实现可逆、可验证的推理,准确率显著提升
  • 适合安全研究人员和自动化威胁分析系统使用

TITAN(通过自动化导航实现威胁情报)是一种将自然语言威胁查询与结构化知识图谱上的可执行推理相连接的框架。它集成了一种路径规划模型,用于从文本中预测逻辑关系链,并结合图执行器在TITAN本体上遍历以获取事实答案和支撑证据。与传统检索系统不同,TITAN基于来自MITRE的类型化、双向图,使推理可在威胁、行为与防御之间清晰且可逆地进行。为支持训练与评估,我们构建了TITAN数据集,包含88209个样本(训练集74258,测试集13951),每条数据均配对自然语言问题、可执行推理路径及逐步思维链解释。实证评估表明,TITAN能使模型生成语法正确且语义连贯的推理路径,并可在底层图谱上确定性执行。

原文摘要 · Abstract (English)

TITAN (Threat Intelligence Through Automated Navigation) is a framework that connects natural-language cyber threat queries with executable reasoning over a structured knowledge graph. It integrates a path planner model, which predicts logical relation chains from text, and a graph executor that traverses the TITAN Ontology to retrieve factual answers and supporting evidence. Unlike traditional retrieval systems, TITAN operates on a typed, bidirectional graph derived from MITRE, allowing reasoning to move clearly and reversibly between threats, behaviors, and defenses. To support training and evaluation, we introduce the TITAN Dataset, a corpus of 88209 examples (Train: 74258; Test: 13951) pairing natural language questions with executable reasoning paths and step by step Chain of Thought explanations. Empirical evaluations show that TITAN enables models to generate syntactically valid and semantically coherent reasoning paths that can be deterministically executed on the underlying graph.

威胁情报知识图谱可执行推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。