跳到主要內容

簡易檢索 / 詳目顯示

研究生: 張家馨
Chang, Chia-Hsin
論文名稱: 基於知識引導之文件向量語意解耦:以階層式條件自編碼器實現
Knowledge-Guided Disentanglement of Document Embeddings via Hierarchical Conditional Autoencoder
指導教授: 蕭舜文
Hsiao, Shun-Wen
口試委員: 陳孟彰
Chen, Meng-Chang
陳建錦
Chen, Chien-Chin
黃意婷
Huang, Yi-Ting
學位類別: 碩士
Master
系所名稱: 商學院 - 資訊管理學系
Department of Management Information System
論文出版年: 2026
畢業學年度: 114
語文別: 英文
論文頁數: 49
中文關鍵詞: 向量解耦知識引導解耦條件式自編碼器弱監督學習網路威脅情資
外文關鍵詞: Representation Disentanglement, Knowledge-Guided Disentanglement, Conditional Autoencoder, Weak Supervision, Cyber Threat Intelligence
相關次數: 點閱:13下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 網路威脅情資(CTI)報告是理解攻擊者行為的主要來源,將其對應至 MITRE ATT&CK 等結構化知識庫是 CTI 分析的核心工作。實務上,報告語句常被編碼為 dense embedding,但這些表徵同時糾纏了技術行為、戰術意圖與來源風格等異質因素,在低標註情境下限制了樣本效率。
    本研究提出一個知識引導的雙路條件式自編碼器(Dual-path Conditional Autoencoder ),以 ATT&CK 描述作為弱監督,將報告 embedding 解耦為技術、戰術與殘差三個具明確語意角色的成分,並以階層方式套用兩階段分解。本研究系統性地分析 condition 的建構(RQ2)與注入(RQ3)對解耦品質的影響。
    在維度控制的公平比較下,主技術因子於低標註區間優於維度對齊基準,展現更佳的樣本效率;來源相關結構被成功導向殘差,且整體準確率不受損;各成分亦呈現可解釋、可遷移的「如何執行(how)–為何執行(why)」語意分工。


    Cyber threat intelligence (CTI) reports are a primary source for understanding adversary behavior, and mapping them onto structured knowledge bases such as MITRE ATT&CK is a central task in CTI analysis. In practice, report sentences are encoded into dense embeddings, but these embeddings entangle heterogeneous factors, including technique-level behavior, tactic-level intent, and source-specific writing style, within a single undifferentiated vector, which limits sample efficiency under low-label conditions.
    This study proposes a knowledge-guided, dual-path Conditional Autoencoder (CAE) that uses ATT&CK descriptions as weak supervision to disentangle a report embedding into three components with well-defined semantic roles, namely technique, tactic, and residual, applying the same decomposition mechanism twice in a hierarchical manner. The thesis systematically studies how condition construction (RQ2) and injection (RQ3) affect disentanglement quality, selecting the configuration with the cleanest disentanglement through a two-stage validation-set sweep.
    Under a dimension-controlled fair comparison, the primary technique factor outperforms the dimension-aligned baseline in the low-label region, exhibiting better few-shot sample efficiency; source-related structure is successfully routed into the residual without harming overall accuracy; and attention analysis, word-space probing, and controlled T5 substitution jointly show that the components carry interpretable, transferable “how–why” semantic roles, further verified on an external threat report.

    1. Introduction 1
    1.1 Research Motivation 1
    1.2 Research Challenges 2
    1.3 Research Questions 3
    1.4 Research Contributions 4
    2. Related Work 4
    2.1 MITRE ATT&CK and Automated CTI Analysis 4
    2.2 Representation Disentanglement 5
    2.3 Conditional Models 6
    2.4 Representation Learning in the CTI Domain 7
    3. Methodology 7
    3.1 Overview 7
    3.2 Construction of ATT&CK Knowledge Anchors 9
    3.3 Hierarchical Conditional Decomposition Mechanism 10
    3.3.1 Stage 1: Technique-Level Decomposition 10
    3.3.2 Stage 2: Tactic-Level Decomposition 11
    3.4 Condition Construction (RQ2) 12
    3.5 Condition Injection (RQ3) 13
    3.6 Loss-Function Design 14
    4. Evaluation Methodology 17
    4.1 Evaluation Overview 17
    4.2 Selection Criteria for Condition Construction and Injection 17
    4.2.1 Selection Criteria and Their Motivation 17
    4.2.2 The Inferential Chain Between Selection and the Final Claim 18
    4.2.3 Two-Stage Selection Procedure 18
    4.3 Source-Leakage Probing 18
    4.4 Downstream Few-Shot Classification 19
    4.5 Transferability Evaluation and Qualitative Analysis 21
    5. Experimental Results 23
    5.1 Dataset and Experimental Setup 23
    5.2 Main Result: Downstream Few-Shot Sample Efficiency 23
    5.3 Mechanism Analysis: Why Disentanglement Works 25
    5.3.1 Source Leakage Decreases Along the Factor Ladder 25
    5.3.2 Full-Set Classification Performance 26
    5.4 Design Selection: How to Attain the Cleanest Disentanglement 27
    5.4.1 Comparison of Injection Mechanisms (RQ3) 27
    5.4.2 Comparison of Construction Methods (RQ2) 29
    5.5 Qualitative Corroboration of Semantic Roles 32
    5.5.1 The How/Why Division of Labor Between Technique and Tactic Factors 32
    5.5.2 T5 Decoding of Latent Factors 33
    5.6 Transferability Verification: External-Report Case Analysis 36
    6. Conclusion 39
    6.1 Summary and Main Findings 39
    6.2 Limitations 40
    6.3 Future Work 41
    Reference 42
    Appendix A: Loss-Function Weight Settings 44
    Appendix B: Per-Sentence Tactic Annotation of the Earth Krahang Report 45

