{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:50:09Z","timestamp":1783702209359,"version":"3.55.0"},"reference-count":82,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T00:00:00Z","timestamp":1778716800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T00:00:00Z","timestamp":1778716800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001798","name":"Edith Cowan University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001798","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Industry 5.0\u2019s increasing integration of IT and OT systems is transforming industrial operations but also expanding the cyber\u2013physical attack surface. Industrial Control Systems (ICS) face escalating security challenges as traditional siloed defenses fail to provide coherent, cross-domain threat insights. We present BRIDG-ICS (BRIDge for Industrial Control Systems), an AI-enriched Knowledge Graph (KG) framework for context-aware threat analysis and quantitative assessment of cyber resilience in smart manufacturing environments. BRIDG-ICS fuses heterogeneous industrial and cybersecurity data into an integrated Industrial Security Knowledge Graph linking assets, vulnerabilities, and adversarial behaviors with probabilistic risk metrics (e.g., exploit likelihood, attack cost). This unified graph representation enables multi-stage attack path simulation using graph-analytic techniques. To enrich the graph\u2019s semantic depth, the framework leverages domain-specific pretrained language models (e.g., SecureBERT, CySecBERT) to extract cybersecurity entities, infer relationships, and transform natural-language threat descriptions into structured graph triples, thereby populating the knowledge graph with missing associations and latent risk indicators. The resulting AI-enriched KG supports multi-hop threat reasoning through graph-based inference, improving visibility into complex attack chains and guiding data-driven mitigation. In simulated industrial scenarios, BRIDG-ICS scales well, reduces potential attack exposure, and can enhance cyber\u2013physical system resilience in Industry 5.0 settings.<\/jats:p>","DOI":"10.1186\/s42400-026-00597-0","type":"journal-article","created":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T06:23:42Z","timestamp":1778739822000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Bridg-ics: AI-grounded knowledge graphs for intelligent threat analytics in industry\u00a05.0 cyber-physical systems"],"prefix":"10.1186","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0013-4555","authenticated-orcid":false,"given":"Padmeswari","family":"Nandiya","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmad","family":"Mohsin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed","family":"Ibrahim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Iqbal H.","family":"Sarker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Helge","family":"Janicke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,14]]},"reference":[{"issue":"5","key":"597_CR1","doi-asserted-by":"publisher","first-page":"917","DOI":"10.3390\/electronics13050917","volume":"13","author":"DS Afenu","year":"2024","unstructured":"Afenu DS, Asiri M, Saxena N (2024) Industrial control systems security validation based on mitre adversarial tactics, techniques, and common knowledge framework. Electronics 13(5):917. https:\/\/doi.org\/10.3390\/electronics13050917","journal-title":"Electronics"},{"key":"597_CR2","doi-asserted-by":"publisher","first-page":"108270","DOI":"10.1016\/j.ress.2021.108270","volume":"220","author":"J Alanen","year":"2022","unstructured":"Alanen J, Linnosmaa J, Malm T, Papakonstantinou N, Ahonen T, Heikkil\u00e4 E, Tiusanen R (2022) Hybrid ontology for safety, security, and dependability risk assessments and security threat analysis (sta) method for industrial control systems. Reliab Eng & Syst Saf 220:108270. https:\/\/doi.org\/10.1016\/j.ress.2021.108270","journal-title":"Reliab