EDBT 2026 Demo / reviewers in the wild / expert
Inoussa Mouiche
dblp:384/6315
· DBLP profile ↗
5ranked-venue papers
5as first author
5since 2021 · last 2026
0009-0008-8024-7631ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TI-NERmergerV2: Automating the integration of threat intelligence NER datasets via STIX standardabstractQuality-labeled data are essential for developing accurate AI models in cybersecurity, particularly for threat intelligence named entity recognition (TI-NER), which automates the extraction of threat indicators and entities from unstructured reports. While several annotated datasets exist, their isolated use hinders scalability due to inconsistent tagging schemes, label names, and non-standard entity categories. This paper introduces TI-NERmergerV2, a robust, semi-automated framework for integrating heterogeneous TI-NER datasets into a unified, high-quality corpus aligned with the structured threat information expression (STIX) standard (e.g, STIX 2.1). Building upon its predecessor, TI-NERmerger, which is limited by its reliance on strict string matching and a narrow cyber lookup space, TI-NERmergerV2 incorporates string normalization, fuzzy fallback matching, and alias expansion using the MITRE ATT&CK knowledge base to resolve lexical variation and annotation inconsistencies. We validate its effectiveness by comparing it with a manual integration of two public datasets (DNRTI and APTNER), producing a unified dataset called AAPTNER. TI-NERmergerV2 achieves over 94% alignment with the manual process, reducing months of expert effort to minutes. Evaluations using a RoBERTa-based NER model further confirm that TI-NERmergerV2 enhances annotation quality and effectively disambiguates key entity types in the resulting DNRTI-STIX2.1 and AAPTNER datasets. The framework generalizes across datasets that adopt STIX domain and observable objects, providing a scalable and reproducible foundation for cyber threat intelligence research. Both the framework and resulting datasets are publicly released to support broader efforts in standardizing and enriching TI-NER resources. Inoussa Mouiche, Sherif Saad |
Comput. Secur. | 1 |
| 2025 | Context-Aware Entity-Relation Extraction for Threat Intelligence Knowledge Graphs
Inoussa Mouiche, Sherif Saad |
CRiSIS | 1 |
| 2025 | Entity and relation extractions for threat intelligence knowledge graphsabstractAdvanced persistent threats (APTs) represent a complex challenge in cybersecurity as they infiltrate networks stealthily to conduct espionage, steal data, and maintain a long-term presence. To combat these threats, security professionals increasingly rely on cyber knowledge graphs (CKGs), which provide scalable solutions to analyze and structure vast amounts of cyber threat intelligence (CTI) from diverse sources in real-time, enabling the automation of proactive security measures. Developing CKGs requires extracting entity and their relationships from unstructured CTI reports. However, existing approaches face significant limitations, such as difficulties with the nuances of cybersecurity language, diverse threat terminologies, and high rates of error propagation, resulting in low accuracy and poor generalizability. This paper introduces a novel Threat Intelligence Knowledge Graph (TiKG) pipeline designed to address these challenges. The TiKG framework leverages SecureBERT, a domain-specific transformer-based model optimized for cybersecurity, and integrates it with an attention-based BiLSTM to capture the context and nuances of security texts, reducing error propagation and improving extraction accuracy. Additionally, the pipeline incorporates a domain-specific ontology and inference model to ensure precise relation mapping in relation extraction. Using three large-scale TI open-source datasets (DNRTI, STUCCO, and CYNER) and a curated CTI dataset, extensive evaluations demonstrate the effectiveness of our framework, showing significant improvements over existing methods in detecting and linking cyber threats. These contributions provide a robust platform for security professionals to analyze and predict potential attacks, develop effective defenses, and enhance the strategic capabilities of cybersecurity operations. Inoussa Mouiche, Sherif Saad |
Comput. Secur. | 1 |
| 2025 | TIJERE: A novel threat intelligence joint extraction model based on analyst expert knowledgeabstractThe extraction of entities and relationships from threat intelligence reports into structured formats, such as cybersecurity knowledge graphs, is essential for automated threat analysis, detection, and mitigation. However, existing joint extraction methods struggle with feature confusion, language ambiguity, noise propagation, and overlapping relations, resulting in low accuracy and poor model performance. This paper presents TIJERE, an innovative joint entity and relation extraction framework that formulates joint extraction as a multisequence labeling representation (MSLR) problem. Specifically, separate sequences are generated for each entity pair. Unlike prior tagging schemes, MSLR integrates expert domain features to enrich positional, contextual, and semantic representations of entities, thereby enhancing feature distinction and classification accuracy. Additionally, TIJERE reduces language ambiguity and enhances domain-specific generalization by leveraging SecureBERT+, a contextual language model fine-tuned on cybersecurity text. This improves both named entity recognition (NER) and relation extraction (RE). This paper also introduces DNRTI-JE, the first publicly available jointly labeled dataset for cybersecurity entity and RE, filling a crucial gap in cyber threat intelligence automation. Empirical evaluations on the curated DNRTI-JE dataset demonstrate that TIJERE achieves state-of-the-art performance, with F1-scores exceeding 0.93 for NER and 0.98 for RE, outperforming existing methods. Together, TIJERE and the standardized benchmarking DNRTI-JE dataset enable high-performance cybersecurity intelligence extraction, with transferable applications in healthcare, finance, and bioinformatics. Inoussa Mouiche, Sherif Saad |
Knowl. Based Syst. | 1 |
| 2024 | TI-NERmerger: Semi-Automated Framework for Integrating NER Datasets in Cybersecurity
Inoussa Mouiche, Sherif Saad |
SECRYPT | 1 |