Context
Modern information systems generate massive amounts of heterogeneous cybersecurity data from multiple sources, including network logs, security alerts, system traces, incident reports, and other security-related information. These data are often highly heterogeneous, temporal, and weakly structured, making their analysis challenging using traditional approaches.
The temporal dimension is particularly important for cybersecurity analysis, as it enables the reconstruction of incident timelines, the identification of different stages of an attack, and a better understanding of the relationships between observed events and behaviors.
Knowledge Graphs (KGs) provide a suitable representation for structuring and connecting heterogeneous cybersecurity information. However, the automatic construction of temporal cybersecurity knowledge graphs remains relatively underexplored. Existing approaches often provide limited support for explicitly representing the temporal evolution of events and malicious behaviors.
Recent advances in Large Language Models (LLMs) offer new opportunities for automatically extracting entities, relationships, and events from heterogeneous and unstructured cybersecurity data. Combined with temporal knowledge graph representations and Graph Neural Networks (GNNs), these technologies can support more advanced cybersecurity analytics and anomaly detection.
Objective
The main objective of this internship is to design, implement, and evaluate an approach for automatically constructing temporal cybersecurity knowledge graphs from heterogeneous data using LLMs.
The resulting knowledge graphs will then be explored for cybersecurity analysis and anomaly detection using graph-based learning approaches, with a particular focus on exploiting the temporal dimension of cybersecurity events.
References
- Ji, S., Pan, S., Cambria, E., Marttinen, P., & Philip, S. Y. A survey on knowledge graphs: Representation, acquisition, and applications. IEEE transactions on neural networks and learning systems 33.2 : 494-514. 2021.
- Liu, K., Wang, F., Ding, Z., Liang, S., Yu, Z., & Zhou, Y. A review of knowledge graph application scenarios in cyber security. arXiv preprint arXiv:2204.04769.
- Lairgi, L. Moncla, K. Benabdeslem, R. Cazabet, & P. Cléau. ATOM: AdapTive and OptiMized dynamic temporal knowledge graph construction using LLMs. In Findings of EACL 2026, pp. 950-966. 2026.
- Lairgi, L. Moncla, R. Cazabet, K. Benabdeslem, & P. Cléau. iText2KG: Incremental knowledge graphs construction using large language models. In WISE, pp. 214-229. 2024.
- Benzekki, K., & Messai, M. L. Empowering Cybersecurity Analysis: Unifying CVE, CWE, and CPE through Knowledge Graphs. Computers & Security, 104726. 2025.
- Khorashadizadeh, H., Amara, F. Z., Ezzabady, M., Ieng, F., Tiwari, S., Mihindukulasooriya, N., … & Groppe, S. Research trends for the interplay between large language models and knowledge graphs. arXiv preprint arXiv:2406.08223.
Internship framework
Location: LIRIS / ERIC
Duration: 6 months.
Desired starting date: Feb/Mar 2027
To apply: The candidate must have advanced skills in computer science (computer security skills are highly desirable). Please send your application with a CV, a cover letter, as well as your grades for the current academic year and last year to :
Internship supervisors
- Khalid Benabdeslem (LIRIS) : benabdeslem@univ-lyon1.fr
- Abir El Haj (ERIC) : abir.el-haj@univ-lyon2.fr
- Mohamed-Lamine Messai (ERIC) : mohamed-lamine.messai@univ-lyon2.fr