Eng & Syst Saf"},{"issue":"6","key":"597_CR3","doi-asserted-by":"publisher","first-page":"161","DOI":"10.3390\/technologies11060161","volume":"11","author":"AM Alnajim","year":"2023","unstructured":"Alnajim AM, Habib S, Islam M, Thwin SM, Alotaibi F (2023) A comprehensive survey of cybersecurity threats, attacks, and effective countermeasures in industrial internet of things. Technologies 11(6):161. https:\/\/doi.org\/10.3390\/technologies11060161","journal-title":"Technologies"},{"key":"597_CR4","doi-asserted-by":"publisher","first-page":"100067","DOI":"10.1016\/j.csa.2024.100067","volume":"3","author":"A Alqudhaibi","year":"2025","unstructured":"Alqudhaibi A, Albarrak M, Jagtap S, Williams N, Salonitis K (2025) Securing industry 4.0: Assessing cybersecurity challenges and proposing strategies for manufacturing management. Cyber Secur and Appl 3:100067. https:\/\/doi.org\/10.1016\/j.csa.2024.100067","journal-title":"Cyber Secur and Appl"},{"issue":"1","key":"597_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3687300","volume":"57","author":"B Al-Sada","year":"2024","unstructured":"Al-Sada B, Sadighian A, Oligeri G (2024) Mitre attack: State of the art and way forward. ACM Comput Surv 57(1):1\u201337. https:\/\/doi.org\/10.1145\/3687300","journal-title":"ACM Comput Surv"},{"key":"597_CR6","unstructured":"Anton SDD, Hafner A, Schotten HD (2019) Devil in the Detail: Attack scenarios in industrial applications. arXiv:https:\/\/arxiv.org\/abs\/1905.10292"},{"issue":"24","key":"597_CR7","doi-asserted-by":"publisher","first-page":"17525","DOI":"10.1109\/JIOT.2021.3081741","volume":"8","author":"SDD Anton","year":"2021","unstructured":"Anton SDD, Fraunholz D, Krohmer D, Reti D, Schneider D, Schotten HD (2021) The global state of security in industrial control systems: An empirical analysis of vulnerabilities around the world. IEEE Internet Things J 8(24):17525\u201317540. https:\/\/doi.org\/10.1109\/JIOT.2021.3081741","journal-title":"IEEE Internet Things J"},{"issue":"18","key":"597_CR8","doi-asserted-by":"publisher","first-page":"8398","DOI":"10.3390\/app14188398","volume":"14","author":"M Badawy","year":"2024","unstructured":"Badawy M, Sherief NH, Abdel-Hamid AA (2024) Legacy ics cybersecurity assessment using hybrid threat modeling\u2013an oil and gas sector case study. Appl Sci 14(18):8398. https:\/\/doi.org\/10.3390\/app14188398","journal-title":"Appl Sci"},{"key":"597_CR9","unstructured":"Barnum S, Piazza C, Faber E (2017) Structured threat information expression (stix\u00ae) 2.0: Overview and core concepts. Technical report, OASIS Committee Specification"},{"key":"597_CR10","unstructured":"Belikovetsky S, Yampolskiy M, Toh J, Cox J, Elovici Y (2017) dr0wned: Cyber-physical attack with additive manufacturing. In: Proceedings of the 11th USENIX workshop on offensive technologies (WOOT 2017). USENIX. https:\/\/www.usenix.org\/conference\/woot17\/workshop-program\/presentation\/belikovetsky"},{"issue":"4","key":"597_CR11","doi-asserted-by":"publisher","first-page":"214","DOI":"10.3390\/info15040214","volume":"15","author":"I Branescu","year":"2024","unstructured":"Branescu I, Grigorescu O, Dascalu M (2024) Automated mapping of common vulnerabilities and exposures to mitre att&ck tactics. Information 15(4):214. https:\/\/doi.org\/10.3390\/info15040214","journal-title":"Information"},{"key":"597_CR12","unstructured":"Byres E (2004) The myths and facts behind cyber security risks for industrial control systems 7"},{"issue":"8","key":"597_CR13","doi-asserted-by":"publisher","first-page":"1815","DOI":"10.3390\/math11081815","volume":"11","author":"Y Chen","year":"2023","unstructured":"Chen Y, Ge X, Yang S, Hu L, Li J, Zhang J (2023) A survey on multimodal knowledge graphs: Construction, completion and applications. Mathematics 11(8):1815. https:\/\/doi.org\/10.3390\/math11081815","journal-title":"Mathematics"},{"issue":"3","key":"597_CR14","doi-asserted-by":"publisher","first-page":"728","DOI":"10.3390\/s25030728","volume":"25","author":"I