Yongheng Zhang 0002

dblp:240/6658-2 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0002-8787-4995ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Debapt: Ontology-driven multi-agent debate for APT adversary profile construction from cyber threat intelligence
abstract
Cyber threat intelligence (CTI) reports contain rich information about advanced persistent threat (APT) groups. This information is useful for adversary profile construction. However, turning long and fragmented CTI reports into structured adversary profiles remains difficult. Existing methods mainly rely on named entity and relation extraction pipelines or single large language models (LLMs). These methods often lack explicit semantic constraints for profile-oriented tasks. They are also prone to omission and hallucination when processing long reports. In this paper, we study APT adversary profile construction from CTI reports. We formulate this task as an ontology-constrained profile information extraction task. To support this task, we develop VICTOR, a domain-specific ontology that organizes profile-relevant information into six dimensions. We then propose Debapt, an ontology-driven multi-agent debate framework. Guided by VICTOR, Debapt performs APT adversary profile construction through two debate loops in the entity extraction phase and relation extraction phase. In each loop, role-specialized agents iteratively extract, review, and adjudicate candidate profile-relevant facts under moderator supervision. These extracted results can be further aggregated across reports to support actor-centric adversary profile construction. To evaluate Debapt, we re-annotate three public CTI datasets under a unified profiling schema. Experimental results show that Debapt improves profile-oriented entity and relation extraction over competitive baselines. It extracts more complete and better grounded profile-relevant facts from CTI reports. Case studies further show that these extracted results can support the construction of analytically useful adversary profiles.
Xinyun Zhao, Lanlan Qi, Yongheng Zhang 0002, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang 0010
Comput. Secur.3
2026 MM-AttacKG: A multimodal approach to attack graph construction with large language models
abstract
Cyber Threat Intelligence (CTI) parsing aims to extract key threat information from massive data, transform it into actionable intelligence, enhance threat detection and defense efficiency, including attack graph construction, intelligence fusion, and indicator extraction. Among these research topics, Attack Graph Construction (AGC) is essential for visualizing and understanding the potential attack paths of threat events from CTI reports. Existing approaches primarily construct the attack graphs purely from the textual data to reveal the logical threat relationships between entities within the attack behavioral sequence. However, they typically overlook the specific threat information inherent in visual modalities, which preserves key threat details from inherently multimodal CTI reports. Inspired by the remarkable multimodal understanding capabilities of Multimodal Large Language Models (MLLMs), we explore their potential in enhancing multimodal attack graph construction. To be specific, we propose a novel framework, MM-AttacKG, which can effectively extract key information from threat images and integrate it into attack graph construction, thereby enhancing the comprehensiveness and accuracy of attack graphs. It first employs a threat image parsing module to extract critical threat information from images and generate textual descriptions using MLLMs. Subsequently, it builds an iterative question-answering pipeline tailored for image parsing to refine the understanding of threat images. Finally, it achieves content-level integration between attack graphs and image-based answers through MLLMs, completing threat information enhancement. We construct a new multimodal dataset, AG-LLM-mm, and conduct extensive experiments to evaluate the effectiveness of MM-AttacKG. The results demonstrate that MM-AttacKG can accurately identify key information in threat images and significantly improve the quality of multimodal attack graph construction, effectively addressing the shortcomings of existing methods in utilizing image-based threat information. The code and the corresponding dataset will be released upon acceptance.
Yongheng Zhang 0002, Xinyun Zhao, Yunshan Ma 0002, Haokai Ma, Yingxiao Guan, Guozheng Yang, Yuliang Lu, Xiang Wang 0010
Knowl. Based Syst.1
2025 AttacKG+: Boosting attack graph construction with Large Language Models
abstract
Attack graph construction seeks to convert textual cyber threat intelligence (CTI) reports into structured representations, portraying the evolutionary traces of cyber attacks. Even though previous research has proposed various methods to construct attack graphs, they generally suffer from limited generalization capability to diverse knowledge types as well as requirement of expertise in model design and tuning. Addressing these limitations, we seek to utilize Large Language Models (LLMs), which have achieved enormous success in a broad range of tasks given exceptional capabilities in both language understanding and zero-shot task fulfillment. Thus, we propose a fully automatic LLM-based framework to construct attack graphs named: AttacKG + . Our framework consists of four consecutive modules: rewriter, parser, identifier, and summarizer, each of which is implemented by instruction prompting and in-context learning empowered by LLMs. Furthermore, we upgrade the existing attack knowledge schema and propose a comprehensive version. We represent a cyber attack as a temporally unfolding event, each temporal step of which encapsulates three layers of representation, including behavior graph, MITRE TTP labels, and state summary. Extensive evaluation demonstrates that: (1) our formulation seamlessly satisfies the information needs in threat event analysis, (2) our construction framework is effective in faithfully and accurately extracting the information defined by AttacKG + . and (3) our attack graph directly benefits downstream security practices such as attack reconstruction. All the code and datasets will be released upon acceptance.
Yongheng Zhang 0002, Tingwen Du, Yunshan Ma 0002, Xiang Wang 0010, Guozheng Yang, Yuliang Lu, Ee-Chien Chang
Comput. Secur.1