[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84780-en":3,"doc-seo-84780-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84780,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","TACTIC-KG Toward Small Agent Teams for Cyber Threat Intelligence Knowledge Graph Construction","Cyber Threat Intelligence (CTI) reports are largely unstructured, heterogeneous, and noisy, which restricts their direct use in automated analysis and reasoning. Cybersecurity Knowledge Graphs (CSKGs) offer a structured view of adversarial entities, actions, and relations, yet building them from free-text CTI is difficult. TACTIC-KG presents an agentic framework that decomposes extraction, typing, verification, and curation into modular, specialized small LLM agents. Using lightweight models (3B–8B), it improves stability, recall, and graph consistency while lowering deployment cost. Experiments on human-annotated CTI show specialization surpasses larger monolithic in-context-learning baselines across extraction F1, typing accuracy, and structural similarity.","arXiv :2607 .0500 1v2 [ cs .CR] 7 Jul 2026  \nTACTIC-KG: Toward Small Agent Teams for Cyber Threat Intelligence Knowledge Graph  \nConstruction  \nMouhamed Amine Bouchiha 1[0000−0001−6142−6855] and Gregory Blanc 1[0000−0001−8150−6617]  \nSAMOVAR, Télécom SudParis, Institut Polytechnique de Paris [mbouchiha@telecom-sudparis.eu](mbouchiha@telecom-sudparis.eu) , [gregory.blanc@telecom-sudparis.eu](gregory.blanc@telecom-sudparis.eu)  \nAbstract. Cyber Threat Intelligence (CTI) reports are predominantly unstructured, heterogeneous, and noisy, which limits their direct usability for automated analysis and reasoning. Cybersecurity Knowledge Graphs (CSKGs) provide a structured representation of adversarial entities, actions, and relations, but constructing such graphs from free-text CTI remains a challenge. Recent approaches rely on monolithic Large Language Models (LLMs) to perform end-to-end extraction and completion, leading to high cost, limited controllability, and unstable performance. This paper introduces TACTIC-KG, an agentic framework for CSKG construction that decomposes the task into modular, specialized LLM agents responsible for extraction, typing, verification, and curation.  \nUsing lightweight models (3B–8B), TACTIC-KG improves stability, recall, and graph consistency while reducing deployment cost. We implement and evaluate TACTIC-KG against recent state-of-the-art systems.  \nExperiments on human-annotated CTI reports show that agent specialization consistently outperforms larger monolithic in-context-learning (ICL) baselines in extraction F1-score, typing accuracy, and structural graph similarity.  \nKeywords: Cyber Threat Intelligence · Knowledge Graphs · Language Models · Agentic Systems · Information Extraction.  \n1 Introduction  \nCyber Threat Intelligence (CTI) reports contain rich textual narratives describing adversarial operations, tactics, and observable indicators. However, transforming these heterogeneous and unstructured reports into processable representations remains a fundamental challenge [7,41] . Traditional natural language processing techniques, such as named entity recognition (NER) [17] or classificationbased pipelines [3], often fail to capture the nuanced and implicit relationships present in CTI, particularly for complex or fine-grained adversarial behaviors [7] . Cybersecurity or CTI Knowledge Graphs (CSKGs) have emerged as a promising solution to structure CTI into entities, relationships, and contextual knowledge, supporting tasks such as visualization, attack-path reasoning, and automated  \n2 M. Bouchiha et al.  \ncorrelation [10, 22 , 41] . Recent research has leveraged Large Language Models (LLMs) to automate CSKG construction, taking advantage of their ability to process free-form text and capture latent semantic patterns. Prompt-based systems such as aCTIon [31] demonstrated the feasibility of LLM-driven documentlevel extraction of ATT&CK techniques, although static prompts can suffer from hallucinations and limited precision on fine-grained entities. Ontology-grounded approaches, exemplified by CTINEXUS [10] and IntelEX [36], improve semantic grounding and entity canonicalization through in-context learning (ICL) [13] and retrieval-augmented generation (RAG) [4], respectively, but at the cost of increased system complexity and sensitivity to retrieval quality.  \nComplementary efforts focus on fine-tuning and domain adaptation of LLMs. Systems such as AECR [8] and Fengrui et al. [15] show that supervised and synthetic fine-tuning can enhance precision and reduce hallucinations, even with smaller model sizes. Comparative studies indicate that, while LLMs generally achieve higher recall than transformer-based classifiers, precision can remain a challenge, motivating hybrid or multi-model architectures [14, 20] . Non-LLM approaches, including AttacKG+ [22], LADDER [3], and CRUcialG [9], highlight the continued relevance of structured pipelines and expert rules, although these methods can be britt","cbCaisBv5BrQ7UnW","https://ap.wps.com/l/cbCaisBv5BrQ7UnW","pdf",822630,2,1,20,"English","en",105,"# Introduction\n# Related work","[{\"question\":\"Why is constructing CSKGs from CTI challenging?\",\"answer\":\"CTI reports are unstructured, noisy, and heterogeneous, making it hard for typical NLP methods to capture implicit and fine-grained relationships needed to form accurate knowledge graphs.\"},{\"question\":\"What is TACTIC-KG and how does it differ from monolithic LLM approaches?\",\"answer\":\"TACTIC-KG is an agentic framework that decomposes CSKG construction into specialized LLM agents for extraction, typing, verification, and curation. This modular orchestration manages uncertainty and enforces ontology compliance instead of relying on a single end-to-end model.\"},{\"question\":\"What benefits does TACTIC-KG achieve in experiments?\",\"answer\":\"On human-annotated CTI reports, agent specialization improves extraction F1-score, typing accuracy, and structural graph similarity, while using lightweight 3B–8B models to reduce deployment cost and increase stability.\"}]",1784198189,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"tactic-kg-toward-small-agent-teams-for-cyber-threat-intelligence-knowledge-graph-construction","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/tactic-kg-toward-small-agent-teams-for-cyber-threat-intelligence-knowledge-graph-construction/84780/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is constructing CSKGs from CTI challenging?","Question",{"text":75,"@type":76},"CTI reports are unstructured, noisy, and heterogeneous, making it hard for typical NLP methods to capture implicit and fine-grained relationships needed to form accurate knowledge graphs.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is TACTIC-KG and how does it differ from monolithic LLM approaches?",{"text":80,"@type":76},"TACTIC-KG is an agentic framework that decomposes CSKG construction into specialized LLM agents for extraction, typing, verification, and curation. This modular orchestration manages uncertainty and enforces ontology compliance instead of relying on a single end-to-end model.",{"name":82,"@type":73,"acceptedAnswer":83},"What benefits does TACTIC-KG achieve in experiments?",{"text":84,"@type":76},"On human-annotated CTI reports, agent specialization improves extraction F1-score, typing accuracy, and structural graph similarity, while using lightweight 3B–8B models to reduce deployment cost and increase stability.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,126,129,133],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":29,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":22,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":22,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]