Switch language한국어
Back to the list

Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion

TL;DR AI

Key summary

2 min read
  1. Researchers trained a CVE-to-MITRE ATT&CK multi-label classifier on 1,207 expert-labeled vulnerabilities and beat a zero-shot baseline.

  2. Adding more expert-curated labels improved performance, but LLM-generated label expansion did not reliably help and sometimes hurt rare-technique coverage.

  3. A corrected evaluation showed earlier reported gains were mostly due to noisy checkpoint selection on a small test split.

  4. The study highlights that label quality matters more than label quantity, and that weak evaluation can overstate security ML results.

Read the original