ICSThreatQA: A knowledge-graph enhanced question answering model for industrial control system threat intelligence.

Saved in:
Bibliographic Details
Title: ICSThreatQA: A knowledge-graph enhanced question answering model for industrial control system threat intelligence.
Authors: Rani, Ruby1 (AUTHOR) ruby.rani@newcastle.ac.uk, Kumar, Mahender1,2 (AUTHOR) mahender.kumar@warwick.ac.uk, Epiphaniou, Gregory2 (AUTHOR) gregory.epiphaniou@warwick.ac.uk, Maple, Carsten2 (AUTHOR) CM@warwick.ac.uk
Source: Expert Systems with Applications. Mar2026, Vol. 301, pN.PAG-N.PAG. 1p.
Subjects: Knowledge graphs, Question answering systems, Internet security, Industrial controls manufacturing
Abstract: • ICSThreatQA: QA system tailored for ICS cybersecurity. • Four QA models, including novel KG-RAG for knowledge-rich answers. • Builds and evaluates 620-pair QA dataset curated from MITRE ATT&CK ICS knowledgebase. • Improves threat detection and incident response in ICS environments. Industrial Control Systems (ICS) underpin critical infrastructure but remain vulnerable to sophisticated cyberattacks. Existing threat intelligence tools emphasise static knowledge bases and isolated indicators, offering limited support for analysts who must navigate complex adversarial tactics. To address this gap, we present ICSThreatQA, the first QA framework tailored to ICS threat intelligence. ICSThreatQA introduces four retrieval-augmented architectures - including a novel Knowledge Graph-enhanced RAG (KG-RAG) - designed to provide accurate, context-aware responses to natural-language security queries. We construct a curated dataset of 620 expert-validated QA pairs from the MITRE ATT&CK ICS knowledge base, encompassing factual, contrastive, inferential, and opinion-based queries. Through extensive evaluation, including automated metrics, human expert ratings, adversarial robustness, and multi-turn dialogues, ICSThreatQA demonstrates significant improvements over baseline RAG and large language models. Notably, KG-RAG achieves the highest answer relevance (0.968) and correctness (0.660), while the Hybrid model balances precision and faithfulness under few-shot settings. These results confirm ICSThreatQA's potential to transform static ICS threat knowledge into an interactive, analyst-ready intelligence system, reducing cognitive burden and accelerating incident response. [ABSTRACT FROM AUTHOR]
Copyright of Expert Systems with Applications is the property of Pergamon Press - An Imprint of Elsevier Science and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:• ICSThreatQA: QA system tailored for ICS cybersecurity. • Four QA models, including novel KG-RAG for knowledge-rich answers. • Builds and evaluates 620-pair QA dataset curated from MITRE ATT&CK ICS knowledgebase. • Improves threat detection and incident response in ICS environments. Industrial Control Systems (ICS) underpin critical infrastructure but remain vulnerable to sophisticated cyberattacks. Existing threat intelligence tools emphasise static knowledge bases and isolated indicators, offering limited support for analysts who must navigate complex adversarial tactics. To address this gap, we present ICSThreatQA, the first QA framework tailored to ICS threat intelligence. ICSThreatQA introduces four retrieval-augmented architectures - including a novel Knowledge Graph-enhanced RAG (KG-RAG) - designed to provide accurate, context-aware responses to natural-language security queries. We construct a curated dataset of 620 expert-validated QA pairs from the MITRE ATT&CK ICS knowledge base, encompassing factual, contrastive, inferential, and opinion-based queries. Through extensive evaluation, including automated metrics, human expert ratings, adversarial robustness, and multi-turn dialogues, ICSThreatQA demonstrates significant improvements over baseline RAG and large language models. Notably, KG-RAG achieves the highest answer relevance (0.968) and correctness (0.660), while the Hybrid model balances precision and faithfulness under few-shot settings. These results confirm ICSThreatQA's potential to transform static ICS threat knowledge into an interactive, analyst-ready intelligence system, reducing cognitive burden and accelerating incident response. [ABSTRACT FROM AUTHOR]
ISSN:09574174
DOI:10.1016/j.eswa.2025.130180