{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T07:15:30Z","timestamp":1772349330464,"version":"3.50.1"},"reference-count":36,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T00:00:00Z","timestamp":1772150400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62272028"],"award-info":[{"award-number":["62272028"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Cyber threat intelligence (CTI) has been explored to strengthen system security via taking raw threat data from various data sources and transforming it into actionable insights that enable organizations to predict, detect, and respond to cyber threats. Named entity recognition (NER) and relation extraction (RE) are the key tasks of CTI data mining. However, current CTI NER and\/or RE research is mainly focused on English CTI, which is not directly transferable to Chinese CTI due to fundamental linguistic and terminological differences. Moreover, the existing limited studies on Chinese CTI do not effectively address uncertainty in predictions in low-resource scenarios where entities and relations are sparse. This work aims to improve the performance of NER and RE tasks in low-resource Chinese CTI scenarios, and we make two major contributions. The first is that we construct a Chinese CTI dataset, which includes 16 types of entities and 9 types of relations\u2014more than those of the existing open-source dataset on Chinese CTI. The second is that we propose an entropy-driven approach for entity and relation (EDAER) extraction. EDAER is the first to combine the techniques of RoBERTa_wwm, Mamba, RDCNN and CRF to perform NER tasks. In addition, EDAER is the first to apply entropy to quantify the uncertainty of the model\u2019s predictions in NER and RE tasks in Chinese CTI scenarios. Moreover, EDAER is the first to apply contrastive learning techniques in Chinese CTI scenarios to learn meaningful features by maximizing the similarity between positive samples and minimizing the similarity between negative samples. Extensive experimental results on public and our built datasets demonstrate that our proposed approach performs the best. These results show that (1) RoBERTa_wwwm significantly outperforms BERT on both NER and RE tasks; (2) Mamba outperforms BiLSTM on the NER task; (3) the entropy-based dynamic gating mechanism contributes to performance improvements in both NER and RE tasks; and (4) the uncertainty-guided contrastive learning mechanism is helpful for performance improvement in the NER task.<\/jats:p>","DOI":"10.3390\/e28030261","type":"journal-article","created":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T11:22:57Z","timestamp":1772191377000},"page":"261","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["EDAER: Entropy-Driven Approach for Entity and Relation Extraction in Chinese Cyber Threat Intelligence"],"prefix":"10.3390","volume":"28","author":[{"given":"Yong","family":"Li","sequence":"first","affiliation":[{"name":"School of Cybersecurity, Northwestern Polytechnical University, Xi\u2019an 100044, China"},{"name":"Data Communication Technology Research Institute, Beijing 100089, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiuping","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cybersecurity, Northwestern Polytechnical University, Xi\u2019an 100044, China"},{"name":"Data Communication Technology Research Institute, Beijing 100089, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yangbai","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cybersecurity, Northwestern Polytechnical University, Xi\u2019an 100044, China"},{"name":"Data Communication Technology Research Institute, Beijing 100089, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiqiang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Cybersecurity, Northwestern Polytechnical University, Xi\u2019an 100044, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaowei","family":"Li","sequence":"additional","affiliation":[{"name":"Data Communication Technology Research Institute, Beijing 100089, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qi","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Jiaotong University, Beijing 100006, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2975-8857","authenticated-orcid":false,"given":"Xiaolin","family":"Chang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Jiaotong University, Beijing 100006, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,2,27]]},"reference":[{"key":"ref_1","unstructured":"(2026, February 20). An Overview of 2025 Global APT Attack Landscape. Available online: https:\/\/nsfocusglobal.com\/pt-br\/an-overview-of-2025-global-apt-attack-landscape\/."