arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.00604cs.CRcs.IR

NeuroGraph:一种用于先进制造中可解释威胁推理的AI图驱动神经符号框架

NeuroGraph: An AI Graph-Driven Neuro-Symbolic Framework for Explainable Threat Reasoning in Advanced Manufacturing

Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim, Iqbal H. Sarker, Helge Janicke

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对先进制造的网络威胁分析难题,提出NeuroGraph框架,采用双LLM架构结合图与神经符号推理,提升了CTI的准确性、可解释性与鲁棒性。

中文摘要 AI 辅助

先进制造中网络物理攻击面日益增长的复杂性使得网络威胁情报(CTI)分析愈发困难。尽管大型语言模型(LLM)和检索增强生成(RAG)改进了CTI工作流程,但基于文本的方法仍易出现幻觉,且对相互关联威胁的结构化推理支持有限。基于图的RAG缓解了部分此类局限,但现有方法往往缺乏本体一致的多跳推理,以及跨异构网络安全数据的透明证据追踪。本文提出一种基于图的神经符号框架,该框架整合了感知本体的符号查询生成、知识图谱检索和神经语言生成,以支持信息技术(IT)与运营技术(OT)环境中准确且可解释的威胁分析。该框架采用双大型语言模型架构:第一个模型将自然语言问题转换为可执行的Cypher查询,用于符号图检索;第二个模型严格基于检索到的图证据生成答案。使用公开可用的网络威胁情报基准进行的实验评估显示,该框架在推理准确性上相比已发表的基线实现了持续提升,同时减少了幻觉、增强了多跳推理能力并提高了对抗扰动的鲁棒性。运行时与可解释性分析进一步表明,该框架保持了交互式推理性能,并暴露了基于图的推理产物,使分析师能够检查和验证分析的每个阶段。总体而言,结果凸显了基于图的神经符号推理作为一种可扩展、可解释且可靠的方法,在下一代工业5.0环境的网络威胁情报领域具有巨大潜力。

英文摘要

The growing complexity of cyber-physical attack surfaces in advanced manufacturing has made cyber threat intelligence analysis increasingly difficult. Although large language models and retrieval-augmented generation have improved CTI workflows, text-based approaches remain vulnerable to hallucinations and provide limited support for structured reasoning over interconnected threats. Graph-based RAG reduces some of these limitations, but existing approaches often lack ontology-consistent multi-hop reasoning and transparent evidence tracing across heterogeneous cybersecurity data. This paper proposes a graph-grounded neuro-symbolic framework that integrates ontology-aware symbolic query generation, knowledge graph retrieval, and neural language generation to support accurate and explainable threat analysis across information technology and operational technology environments. The framework adopts a dual-large language model architecture: the first model translates natural-language questions into executable Cypher queries for symbolic graph retrieval, while the second generates answers strictly from the retrieved graph evidence. Experimental evaluation using publicly available cyber threat intelligence benchmarks shows consistent improvements over the published baseline in reasoning accuracy, while also reducing hallucinations, strengthening multi-hop reasoning, and improving robustness to adversarial perturbations. Runtime and explainability analyses further demonstrate that the framework maintains interactive inference performance and exposes graph-grounded reasoning artifacts that allow analysts to inspect and verify each stage of the analysis. Overall, the results highlight the potential of graph-grounded neuro-symbolic reasoning as a scalable, interpretable, and reliable approach to cyber threat intelligence for next-generation Industry 5.0 environments.

发表机构

  • School of Science (Computing & Security Discipline), Edith Cowan University(伊迪丝考文大学科学与计算与安全学科)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