3 papers
cs.CR2026
Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion
Cédric Bonhomme, Alexandre Dulaunoy
We present a reproducible pipeline for mapping Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK Enterprise techniques from free-text vulnerability descriptions. Rather t…
cs.CR2026
Modeling Sparse and Bursty Vulnerability Sightings: Forecasting Under Data Constraints
Cedric Bonhomme, Alexandre Dulaunoy
Understanding and anticipating vulnerability-related activity is a major challenge in cyber threat intelligence. This work investigates whether vulnerability sightings, such as pro…
cs.CR2025
VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification
Cédric Bonhomme, Alexandre Dulaunoy
This paper presents VLAI, a transformer-based model that predicts software vulnerability severity levels directly from text descriptions. Built on RoBERTa, VLAI is fine-tuned on ov…