    Dittadi, A., Träuble, F., Locatello, F., Wüthrich, M., Aber, V., Winther, O., Schölkopf, B., & Bauer, S. (2021). On the transfer of disentangled representations in realistic settings. Proceedings of the International Conference on Learning Representations (ICLR).
    Eastwood, C., & Williams, C. K. I. (2018). A framework for the quantitative evaluation of disentangled representations. Proceedings of the International Conference on Learning Representations (ICLR).
    Gretton, A., Bousquet, O., Smola, A., & Schölkopf, B. (2005). Measuring statistical dependence with Hilbert-Schmidt norms. Proceedings of the International Conference on Algorithmic Learning Theory (ALT), 63–77.
    Higgins, I., Matthey, L., Pal, A., Burgess, C., Glorot, X., Botvinick, M., Mohamed, S., & Lerchner, A. (2017). β-VAE: Learning basic visual concepts with a constrained variational framework. Proceedings of the International Conference on Learning Representations (ICLR).
    Husari, G., Al-Shaer, E., Ahmed, M., Chu, B., & Niu, X. (2017). TTPDrill: Automatic and accurate extraction of threat actions from unstructured text of CTI sources. Proceedings of the 33rd Annual Computer Security Applications Conference (ACSAC), 103–115.
    Kim, H., & Mnih, A. (2018). Disentangling by factorising. Proceedings of the International Conference on Machine Learning (ICML), 2649–2658.
    Legoy, V., Caselli, M., Seifert, C., & Peter, A. (2020). Automated retrieval of ATT&CK tactics and techniques for cyber threat reports. arXiv preprint arXiv:2004.14322.
    Li, Z., Zeng, J., Chen, Y., & Liang, Z. (2022). AttacKG: Constructing technique knowledge graph from cyber threat intelligence reports. Proceedings of the European Symposium on Research in Computer Security (ESORICS), 589–609.
    Locatello, F., Bauer, S., Lucic, M., Rätsch, G., Gelly, S., Schölkopf, B., & Bachem, O. (2019). Challenging common assumptions in the unsupervised learning of disentangled representations. Proceedings of the International Conference on Machine Learning (ICML), 4114–4124.
    MITRE. (2020). Threat Report ATT&CK Mapping (TRAM). Retrieved from https://github.com/center-for-threat-informed-defense/tram
    Montero, M. L., Ludwig, C. J. H., Costa, R. P., Malhotra, G., & Bowers, J. (2022). Lost in latent space: Disentangled models and the challenge of combinatorial generalisation. Proceedings of the International Conference on Learning Representations (ICLR).
    Perez, E., Strub, F., de Vries, H., Dumoulin, V., & Courville, A. (2018). FiLM: Visual reasoning with a general conditioning layer. Proceedings of the AAAI Conference on Artificial Intelligence, 3942–3951.
    Rombach, R., Blattmann, A., Lorenz, D., Esser, P., & Ommer, B. (2022). High-resolution image synthesis with latent diffusion models. Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 10684–10695.
    Sohn, K., Lee, H., & Yan, X. (2015). Learning structured output representation using deep conditional generative models. Advances in Neural Information Processing Systems (NeurIPS), 28.
    Strom, B. E., Applebaum, A., Miller, D. P., Nickels, K. C., Pennington, A. G., & Thomas, C. B. (2018). MITRE ATT&CK: Design and philosophy. MITRE Technical Report.
    Ting, Y.-S., Rix, H.-W., Contursi, G., Ho, A. Y. Q., & Frankel, N. (2022). Disentangling the Milky Way with a label-free conditional autoencoder. The Astrophysical Journal, 926(2), 189.
    van Steenkiste, S., Locatello, F., Schmidhuber, J., & Bachem, O. (2019). Are disentangled representations helpful for abstract visual reasoning? Advances in Neural Information Processing Systems (NeurIPS), 32.
    Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, Ł., & Polosukhin, I. (2017). Attention is all you need. Advances in Neural Information Processing Systems (NeurIPS), 30.
    You, Y., Yao, J., Liu, J., Wang, B., & Jiang, J. (2022). CyberEntRel: Joint extraction of cyber entities and relations using deep learning. Computers & Security, 113, 102537.

    無法下載圖示 全文公開日期 2031/08/25
    QR CODE
    :::