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Wu, X., Wang, M., Chang, X., Li, C., Wang, Y., Liang, B., and Deng, S. (2025). Resisting Memorization-Based APT Attacks Under Incomplete Information in DDHR Architecture: An Entropy-Heterogeneity-Aware RL-Based Scheduling Approach. Entropy, 27.","DOI":"10.3390\/e27121238"},{"key":"ref_3","unstructured":"(2026, February 20). Incident Response Recommendations and Considerations for Cybersecurity Risk Management, Available online: https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-61r3.pdf."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"104120","DOI":"10.1016\/j.cose.2024.104120","article-title":"Entity and relation extractions for threat intelligence knowledge graphs","volume":"148","author":"Mouiche","year":"2025","journal-title":"Comput. Secur."},{"key":"ref_5","first-page":"299","article-title":"Chinese Cyber Threat Intelligence Named Entity Recognition via RoBERTa-wwm-RDCNN-CRF","volume":"77","author":"Zhen","year":"2023","journal-title":"Comput. Mater. Contin."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"627","DOI":"10.1109\/TSUSC.2023.3240411","article-title":"Cdtier: A Chinese dataset of threat intelligence entity relationships","volume":"8","author":"Zhou","year":"2023","journal-title":"IEEE Trans. Sustain. Comput."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Cui, Y., Che, W., Liu, T., Qin, B., Wang, S., and Hu, G. (2020). Revisiting pre-trained models for Chinese natural language processing. arXiv.","DOI":"10.18653\/v1\/2020.findings-emnlp.58"},{"key":"ref_8","unstructured":"Gu, A., and Dao, T. (2024, January 7\u20139). Mamba: Linear-time sequence modeling with selective state spaces. Proceedings of the First Conference on Language Modeling, Philadelphia, PA, USA."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Demirol, D., Das, R., and Hanbay, D. (2025). A novel approach for cyber threat analysis systems using bert model from cyber threat intelligence data. Symmetry, 17.","DOI":"10.3390\/sym17040587"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Chen, L., Deng, H., Zhang, J., Zheng, B., and Jiang, R. (2025). Threat Intelligence Named Entity Recognition Based on Segment-Level Information Extraction and Similar Semantic Space Construction. Symmetry, 17.","DOI":"10.3390\/sym17050783"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"4109","DOI":"10.1007\/s10489-021-02546-5","article-title":"Uamner: Uncertainty-aware multimodal named entity recognition in social media posts","volume":"52","author":"Liu","year":"2022","journal-title":"Appl. Intell."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Han, Y., Lu, Z., Jiang, B., Liu, Y., Zhang, C., Jiang, Z., and Li, N. (2020). MTLAT: A Multi-Task Learning Framework Based on Adversarial Training for Chinese Cybersecurity NER. Network and Parallel Computing; NPC 2020, Springer.","DOI":"10.1007\/978-3-030-79478-1_4"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"111762","DOI":"10.1016\/j.knosys.2024.111762","article-title":"Uncertainty-Aware Contrastive Learning for semi-supervised named entity recognition","volume":"296","author":"Yang","year":"2024","journal-title":"Knowl.-Based Syst."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"126707","DOI":"10.1016\/j.eswa.2025.126707","article-title":"A Two-Stage Boundary-Enhanced Contrastive Learning approach for nested named entity recognition","volume":"271","author":"Liu","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"11020","DOI":"10.1007\/s10489-024-05798-z","article-title":"Hierarchical symmetric cross entropy for distant supervised relation extraction","volume":"54","author":"Liu","year":"2024","journal-title":"Appl. Intell."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Sun, Q., Huang, K., Yang, X., Hong, P., Zhang, K., and Poria, S. (2023). Uncertainty Guided Label Denoising for Document-level Distant Relation Extraction. Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), Association for Computational Linguistics.","DOI":"10.18653\/v1\/2023.acl-long.889"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Jamal, R., Ourekouch, M., and Erradi, M. (2025). UOREX: Towards Uncertainty-Aware Open Relation Extraction. Proceedings of the 2025 Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers), Association for Computational Linguistics.","DOI":"10.18653\/v1\/2025.naacl-long.307"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Li, Y., Yu, X., Liu, Y., Chen, H., and Liu, C. (2023). Uncertainty-Aware Bootstrap Learning for Joint Extraction on Distantly-Supervised Data. Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Volume 2: Short Papers), Association for Computational Linguistics.","DOI":"10.18653\/v1\/2023.acl-short.116"},{"key":"ref_19","unstructured":"Devlin, J., Chang, M.W., Lee, K., and Toutanova, K. (2019). Bert: Pre-training of deep bidirectional transformers for language understanding. Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers), Association for Computational Linguistics."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Tsai, C., Yang, C., and Chen, C. (2020). CTI ANT: Hunting for Chinese threat intelligence. 2020 IEEE International Conference on Big Data (Big Data), IEEE.","DOI":"10.1109\/BigData50022.2020.9378125"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Long, Z., Tan, L., Zhou, S., He, C., and Liu, X. (2019, January 14\u201319). Collecting indicators of compromise from unstructured text of cybersecurity articles using neural-based sequence labelling. Proceedings of the 2019 International Joint Conference on Neural Networks (IJCNN), Budapest, Hungary.","DOI":"10.1109\/IJCNN.2019.8852142"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Feng, X., He, S., Wei, X., Liu, R., Yue, H., and Wang, X. (2025). PROMPT-BART: A Named Entity Recognition Model Applied to Cyber Threat Intelligence. Appl. Sci., 15.","DOI":"10.20944\/preprints202507.0741.v1"},{"key":"ref_23","first-page":"48","article-title":"Uncertainty Management in the Construction of Knowledge Graphs: A Survey","volume":"3","author":"Jarnac","year":"2025","journal-title":"Trans. Graph Data Knowl."},{"key":"ref_24","unstructured":"(2022, March 06). Neo4j. Available online: https:\/\/neo4j.com\/."},{"key":"ref_25","unstructured":"Lafferty, J., McCallum, A., and Pereira, F. (2001). Conditional random fields: Probabilistic models for segmenting and labeling sequence data. ICML \u201801: Proceedings of the Eighteenth International Conference on Machine Learning, Morgan Kaufmann Publishers Inc."},{"key":"ref_26","unstructured":"Yu, F., and Koltun, V. (2015). Multi-scale context aggregation by dilated convolutions. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Ioffe, S., Vanhoucke, V., and Alemi, A. (2017). Inception-v4, inception-resnet and the impact of residual connections on learning. Proceedings of the AAAI Conference on Artificial Intelligence, AAAI Press.","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref_29","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","volume":"Volume 37","author":"Bach","year":"2015","journal-title":"Proceedings of the 32nd International Conference on Machine Learning"},{"key":"ref_30","unstructured":"Glorot, X., Bordes, A., and Bengio, Y. (2011). Deep sparse rectifier neural networks. Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics, JMLR, Inc.. JMLR Workshop and Conference Proceedings."},{"key":"ref_31","unstructured":"(2025, June 01). Tencent Security. Available online: https:\/\/security.tencent.com."},{"key":"ref_32","unstructured":"(2025, June 01). Alibaba Cloud Security. Available online: https:\/\/help.aliyun.com\/zh\/acsg\/."},{"key":"ref_33","unstructured":"(2025, June 01). 360 Security. Available online: https:\/\/360.net\/research\/analysis\/."},{"key":"ref_34","unstructured":"(2025, June 01). ThreatBook. Available online: https:\/\/www.threatbook.cn."},{"key":"ref_35","unstructured":"(2025, June 01). FreeBuf. Available online: https:\/\/www.freebuf.com."},{"key":"ref_36","unstructured":"(2025, June 01). Qianxin. Available online: https:\/\/ti.qianxin.com\/."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/261\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T05:28:03Z","timestamp":1772342883000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/261"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,27]]},"references-count":36,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,3]]}},"alternative-id":["e28030261"],"URL":"https:\/\/doi.org\/10.3390\/e28030261","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,27]]}}}