Bridging legal obligations and cybersecurity practice requires mapping abstract regulatory language to concrete technical threats, a task currently performed manually by compliance professionals. Existing work either extracts legal obligations without grounding them in technical threat taxonomies, or models cybersecurity threats without linking them to the legal texts that create compliance obligations. We present a preliminary neuro-symbolic multi-agent framework for integrating legal-cybersecurity knowledge that maps multilingual EU regulatory text to MITRE ATT&CK techniques and leverages those mappings to support traceable legal document retrieval. The framework combines curated multilingual indicators, LLM-based re-analysis, and a MITRE-annotated knowledge graph used at query time for retrieval. We apply the approach to 1,351 EU legal and policy documents from the CEPS-Zenner collection spanning 10 languages. Our preliminary evaluation includes agreement with proxy labels for corpus-scale internal consistency, a small human study for trustworthiness analysis, and performance evaluation against BM25 on in-domain regulatory text. The results suggest that technique-aware retrieval may be useful for compliance support in the EU cybersecurity domain, while also highlighting the need for broader expert annotation and stronger ground-truth benchmarks.
A Neuro-Symbolic Multi-Agent Approach to Legal-Cybersecurity Knowledge Integration / Bonfanti, C., Druetto, A., Basile, C., Ranasinghe, T., Zampieri, M.. - (In corso di stampa). (Convegno Nazionale CINI sull'Intelligenza Artificiale, Roma 18-19 Giugno 2026).
A Neuro-Symbolic Multi-Agent Approach to Legal-Cybersecurity Knowledge Integration
Bonfanti,Chiara;Basile, Cataldo;
In corso di stampa
Abstract
Bridging legal obligations and cybersecurity practice requires mapping abstract regulatory language to concrete technical threats, a task currently performed manually by compliance professionals. Existing work either extracts legal obligations without grounding them in technical threat taxonomies, or models cybersecurity threats without linking them to the legal texts that create compliance obligations. We present a preliminary neuro-symbolic multi-agent framework for integrating legal-cybersecurity knowledge that maps multilingual EU regulatory text to MITRE ATT&CK techniques and leverages those mappings to support traceable legal document retrieval. The framework combines curated multilingual indicators, LLM-based re-analysis, and a MITRE-annotated knowledge graph used at query time for retrieval. We apply the approach to 1,351 EU legal and policy documents from the CEPS-Zenner collection spanning 10 languages. Our preliminary evaluation includes agreement with proxy labels for corpus-scale internal consistency, a small human study for trustworthiness analysis, and performance evaluation against BM25 on in-domain regulatory text. The results suggest that technique-aware retrieval may be useful for compliance support in the EU cybersecurity domain, while also highlighting the need for broader expert annotation and stronger ground-truth benchmarks.Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/11583/3015317
