[1] Manai E, Mejri M, Fattahi J. Helping CNAs generate CVSS scores faster and more confidently using XAI[J]. Applied Sciences, 2024, 14(20):9231.
[2] Shahid M R, Debar H. CVSS-BERT: Explainable natural language processing to determine the severity of a computer security vulnerability from its description[C]//IEEE ICMLA. 2021.
[3] Tiwari H, Chen Y, Lin C. Advancing vulnerability classification with BERT: A multi-objective learning model[EB/OL]. arXiv, 2025.
[4] Costa J C, Roxo T, Sequeiros J B F, et al. Predicting CVSS metric via description interpretation[J]. IEEE Access, 2022, 10:59125-59134.
[5] Aghaei E, Niu X, Shadid W, et al. SecureBERT: A domain-specific language model for cybersecurity[EB/OL]. arXiv:2204.02685, 2022.
[6] Z. Han, X. Li, Z. Xing, H. Liu, and Z. Feng. Learning to predict severity of software vulnerability using only vulnerability description[C]//IEEE ICSME. 2017:125-136.
[7] Isogai S, Ogata S, Kashiwa Y, et al. Comparison of methods for automatically predicting CVSS base vector[C]//COMPSAC. 2024:1029-1034.
[8] National Institute of Standards and Technology. National Vulnerability Database (NVD) [EB/OL]. Available: https://nvd.nist.gov/. Accessed: 2026-06-15.
[9] Kühn P, Relke D N, Reuter C. Common vulnerability scoring system prediction based on open source intelligence information sources[J]. Computers & Security, 2023, 131:103286.
[10] Sanvito D, Arriciati G, Siracusano G, et al. AutoCVSS: Assessing the performance of LLMs for automated software vulnerability scoring[C]//Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing: Industry Track. 2025:564-575.
[11] FIRST. Common Vulnerability Scoring System version 3.1: Specification Document [EB/OL]. 2019.
[12] C. Elbaz, L. Rilling, and C. Morin. Fighting n-day vulnerabilities with automated CVSS vector prediction at disclosure[C]//Proceedings of the 15th International Conference on Availability, Reliability and Security. 2020:1-10.
[13] A. Khazaei, M. Ghasemzadeh, and V. Derhami. An automatic method for CVSS score prediction using vulnerabilities description[J]. Journal of Intelligent & Fuzzy Systems, 2016, 30(1):89-96.
[14] Su J, Wu Y. Refining CVE-to-CWE mapping with enhanced attention in BERT-based models[J]. Applied and Computational Engineering, 2024, 71:107-112.
[15] Devlin J, Chang M W, Lee K, et al. BERT: Pre-training of deep bidirectional transformers for language understanding[C]//NAACL. 2019:4171-4186.
[16] Vasireddy D T, Dale D S, Li Q. CVSS base score prediction using an optimized machine learning scheme[C]//Resilience Week. 2023:1-6.
[17] Walkowski M, Krakowiak M, Jaroszewski M, et al. Automatic CVSS-based vulnerability prioritization and response with context information[C]//SoftCOM. 2021:1-6.
[18] Huang F, Liu Z, Zhou J, et al. Vulnerability analysis of high-performance transmission and bearer network of 5G smart grid based on complex network[C]//ICICN. 2021:1-5.
[19] 温敏初, 梁炜, 张嘉麟. 面向TDMA无线传感器网络的攻击构造与入侵检测方法研究[J]. 计算机工程, 2025, 51(8):203-214.
WEN Minchu, LIANG Wei, ZHANG Jialin. Research on attack construction and intrusion detection methods for TDMA wireless sensor networks[J]. Computer Engineering, 2025, 51(8):203-214.
[20] Kai S, Zheng J, Shi F, et al. A CVSS-based vulnerability assessment method for reducing scoring error[C]//CECIT. 2021:1-5.
[21] Liu Y, Ott M, Goyal N, et al. RoBERTa: A robustly optimized BERT pretraining approach[C]//ICLR. 2020.
[22] Radford A, Kim J W, Hallacy C, et al. Learning transferable visual models from natural language supervision[C]//ICML. 2021:8748-8763.
[23] Reimers N, Gurevych I. Sentence-BERT: Sentence embeddings using Siamese BERT-networks[C]//EMNLP. 2019:3982-3992.
[24] 郑雅洲, 刘万平, 黄东. 一种基于注意力机制的BERT-CNN-GRU检测方法[J]. 计算机工程, 2025, 51(1):258-268.
ZHENG Yazhou, LIU Wanping, HUANG Dong. A BERT-CNN-GRU detection method based on attention mechanism[J]. Computer Engineering, 2025, 51(1):258-268.
[25] Gururangan S, Marasović A, Swayamdipta S, et al. Don't stop pretraining: Adapt language models to domains and tasks[C]//ACL. 2020:8342-8360.
[26] Manjunatha M A, Kota K, Babu A S, et al. CVE severity prediction from vulnerability description: A deep learning approach[J]. Procedia Computer Science, 2024, 235:3105-3117.
[27] Trinh L C, Kien V T, Hoang T M, et al. A multimodal deep learning approach for efficient vulnerability detection in smart contracts[C]//GLOBECOM. 2023:3421-3426.
[28] Nowak M R, Walkowski M, Sujecki S. Support for the vulnerability management process using conversion CVSS base score 2.0 to 3.x[J]. Sensors, 2023, 23(4):1802.
[29] 王煜焜, 徐行健, 孟繁军, 等. 基于多特征注意力双向循环神经网络的客观题难度预测模型[J]. 计算机工程, 2025, 51(10):130-139.
WANG Yukun, XU Xingjian, MENG Fanjun, et al. Objective question difficulty prediction model based on multi-feature attention bidirectional recurrent neural network[J]. Computer Engineering, 2025, 51(10):130-139.
[30] Coutinho L S, Menasché D S, Fiore M, et al. How context impacts vulnerability severity: An analysis of product-specific CVSS scores[C]//LADC. 2024.
[31] Sarker I H, Salah T, Kayes A S M. Explainable AI for cybersecurity automation, intelligence and decision support systems[J]. Intelligent Systems with Applications, 2024, 20:200362.
[32] Levshun D, Mamedov E, Shestakov A. Exploring BERT for predicting vulnerability categories in device configurations[C]//ICISSP. 2024:451-460.
[33] Zhang H, Wang Q, Liu X. A lightweight transformer-based multi-task learning model with dynamic weight allocation for improved vulnerability prediction[J]. Scientific Reports, 2025.
[34] Bonhomme C, Dulaunoy A. VLAI: A RoBERTa-based model for automated vulnerability severity classification[EB/OL]. arXiv:2507.03607, 2025.
[35] Du X, Zhang Y, Li Z. A vulnerability severity prediction method based on bimodal data and multi-task learning[J]. Journal of Systems and Software, 2024.
[36] Chen T, Guestrin C. XGBoost: A scalable tree boosting system[C]//KDD. 2016:785-794.
|