{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T07:55:48Z","timestamp":1776930948698,"version":"3.51.2"},"publisher-location":"New York, NY, USA","reference-count":53,"publisher":"ACM","funder":[{"name":"Nederlandse Organisatie voor Wetenschappelijk Onderzoek (NWO)","award":["NWA.1215.18.006"],"award-info":[{"award-number":["NWA.1215.18.006"]}]},{"name":"European Union (EU) under Horizon Europe","award":["101120393"],"award-info":[{"award-number":["101120393"]}]},{"name":"Nederlandse Organisatie voor Wetenschappelijk Onderzoek (NWO)","award":["KIC1.VE01.20.004"],"award-info":[{"award-number":["KIC1.VE01.20.004"]}]},{"name":"Dutch Sector Plan"},{"name":"The Natural Sciences and Engineering Research Council of Canada (NSERC) