{"id":{"repo_id":"utc","oai_identifier":"oai:scholar.utc.edu:theses-2140"},"canonical_url":"https://search.dev.ndltd.org/etd/utc/oai:scholar.utc.edu:theses-2140","repository":{"repo_id":"utc","name":"University of Tennessee - Chattanooga","base_url":"https://scholar.utc.edu/do/oai/"},"display":{"title":"Optimizing cybersecurity knowledge graph question answering: a framework for performance and generalization","abstract":"UTC's ForensiQ system demonstrates that Knowledge Graph Question Answering (KGQA) systems can handle the scale and complexity of Internet of Things (IoT) forensics. However, using KGQA systems requires a high level of technical expertise, and there are concerns about ForensiQ's inference speed and generalization ability. This thesis aims to enhance KGQA system usability in IoT forensics by extending ForensiQ’s framework to aid investigators, improving ForensiQ's entity detection speed, and testing performance on rephrased questions. Towards this goal, a Django web application was developed to visualize KGQA reasoning, aid KG exploration, and facilitate the creation of custom KGQA datasets. We also replaced ForensiQ's language-model-based entity detector with a name-dictionary-based one, significantly improving the entity detection speed while maintaining accuracy. Tested with rephrased questions, the extended ForensiQ versions outperform the baseline. The experimental results demonstrate the significant improvement of the extended ForensiQ framework on performance and generalization for IoT forensics investigation.","abstract_html":"UTC&#x27;s ForensiQ system demonstrates that Knowledge Graph Question Answering (KGQA) systems can handle the scale and complexity of Internet of Things (IoT) forensics. However, using KGQA systems requires a high level of technical expertise, and there are concerns about ForensiQ&#x27;s inference speed and generalization ability. This thesis aims to enhance KGQA system usability in IoT forensics by extending ForensiQ’s framework to aid investigators, improving ForensiQ&#x27;s entity detection speed, and testing performance on rephrased questions. Towards this goal, a Django web application was developed to visualize KGQA reasoning, aid KG exploration, and facilitate the creation of custom KGQA datasets. We also replaced ForensiQ&#x27;s language-model-based entity detector with a name-dictionary-based one, significantly improving the entity detection speed while maintaining accuracy. Tested with rephrased questions, the extended ForensiQ versions outperform the baseline. The experimental results demonstrate the significant improvement of the extended ForensiQ framework on performance and generalization for IoT forensics investigation.","abstract_has_math":false,"creators":["Gumaa, Ayman"],"institution":"University of Tennessee at Chattanooga","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":["Xie, Mengjun","Qin, Hong; Liang, Yu","College of Engineering and Computer Science"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-08-01T07:00:00Z","date_published":"2025-08-01T07:00:00Z","updated_at":"2026-07-24T05:47:21Z","subjects":["Digital forensic science","Internet of things"],"languages":["English","eng"],"rights":[],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://scholar.utc.edu/theses/960","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Xie, Mengjun","Qin, Hong; Liang, Yu","College of Engineering and Computer Science"]},{"key":"dc:creator","label":"Author","values":["Gumaa, Ayman"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2024-08-01T07:00:00Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-08-01T07:00:00Z"]},{"key":"dc:publisher","label":"Institution","values":["University of Tennessee at Chattanooga","Chattanooga (Tenn.)"]},{"key":"dc:relation","label":"Dc Relation","values":["Masters Theses and Doctoral Dissertations"]},{"key":"dc:type","label":"Dc Type","values":["Masters theses","Text"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Digital forensic science","Internet of things"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["English","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://scholar.utc.edu/theses/960"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Dept. of Computer Science and Engineering","M. S.; A thesis submitted to the faculty of the University of Tennessee at Chattanooga in partial fulfillment of the requirements of the degree of Master of Science."]},{"key":"dc:description.abstract","label":"Abstract","values":["UTC's ForensiQ system demonstrates that Knowledge Graph Question Answering (KGQA) systems can handle the scale and complexity of Internet of Things (IoT) forensics. However, using KGQA systems requires a high level of technical expertise, and there are concerns about ForensiQ's inference speed and generalization ability. This thesis aims to enhance KGQA system usability in IoT forensics by extending ForensiQ’s framework to aid investigators, improving ForensiQ's entity detection speed, and testing performance on rephrased questions. Towards this goal, a Django web application was developed to visualize KGQA reasoning, aid KG exploration, and facilitate the creation of custom KGQA datasets. We also replaced ForensiQ's language-model-based entity detector with a name-dictionary-based one, significantly improving the entity detection speed while maintaining accuracy. Tested with rephrased questions, the extended ForensiQ versions outperform the baseline. The experimental results demonstrate the significant improvement of the extended ForensiQ framework on performance and generalization for IoT forensics investigation."]},{"key":"dc:title","label":"Title","values":["Optimizing cybersecurity knowledge graph question answering: a framework for performance and generalization"]}]}],"canonical_facts":{"dc:contributor":["Xie, Mengjun","Qin, Hong; Liang, Yu","College of Engineering and Computer Science"],"dc:creator":["Gumaa, Ayman"],"dc:date":["2024-08-01T07:00:00Z"],"dc:date.available":["2025-08-01T07:00:00Z"],"dc:description":["Dept. of Computer Science and Engineering","M. S.; A thesis submitted to the faculty of the University of Tennessee at Chattanooga in partial fulfillment of the requirements of the degree of Master of Science."],"dc:description.abstract":["UTC's ForensiQ system demonstrates that Knowledge Graph Question Answering (KGQA) systems can handle the scale and complexity of Internet of Things (IoT) forensics. However, using KGQA systems requires a high level of technical expertise, and there are concerns about ForensiQ's inference speed and generalization ability. This thesis aims to enhance KGQA system usability in IoT forensics by extending ForensiQ’s framework to aid investigators, improving ForensiQ's entity detection speed, and testing performance on rephrased questions. Towards this goal, a Django web application was developed to visualize KGQA reasoning, aid KG exploration, and facilitate the creation of custom KGQA datasets. We also replaced ForensiQ's language-model-based entity detector with a name-dictionary-based one, significantly improving the entity detection speed while maintaining accuracy. Tested with rephrased questions, the extended ForensiQ versions outperform the baseline. The experimental results demonstrate the significant improvement of the extended ForensiQ framework on performance and generalization for IoT forensics investigation."],"dc:identifier":["https://scholar.utc.edu/theses/960"],"dc:language":["English","eng"],"dc:publisher":["University of Tennessee at Chattanooga","Chattanooga (Tenn.)"],"dc:relation":["Masters Theses and Doctoral Dissertations"],"dc:rights":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:subject":["Digital forensic science","Internet of things"],"dc:title":["Optimizing cybersecurity knowledge graph question answering: a framework for performance and generalization"],"dc:type":["Masters theses","Text"]},"updated_at":"2026-07-24T05:47:21Z"}