A Cybersecurity Named Entity Recognition Model Based on Active Learning and Self-learning
Zhaoli Liu, Kun Jiang, Zheng Liu, Tao Qin · 2024
With the rapid development of Internet, there are more and more cybersecurity reports which contain valuable knowledge about the security events, but these data are difficult to utilize due to their unstructured characteristics. Named Entity Recognition (NER) from these unstructured texts is a critical and fundamental task for data utilization. Recently deep neural network-based models have achieved high performance in NER, however these models heavily rely on large amounts of labeled data. Since the labeled data is scarce in most professional domains, such as cybersecurity, and structure of the entities is very complex. To address these issues, we propose a semi-supervised entity recognition method based on active learning and selflearning, which mainly consists of two phases: entity recognition model construction and intelligent new training sample selection. In the first phase, an entity recognition model that integrates the pre-trained language model ALBERT is proposed, we employ a word-by-word processing way to solve the problems caused by word segmentation errors and polysemous words. In the second phase, we employ the active learning and self-learning strategies to select the most valuable data from unlabeled dataset, and then insert these data into the labeled dataset for iterative training, thus improving the performance of the NER model. To evaluate the performance of the proposed method, we collect data from several famous platforms, including CNNVD, FreeBuf Security Forum and SangFor Security Response Center, and the experimental results show that the proposed method not only improves the accuracy of entity recognition, but also effectively alleviates the problem caused by the scarcity of labeled data.