MITRE-SAGE: A Multi-Agent Cybersecurity Question-Answering model

📅 2026-08-03
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决网络安全分析中的信息过载等问题,提出MITRE-SAGE模型,通过多代理检索增强生成框架整合语义和结构知识,提高基于LLM的问答系统可靠性。
📝 Abstract
Effective cybersecurity operations require timely and accurate analysis of large-scale heterogeneous security information; however, analysts increasingly struggle with information overload, alert fatigue, and time-constrained decision-making. Although large language models (LLMs) have demonstrated promising capabilities for question answering (QA), their effectiveness in cybersecurity remains limited by insufficient domain knowledge, a tendency to hallucinate, and difficulties in capturing both semantic and structural relationships. This work proposes MITRE-SAGE, a multi-agent retrieval-augmented generation framework that integrates semantic and structural cybersecurity knowledge to improve the reliability and interpretability of LLM-based QA systems. By decomposing complex tasks into query interpretation, evidence retrieval, and answer synthesis, MITRE-SAGE effectively supports cybersecurity tasks such as vulnerability assessment, threat profiling, and relationship extraction. Furthermore, we propose MITRE-QA, a comprehensive benchmark comprising 3,000 question-answer pairs for evaluating LLMs across diverse cybersecurity knowledge tasks, and use it to systematically evaluate MITRE-SAGE against representative baseline methods. Extensive experiments demonstrate that MITRE-SAGE consistently outperforms standalone LLMs and conventional RAG approaches. Notably, a lightweight configuration comprising Qwen2.5-7B sub-agents and a Qwen2.5-14B orchestrator achieves superior performance on five of the eight benchmark tasks, indicating the effectiveness of the proposed multi-agent framework. The results highlight the potential of MITRE-SAGE as a scalable and interpretable approach for reliable cybersecurity QA, while MITRE-QA provides a standardized benchmark for future research.
Problem

Research questions and friction points this paper is trying to address.

cybersecurity
information overload
large language models
domain knowledge
semantic and structural relationships
Innovation

Methods, ideas, or system contributions that make the work stand out.

multi-agent framework
retrieval-augmented generation
cybersecurity QA
semantic and structural knowledge integration
MITRE-QA benchmark
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Ali Habibzadeh
Department of Computer Engineering, University of Guilan, Rasht, Iran
F
Farid Feyzi
Department of Computer Engineering, University of Guilan, Rasht, Iran
Reza Ebrahimi Atani
Reza Ebrahimi Atani
Associate Professor of Computer Engineering, University of Guilan
CryptographyComputer SecurityNetwork Security