Cindri\u0107","year":"2025","unstructured":"Cindri\u0107 I, Jur\u010devi\u0107 M, Hadjina T (2025) Mapping of industrial iot to iec 62443 standards. Sensors 25(3):728. https:\/\/doi.org\/10.3390\/s25030728","journal-title":"Sensors"},{"key":"597_CR15","unstructured":"Cybersecurity and infrastructure security agency (CISA): Industrial control systems advisories (ICSA). Accessed: October 2025 (2024). https:\/\/www.cisa.gov\/ics\/advisories"},{"key":"597_CR16","doi-asserted-by":"publisher","unstructured":"Falcarin P, Dainese F (2024) Building a cybersecurity knowledge graph with cybergraph. In: Proceedings of the 2024 ACM\/IEEE 4th International workshop on engineering and cybersecurity of critical systems (EnCyCriS) and 2024 IEEE\/ACM Second International workshop on software vulnerability. EnCyCriS\/SVM \u201924, pp. 29\u201336. Association for computing machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3643662.3643962","DOI":"10.1145\/3643662.3643962"},{"key":"597_CR17","doi-asserted-by":"publisher","unstructured":"Fujimoto M, Matsuda W, Mitsunaga T, Hashimoto Y (2021) Efficient industrial control systems risk assessment using the attack path to the critical device. In: Proceedings of the 2021 3rd International conference on management science and industrial engineering. MSIE \u201921, pp. 104\u2013110. Association for computing machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3460824.3460859","DOI":"10.1145\/3460824.3460859"},{"key":"597_CR18","doi-asserted-by":"crossref","unstructured":"Gao P, Liu X, Choi E, Ma S, Yang X, Song D (2024) Threatkg: An ai-powered system for automated open-source cyber threat intelligence gathering and management arXiv:2212.10388 [cs.CR]","DOI":"10.1145\/3689217.3690613"},{"issue":"4","key":"597_CR19","doi-asserted-by":"publisher","first-page":"1466","DOI":"10.3390\/app14041466","volume":"14","author":"MA Hassan","year":"2024","unstructured":"Hassan MA, Zardari S, Farooq MU, Alansari MM, Nagro SA (2024) Systematic analysis of risks in industry 5.0 architecture. Appl Sci 14(4):1466","journal-title":"Appl Sci"},{"issue":"4","key":"597_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3447772","volume":"54","author":"A Hogan","year":"2021","unstructured":"Hogan A, Blomqvist E, Cochez M, D\u2019amato C, Melo GD, Gutierrez C, Kirrane S, Gayo JEL, Navigli R, Neumaier S, Ngomo A-CN, Polleres A, Rashid SM, Rula A, Schmelzeisen L, Sequeda J, Staab S, Zimmermann A (2021) Knowledge graphs. ACM Comput Surv 54(4):1\u201337. https:\/\/doi.org\/10.1145\/3447772","journal-title":"ACM Comput Surv"},{"issue":"4","key":"597_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3447772","volume":"54","author":"A Hogan","year":"2021","unstructured":"Hogan A, Blomqvist E, Cochez M, D\u2019amato C, Melo GD, Gutierrez C, Kirrane S, Gayo JEL, Navigli R, Neumaier S, Ngomo A-CN, Polleres A, Rashid SM, Rula A, Schmelzeisen L, Sequeda J, Staab S, Zimmermann A (2021) Knowledge graphs. ACM Comput Surv 54(4):1\u201337. https:\/\/doi.org\/10.1145\/3447772","journal-title":"ACM Comput Surv"},{"key":"597_CR22","unstructured":"H\u00f8st, A., Lison P, Moonen L (2023) Constructing a knowledge graph from textual descriptions of software vulnerabilities in the national vulnerability database. In: Alum\u00e4e, T., Fishel, M. (eds.) Proceedings of the 24th Nordic Conference on Computational Linguistics (NoDaLiDa), pp. 386\u2013391. University of Tartu Library, T\u00f3rshavn, Faroe Islands. https:\/\/aclanthology.org\/2023.nodalida-1.40\/"},{"key":"597_CR23","unstructured":"Huang L, Xiao X (2024) Ctikg: Llm-powered knowledge graph construction from cyber threat intelligence. In: Proceedings of the first conference on language modeling (COLM 2024)"},{"key":"597_CR24","unstructured":"Initiative VC (2021) automated construction of threat knowledge graph for industrial control system