Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet Embedding
Jian Cui, Hanna Kim, Eugene Jang, Dayeon Yim, Kicheol Kim, Yongjae Lee, Jin-Woo Chung, Seungwon Shin, Xiaojing Liao
Abstract
Twitter is recognized as a crucial platform for the dissemination and gathering of Cyber Threat Intelligence (CTI). Its capability to provide real-time, actionable intelligence makes it an indispensable tool for detecting security events, helping security professionals cope with ever-growing threats. However, the large volume of tweets and inherent noises of human-crafted tweets pose significant challenges in accurately identifying security events. While many studies tried to filter out event-related tweets based on keywords, they are not effective due to their limitation in understanding the semantics of tweets. Another challenge in security event detection from Twitter is the comprehensive coverage of security events. Previous studies emphasized the importance of early detection of security events, but they overlooked the importance of event coverage. To cope with these challenges, in our study, we introduce a novel event attribution-centric tweet embedding method to enable the high precision and coverage of events. Our experiment result shows that the proposed method outperforms existing text and graph-based tweet embedding methods in identifying security events. Leveraging this novel embedding approach, we have developed and implemented a framework, Tweezers, that is applicable to security event detection from Twitter for CTI gathering. This framework has demonstrated its effectiveness, detecting twice as many events compared to established baselines. Additionally, we have showcased two applications, built on Tweezers for the integration and inspection of security events, i.e., security event trend analysis and informative security user identification.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on11
- How Attentive are Graph Attention Networks?Shaked Brody, Uri Alon, Eran YahavICLR 2022 · 1,717 citations
- Tiresias: Predicting Security Events Through Deep LearningYun Shen, Enrico Mariconti, Pierre-Antoine Vervier, Gianluca StringhiniCCS 2018 · 180 citations
- Knowledge-Preserving Incremental Social Event Detection via Heterogeneous GNNsYuwei Cao, Hao Peng, Jia Wu, Yingtong Dou et al.WWW 2021 · 118 citations
- DEEPCASE: Semi-Supervised Contextual Analysis of Security EventsThijs van Ede, Hojjat Aghakhani, Noah Spahn, Riccardo Bortolameotti et al.S&P 2022 · 91 citations
- Multi-modal Multi-label Emotion Recognition with Heterogeneous Hierarchical Message PassingDong Zhang, Xincheng Ju, Wei Zhang, Junhui Li et al.AAAI 2021 · 56 citations
Related papers
- #Twiti: Social Listening for Threat IntelligenceHyejin Shin, WooChul Shim, Saebom Kim, Sol Lee et al.WWW 2021 · 32 citations
- BIC: Twitter Bot Detection with Text-Graph Interaction and Semantic ConsistencyZhenyu Lei, Herun Wan, Wenqian Zhang, Shangbin Feng et al.ACL 2023 · 28 citations
- ETS-MM: A Multi-Modal Social Bot Detection Model Based on Enhanced Textual Semantic RepresentationWei Li, Jiawen Deng, Jiali You, Yuanyuan He et al.WWW 2025 · 10 citations
- Explicit and Implicit Data Augmentation for Social Event DetectionCongbo Ma, Yuxia Wang, Jia Wu, Jian Yang et al.ACL 2025 · 2 citations
- Heterogeneity-Aware Twitter Bot Detection with Relational Graph TransformersShangbin Feng, Zhaoxuan Tan, Rui Li, Minnan LuoAAAI 2022 · 138 citations
