Triple
T27756185
| Position | Surface form | Disambiguated ID | Type / Status |
|---|---|---|---|
| Subject | LoveLetter |
E701337
|
entity |
| Predicate | payloadAction |
P163218
|
FINISHED |
| Object | downloading additional malware |
—
|
LITERAL FINISHED |
How this triple was built (2 steps)
Every LLM step that produced this triple, in pipeline order — named-entity classification, the disambiguation choices (the exact options shown, with the pick highlighted), and the generated description. The batch + timestamp of each is in the Provenance table below.
NER
Named-entity recognition
gpt-5-mini
Instruction
Given a phrase, classify it is english named entity (e.g., persons, organizations, works of art) in Latin script, or not (e.g., literals, dates, URLs, verbose phrases). For disambiguation, the statement where the phrase occurs as object is also given. Please return a JSON object with `phrase` (string, the phrase being analyzed) and `is_ne` (boolean, indicating whether the phrase is a Named Entity).
Input
Phrase: downloading additional malware | Statement: [LoveLetter, payloadAction, downloading additional malware]
PD
Predicate disambiguation
gpt-5-mini-2025-08-07
Target predicate: payloadAction Context triple: [LoveLetter, payloadAction, downloading additional malware]
-
A.
payloadAction
chosen
Indicates an action performed on, with, or involving a payload (such as creating, sending, modifying, or processing it).
-
B.
payloadModule
Indicates a relationship where a module functions as the payload component within a larger system or structure.
-
C.
payloadType
Indicates the kind or category of payload associated with or carried by an entity or action.
-
D.
payloadServiced
Indicates that a payload has been attended to, maintained, or otherwise handled to fulfill its required service or operational needs.
-
E.
payloadField
Indicates that one entity specifies or refers to a particular field within a payload structure associated with another entity.
- F. None of above.
Provenance (3 batches)
The batch behind each pipeline step, in order, with when it ran. Timestamps are batch-level — stages were processed in waves, so the object chain (NER → NED1 → NEDg → NED2) reads in order, but predicate / elicitation batches can sit in a different wave.
| Step | Stage | Batch ID | Status | When |
|---|---|---|---|---|
| creating | Elicitation | batch_69ef6a5193808190816eb7d0020b2d87 |
completed | April 27, 2026, 1:53 p.m. |
| NER | Named-entity recognition | batch_69f63fd6c68481908c542aa03e297b9c |
completed | May 2, 2026, 6:17 p.m. |
| PD | Predicate disambiguation | batch_69f63c6895f0819088655277e45859a8 |
completed | May 2, 2026, 6:03 p.m. |
Created at: April 27, 2026, 4:23 p.m.