security. https:\/\/cyberinitiative.org\/research\/funded-projects\/2021-funded-projects\/2021-research-collaboration\/ics-security.html. Accessed: 2025-10-21"},{"key":"597_CR25","unstructured":"ISA\/IEC 62443: Industrial automation and control systems security. Standard series available at https:\/\/www.isa.org\/isa62443\/. Accessed: October 10, 2025 (2021)"},{"key":"597_CR26","doi-asserted-by":"publisher","first-page":"164118","DOI":"10.1109\/ACCESS.2021.3133260","volume":"9","author":"Z Jadidi","year":"2021","unstructured":"Jadidi Z, Lu Y (2021) A threat hunting framework for industrial control systems. IEEE Access 9:164118\u2013164130. https:\/\/doi.org\/10.1109\/ACCESS.2021.3133260","journal-title":"IEEE Access"},{"key":"597_CR27","doi-asserted-by":"publisher","unstructured":"Jaffal NO, Alkhanafseh M, Mohaisen D (2025) Large language models in cybersecurity: A survey of applications, vulnerabilities, and defense techniques. AI 6(9) p.216 https:\/\/doi.org\/10.3390\/ai6090216","DOI":"10.3390\/ai6090216"},{"key":"597_CR28","doi-asserted-by":"publisher","unstructured":"Jia Y, Qi Y, Shang H, Jiang R, Li A (2018) A practical approach to constructing a knowledge graph for cybersecurity. Engineering 4(1):53\u201360. https:\/\/doi.org\/10.1016\/j.eng.2018.01.004 Cybersecurity","DOI":"10.1016\/j.eng.2018.01.004"},{"key":"597_CR29","doi-asserted-by":"crossref","unstructured":"Ji S, Pan S, Cambria E, Marttinen P, Yu PS (2022) A survey on knowledge graphs: Representation, acquisition, and applications. IEEE Transactions on Neural Networks and Learning Systems","DOI":"10.1109\/TNNLS.2021.3070843"},{"key":"597_CR30","unstructured":"Kaspersky (2025) ICS-CERT: A brief overview of the main incidents in industrial cybersecurity Q2 2025. https:\/\/ics-cert.kaspersky.com\/publications\/reports\/2025\/10\/09\/a-brief-overview-of-the-main-incidents-in-industrial-cybersecurity-q2-2025\/. Accessed: 2025-10-25"},{"key":"597_CR31","doi-asserted-by":"publisher","first-page":"103543","DOI":"10.1016\/j.cose.2023.103543","volume":"136","author":"SM Khalil","year":"2024","unstructured":"Khalil SM, Bahsi H, Kor\u00f5tko T (2024) Threat modeling of industrial control systems: A systematic literature review. Comput & Secur 136:103543. https:\/\/doi.org\/10.1016\/j.cose.2023.103543","journal-title":"Comput & Secur"},{"issue":"12","key":"597_CR32","doi-asserted-by":"publisher","first-page":"1036","DOI":"10.3390\/info16121036","volume":"16","author":"N Khan","year":"2025","unstructured":"Khan N, Ahmad K, Al Tamimi A, Alani MM, Bermak A, Khalil I (2025) Explainable ai-based intrusion detection systems for industry 5.0 and adversarial xai: A systematic review. Information 16(12):1036. https:\/\/doi.org\/10.3390\/info16121036","journal-title":"Information"},{"key":"597_CR33","doi-asserted-by":"publisher","first-page":"1434436","DOI":"10.3389\/fcomp.2024.1434436","volume":"6","author":"R Kour","year":"2024","unstructured":"Kour R, Karim R, Dersin P, Venkatesh N (2024) Cybersecurity for industry 5.0: trends and gaps. Frontiers in Comput Sci 6:1434436. https:\/\/doi.org\/10.3389\/fcomp.2024.1434436","journal-title":"Frontiers in Comput Sci"},{"key":"597_CR34","unstructured":"Kulvatunyou B, Drobnjakovic M, Ameri F, Will C, Smith B (2022) The industrial ontologies foundry (iof) core ontology. In: Formal Ontologies Meet Industry (FOMI) 2022, Tarbes, France. Accessed 8 Dec 2025. https:\/\/tsapps.nist.gov\/publication\/get_pdf.cfm?pub_id=935068"},{"key":"597_CR35","doi-asserted-by":"crossref","unstructured":"Kurniawan K, Kiesling E, Winkler D, Ekelhart A (2025) The ics-sec kg: An integrated cybersecurity resource for industrial control systems, 153\u2013170","DOI":"10.1007\/978-3-031-77847-6_9"},{"issue":"5","key":"597_CR36","doi-asserted-by":"publisher","first-page":"2756","DOI":"10.1109\/TKDE.2025.3538110","volume":"37","author":"L Li","year":"2025","unstructured":"Li L, Jin Z, Zhang X, Duan H, Wang J, Tao Z, Zhao H, Zhu X (2025) Multi-view riemannian manifolds fusion enhancement