APT-KG2QA: An Intelligent Fine-Tuning Strategy for Large Language Models Utilizing the APT Knowledge Graph
Bingqi Ma, Yinghai Zhou, Si Wu, Ziyu Wang, Yanjun Xiao, Yu Cui, Yuan Liu, Zhihong Tian · IEEE Internet of Things Journal · 2025
The proliferation of Internet of Things (IoT) devices, now numbering in the tens of billions, has exposed new attack surfaces due to their heterogeneous network architectures and vast numbers of distributed endpoints. The offensive-defensive dynamics of Advanced Persistent Threats (APTs) in IoT environments exhibit unique complexities, including enhanced stealth capabilities and prolonged attack lifecycles. This paper introduces APT-KG2QA, a knowledge graph-driven framework for generating specialized question-answering datasets. This methodology addresses two critical challenges in deploying large language models (LLMs) for cybersecurity applications: mitigating inherent biases in attack behavior recognition and overcoming logical reasoning deficits stemming from limited access to high-quality, domain-specific training data. The methodology utilizes a systematic conversion mechanism to translate the APT KG data into a hierarchical instruction template framework, which incorporates a hybrid prompt template engine with adversarial augmentation modules to produce domain-adaptive fine-tuning data. Low-Rank Adaptation (LoRA) technique facilitates parameter-efficient fine-tuning for four basic models. Experimental results indicate that the models enriched with domain knowledge achieve average increases of 577.7% in BLEU-4 and 623.7% in ROUGE-L measures, showing significant enhancements noted in output correctness, relevance, and comprehensibility. This study explores cross-modal integration pathways between KGs and LLMs, confirming the effectiveness of structured knowledge infusion in improving cybersecurity analysis capabilities, thus offering methodological guidance for developing intelligent security defense systems.