Adaptive Retrieval and Verification: A Shared Agentic Controller for Cybersecurity RAG and GraphRAG
Abstract
Cybersecurity question answering often requires connecting evidence across heterogeneous sources and reasoning over multiple entities and relationships. Conventional Retrieval-Augmented Generation (RAG) retrieves semantically similar evidence as a flat context, limiting its ability to support cross-domain and multi-hop questions. We propose an agentic, multi-layer cybersecurity GraphRAG framework that integrates heterogeneous repositories through explicit bridge relationships and combines semantic retrieval with intent-aware graph traversal and re-ranking. A shared, bounded controller is instantiated over both flat RAG and GraphRAG to plan evidence requirements, assess retrieval sufficiency, perform targeted retries, and verify generated claims before returning a complete answer, partial answer, or abstention. We evaluate Basic RAG, Agentic RAG, GraphRAG, and Agentic GraphRAG on a 40-question cybersecurity benchmark. Agentic GraphRAG achieves the highest overall answer-quality score of 4.04/5, compared with 3.82 for GraphRAG, 3.05 for Agentic RAG, and 3.00 for Basic RAG. Relative to GraphRAG, it provides numerical improvements of 5.8% in overall answer quality, 20.5% in pooled identifier recall, and 30.9% on multi-hop questions. These gains increase mean latency from 4.23 to 30.96 seconds. The results indicate that agentic control is most effective when supported by structured, relational evidence, while revealing a substantial quality-efficiency trade-off.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.