for knowledge graph completion. IEEE Trans Knowl Data Eng 37(5):2756\u20132770. https:\/\/doi.org\/10.1109\/TKDE.2025.3538110","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"597_CR37","doi-asserted-by":"crossref","unstructured":"Liang K, Meng L, Liu M, Liu Y, Tu W, Wang S, Zhou S, Liu X, Sun F (2023) A Survey of Knowledge Graph Reasoning on Graph Types: Static, Dynamic, and Multimodal. arXiv:2212.05767","DOI":"10.1109\/TPAMI.2024.3417451"},{"key":"597_CR38","unstructured":"Li L, Jin Z, He Y, Jin D, Duan H, Tao Z, Zhang X, Li J (2025) Rethinking Regularization Methods for Knowledge Graph Completion. arXiv:abs\/2505.23442"},{"key":"597_CR39","unstructured":"Li L, Jin Z, Zhang Y, Jin D, Dou C, He Y, Zhang X, Zhao H (2025) Towards Structure-aware Model for Multi-modal Knowledge Graph Completion. arXiv:https:\/\/arxiv.org\/abs\/2505.21973"},{"key":"597_CR40","doi-asserted-by":"publisher","unstructured":"Li M, Liang K, Lai Y, Liu X (2025) Knowledge graph reasoning based on information enhancement and subgraph alignment. IEEE Transactions on Neural Networks and Learning Systems, 1\u201313 https:\/\/doi.org\/10.1109\/TNNLS.2025.3627430","DOI":"10.1109\/TNNLS.2025.3627430"},{"key":"597_CR41","doi-asserted-by":"publisher","unstructured":"Liu T (2024) Multi-modal knowledge graph completion: A survey. In: Proceedings of the International conference on image processing, machine learning and pattern recognition. IPMLP \u201924, 116\u2013121. Association for computing machinery, New York, NY, USA. https:\/\/doi.org\/10.1145\/3700906.3700925","DOI":"10.1145\/3700906.3700925"},{"issue":"15","key":"597_CR42","doi-asserted-by":"publisher","first-page":"2287","DOI":"10.3390\/electronics11152287","volume":"11","author":"K Liu","year":"2022","unstructured":"Liu K, Wang F, Ding Z, Liang S, Yu Z, Zhou Y (2022) Recent progress of using knowledge graph for cybersecurity. Electronics 11(15):2287. https:\/\/doi.org\/10.3390\/electronics11152287","journal-title":"Electronics"},{"key":"597_CR43","doi-asserted-by":"crossref","unstructured":"Li Z, Zeng J, Chen Y, Liang Z (2022) Attackg: Constructing technique knowledge graph from cyber threat intelligence reports. arXiv:https:\/\/arxiv.org\/abs\/2111.07093","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"597_CR44","unstructured":"Makrakis GM, Kolias C, Kambourakis G, Rieger C, Benjamin J (2021) Vulnerabilities and attacks against industrial control systems and critical infrastructures. CoRR arXiv:abs\/2109.03945"},{"key":"597_CR45","doi-asserted-by":"publisher","unstructured":"Mavroeidis V, Bromander S (2017) Cyber threat intelligence model: An evaluation of taxonomies, sharing standards, and ontologies within cyber threat intelligence. In: 2017 European Intelligence and Security Informatics Conference (EISIC), 91\u201398. https:\/\/doi.org\/10.1109\/EISIC.2017.20","DOI":"10.1109\/EISIC.2017.20"},{"key":"597_CR46","unstructured":"Mendes C, Rios TN (2023) Explainable artificial intelligence and cybersecurity: A systematic literature review. arXiv:2303.01259"},{"key":"597_CR47","doi-asserted-by":"publisher","first-page":"100464","DOI":"10.1016\/j.ijcip.2021.100464","volume":"35","author":"T Miller","year":"2021","unstructured":"Miller T, Staves A, Maesschalck S, Sturdee M, Green B (2021) Looking back to look forward: Lessons learnt from cyber-attacks on industrial control systems. Int J Crit Infrastruct Prot 35:100464. https:\/\/doi.org\/10.1016\/j.ijcip.2021.100464","journal-title":"Int J Crit Infrastruct Prot"},{"key":"597_CR48","unstructured":"MITRE corporation: common attack pattern enumeration and classification (CAPEC). Accessed: Oct. 2025 (2024). https:\/\/capec.mitre.org\/"},{"key":"597_CR49","unstructured":"MITRE corporation: common platform enumeration (CPE). Accessed: Oct. 2025 (2024). https:\/\/cpe.mitre.org\/"},{"key":"597_CR50","unstructured":"MITRE corporation: common vulnerabilities and exposures (CVE). Accessed: Oct. 2025 (2024). https:\/\/cve.mitre.org\/"},{"key":"597_CR51","unstructured":"MITRE corporation: common weakness enumeration (CWE). Accessed: Oct. 2025 (2024). https:\/\/cwe.mitre.org\/"},{"key":"597_CR52","unstructured":"MITRE: ATT&CK for industrial control systems (ICS). https:\/\/attack.mitre.org\/matrices\/ics\/. Accessed: Oct. 10, 2025 (2022)"},{"key":"597_CR53","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104120","volume":"148","author":"I Mouiche","year":"2025","unstructured":"Mouiche I, Saad S (2025) Entity and relation extractions for threat intelligence knowledge graphs. Comput & Secur 148:104120. https:\/\/doi.org\/10.1016\/j.cose.2024.104120","journal-title":"Comput & Secur"},{"key":"597_CR54","first-page":"271","volume-title":"Contributions presented at the international conference on computing, communication,","author":"N Naik","year":"2024","unstructured":"Naik N, Jenkins P, Grace P, Naik D, Prajapat S, Song J (2024) A comparative analysis of threat modelling methods: Stride, dread, vast, pasta, octave, and linddun. In: Naik N, Jenkins P, Prajapat S, Grace P (eds) Contributions presented at the international conference on computing, communication,. Springer, Cham, pp 271\u2013280"},{"issue":"21","key":"597_CR55","doi-asserted-by":"publisher","first-page":"8840","DOI":"10.3390\/s23218840","volume":"23","author":"M Nankya","year":"2023","unstructured":"Nankya M, Chataut R, Akl R (2023) Securing industrial control systems: Components, cyber threats, and machine learning-driven defense strategies. Sensors (Basel) 23(21):8840. https:\/\/doi.org\/10.3390\/s23218840","journal-title":"Sensors (Basel)"},{"key":"597_CR56","unstructured":"National institute of standards and technology (NIST): Guide to industrial control systems (ICS) security, NIST SP 800-82 Rev. 3. https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-82r3.pdf. Accessed: October 10, 2025 (2023)"},{"issue":"6","key":"597_CR57","doi-asserted-by":"publisher","first-page":"5695","DOI":"10.1109\/TKDE.2022.3175719","volume":"35","author":"Y Ren","year":"2023","unstructured":"Ren Y, Xiao Y, Zhou Y, Zhang Z, Tian Z (2023) Cskg4apt: A cybersecurity knowledge graph for advanced persistent threat organization attribution. IEEE Trans Knowl Data Eng 35(6):5695\u20135709. https:\/\/doi.org\/10.1109\/TKDE.2022.3175719","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"597_CR58","doi-asserted-by":"publisher","first-page":"163046","DOI":"10.1109\/ACCESS.2025.3603580","volume":"13","author":"MS Salek","year":"2025","unstructured":"Salek MS, Chowdhury M, Munir MB, Cai Y, Hasan MI, Tine J-M, Khan L, Rahman M (2025) A large language model-supported threat modeling framework for transportation cyber-physical systems. IEEE Access 13:163046\u2013163070. https:\/\/doi.org\/10.1109\/ACCESS.2025.3603580","journal-title":"IEEE Access"},{"issue":"1","key":"597_CR59","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1108\/TQM-07-2022-0215","volume":"36","author":"M Samanta","year":"2023","unstructured":"Samanta M, Virmani N, Singh R, Haque S, Jamshed M (2023) Analysis of critical success factors for successful integration of lean six sigma and industry 4.0 for organizational excellence. The TQM J 36(1):208\u2013243. https:\/\/doi.org\/10.1108\/TQM-07-2022-0215","journal-title":"The TQM J"},{"key":"597_CR60","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107524","volume":"233","author":"I Sarhan","year":"2021","unstructured":"Sarhan I, Spruit M (2021) Open-cykg: An open cyber threat intelligence knowledge graph. Knowl-Based Syst 233:107524. https:\/\/doi.org\/10.1016\/j.knosys.2021.107524","journal-title":"Knowl-Based Syst"},{"key":"597_CR61","doi-asserted-by":"publisher","unstructured":"Shen G, Wang W, Mu Q, Pu Y, Qin Y, Yu M (2020) Data-driven cybersecurity knowledge graph construction for industrial control system security 2020:1\u201313. https:\/\/doi.org\/10.1155\/2020\/8883696","DOI":"10.1155\/2020\/8883696"},{"issue":"9","key":"597_CR62","doi-asserted-by":"publisher","first-page":"3511","DOI":"10.1007\/s10115-023-01860-3","volume":"65","author":"LF