In recent years, threat intelligence analysis based on knowledge graphs has been widely regarded as a key approach to achieving proactive defense. However, existing research still suffers from deficiencies in timeliness and comprehensiveness when it comes to supplementing malicious vulnerabilities, mitigation measures, and their interrelationships, making it difficult to support systematic characterization of complex threats. Particularly in the process of predicting proactive defense measures for vulnerabilities, the modeling design of knowledge graphs remains imperfect, exhibiting significant limitations when depicting causal relationships between vulnerabilities and mitigation measures. Furthermore, most existing approaches model semantic and structural features in isolation, lacking effective mechanisms for synergistic integration. This hinders the deep mining and practical application value of threat intelligence. To address these challenges, we propose $\text {R}^{{3}}\text {S}$ (Reconciling Semantic and Structural Signals), a framework for attack-mitigation reasoning in security knowledge graphs. $\text {R}^{{3}}\text {S}$ consists of two key components: H-AIMG, a hierarchical adversary-informed mitigation graph constructed from practical intelligence on vulnerabilities and attack techniques within the APT organization ecosystem, and DPSR, a Dual-Phase Semantic–Structural Reconciliation approach that jointly exploits semantic and structural perspectives in a coordinated manner. Rather than relying on a fixed fusion mechanism, DPSR dynamically partitions the candidate set based on the confidence gradient of semantic scores, using an algorithm to detect the elbow point in the score distribution. This process guides the adaptive coordination of semantic and structural candidate sets for synergistic ranking, enabling context-sensitive integration of both perspectives. This paper leverages a collaborative optimization strategy to harness the complementary strengths of both approaches, thereby significantly enhancing the overall effectiveness of knowledge graphs in threat intelligence reasoning and attribution. Finally, extensive experiments conducted on H-AIMG clearly validate the effectiveness of the proposed DPSR.