Sikos","year":"2023","unstructured":"Sikos LF (2023) Cybersecurity knowledge graphs. Knowl Inf Syst 65(9):3511\u20133531. https:\/\/doi.org\/10.1007\/s10115-023-01860-3","journal-title":"Knowl Inf Syst"},{"issue":"22","key":"597_CR63","doi-asserted-by":"publisher","first-page":"7135","DOI":"10.3390\/s24227135","volume":"24","author":"H Song","year":"2024","unstructured":"Song H, Yuan Y, Wang Y, Yang J, Luo H, Li S (2024) A security posture assessment of industrial control systems based on evidential reasoning and belief rule base. Sensors (Basel) 24(22):7135. https:\/\/doi.org\/10.3390\/s24227135","journal-title":"Sensors (Basel)"},{"key":"597_CR64","unstructured":"Srinivasan H, Karimi M (2025) Threat-based security controls to protect industrial control systems. arXiv:https:\/\/arxiv.org\/abs\/2501.13268"},{"key":"597_CR65","doi-asserted-by":"publisher","DOI":"10.1016\/j.cie.2024.110657","volume":"200","author":"X Sun","year":"2025","unstructured":"Sun X, Song Y (2025) Unlocking the synergy: Increasing productivity through human-ai collaboration in the industry 5.0 era. Comput & Ind Eng 200:110657","journal-title":"Comput & Ind Eng"},{"key":"597_CR66","doi-asserted-by":"publisher","unstructured":"Sun L, Li Z, Xie L, Ye M, Chen B (2022) Aptkg: Constructing threat intelligence knowledge graph from open-source apt reports based on deep learning. In: 2022 5th International conference on data science and information technology (DSIT), 01\u201306. https:\/\/doi.org\/10.1109\/DSIT55514.2022.9943933","DOI":"10.1109\/DSIT55514.2022.9943933"},{"key":"597_CR67","unstructured":"Syed Z, Padia A, Finin T, Mathews L, Joshi A (2016) Uco: A unified cybersecurity ontology. Technical report"},{"key":"597_CR68","unstructured":"Toward sustainability and resilience with industry 4.0 and industry 5.0. Frontiers in manufacturing technology 1, 861656 (2022). Accessed: 2025-10-21"},{"key":"597_CR69","doi-asserted-by":"crossref","unstructured":"Tsoumas B, Papagiannakopoulos P, Dritsas S, Gritzalis D (2006) Security-by-ontology: A knowledge-centric approach, 99\u2013110","DOI":"10.1007\/0-387-33406-8_9"},{"issue":"2","key":"597_CR70","doi-asserted-by":"publisher","first-page":"85","DOI":"10.14445\/22312803\/IJCTT-V69I2P113","volume":"69","author":"P Tyagi","year":"2021","unstructured":"Tyagi P (2021) Convergence of IT and OT - cybersecurity related challenges and best practices. Int J Comput Trends Technol (IJCTT) 69(2):85\u201392. https:\/\/doi.org\/10.14445\/22312803\/IJCTT-V69I2P113","journal-title":"Int J Comput Trends Technol (IJCTT)"},{"key":"597_CR71","doi-asserted-by":"publisher","first-page":"122317","DOI":"10.1016\/j.techfore.2023.122317","volume":"188","author":"N Virmani","year":"2023","unstructured":"Virmani N, Sharma S, Kumar A, Luthra S (2023) Adoption of industry 4.0 evidence in emerging economy: Behavioral reasoning theory perspective. Technol Forecast Soc Chang 188:122317. https:\/\/doi.org\/10.1016\/j.techfore.2023.122317","journal-title":"Technol Forecast Soc Chang"},{"issue":"2","key":"597_CR72","doi-asserted-by":"publisher","first-page":"454","DOI":"10.1109\/TEM.2020.3048554","volume":"70","author":"N Virmani","year":"2023","unstructured":"Virmani N, Salve UR, Kumar A, Luthra S (2023) Analyzing roadblocks of industry 4.0 adoption using graph theory and matrix approach. IEEE Trans Eng Manage 70(2):454\u2013463. https:\/\/doi.org\/10.1109\/TEM.2020.3048554","journal-title":"IEEE Trans Eng Manage"},{"key":"597_CR73","doi-asserted-by":"publisher","unstructured":"Virmani N, Salve U (2022) Significance of human factors and ergonomics (hfe): Mediating its role between industry 4.0 implementation and operational excellence. IEEE Transactions on Engineering Management PP, 1\u201314 https:\/\/doi.org\/10.1109\/TEM.2021.3091398","DOI":"10.1109\/TEM.2021.3091398"},{"issue":"12","key":"597_CR74","doi-asserted-by":"publisher","first-page":"9214","DOI":"10.1109\/JIOT.2021.3094295","volume":"9","author":"Y Wu","year":"2022","unstructured":"Wu Y, Dai H-N, Tang H (2022) Graph neural networks for anomaly detection in industrial internet of things. IEEE Internet Things J 9(12):9214\u20139231. https:\/\/doi.org\/10.1109\/JIOT.2021.3094295","journal-title":"IEEE Internet Things J"},{"issue":"12","key":"597_CR75","doi-asserted-by":"publisher","first-page":"12305","DOI":"10.1002\/int.23088","volume":"37","author":"F Yan","year":"2022","unstructured":"Yan F, Wen S, Nepal S, Paris C, Xiang Y (2022) Explainable machine learning in cybersecurity: A survey. Int J Intell Syst 37(12):12305\u201312334. https:\/\/doi.org\/10.1002\/int.23088","journal-title":"Int J Intell Syst"},{"key":"597_CR76","doi-asserted-by":"crossref","unstructured":"Yin J, Hong W, Wang H, Cao J, Miao Y, Zhang Y (2024) A compact vulnerability knowledge graph for risk assessment. ACM Trans. Knowl. Discov. Data 18(8)","DOI":"10.1145\/3671005"},{"key":"597_CR77","doi-asserted-by":"publisher","first-page":"104220","DOI":"10.1016\/j.cose.2024.104220","volume":"150","author":"Y Zhang","year":"2025","unstructured":"Zhang Y, Du T, Ma Y, Wang X, Xie Y, Yang G, Lu Y, Chang E-C (2025) Attackg+: Boosting attack graph construction with large language models. Comput & Secur 150:104220. https:\/\/doi.org\/10.1016\/j.cose.2024.104220","journal-title":"Comput & Secur"},{"key":"597_CR78","doi-asserted-by":"publisher","first-page":"104558","DOI":"10.1016\/j.cose.2025.104558","volume":"157","author":"X Zhang","year":"2025","unstructured":"Zhang X, Lai Y, Dong X, Xu X (2025) Mer-gcn: Reasoning about attacking group behaviors using industrial control system attack knowledge graphs. Comput & Secur 157:104558","journal-title":"Comput & Secur"},{"key":"597_CR79","unstructured":"Zhao, J., Yan, Q., Liu, X., Li, B., Zuo, G.: Cyber threat intelligence modeling based on heterogeneous graph convolutional network. In: 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020), pp. 241\u2013256. USENIX Association, San Sebastian (2020). https:\/\/www.usenix.org\/conference\/raid2020\/presentation\/zhao"},{"key":"597_CR80","doi-asserted-by":"publisher","first-page":"103524","DOI":"10.1016\/j.cose.2023.103524","volume":"136","author":"X Zhao","year":"2024","unstructured":"Zhao X, Jiang R, Han Y, Li A, Peng Z (2024) A survey on cybersecurity knowledge graph construction. Comput & Secur 136:103524. https:\/\/doi.org\/10.1016\/j.cose.2023.103524","journal-title":"Comput & Secur"},{"key":"597_CR81","doi-asserted-by":"crossref","unstructured":"Zhou Y, Wang Z, Jiang Y, Ma B, Wang R, Liu Y, Zhao Y, Tian Z (2025) Aekg4apt: An ai-enhanced knowledge graph for advanced persistent threats with large language model analysis","DOI":"10.1145\/3735645"},{"issue":"2","key":"597_CR82","doi-asserted-by":"publisher","first-page":"715","DOI":"10.1109\/tkde.2022.3224228","volume":"36","author":"X Zhu","year":"2024","unstructured":"Zhu X, Li Z, Wang X, Jiang X, Sun P, Wang X, Xiao Y, Yuan NJ (2024) Multi-modal knowledge graph construction and application: A survey. IEEE Trans Knowl Data Eng 36(2):715\u2013735. https:\/\/doi.org\/10.1109\/tkde.2022.3224228","journal-title":"IEEE Trans Knowl Data Eng"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00597-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00597-0","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00597-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T06:24:06Z","timestamp":1778739846000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00597-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,14]]},"references-count":82,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["597"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00597-0","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,14]]},"assertion":[{"value":"12 December 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}],"article-number":"167"}}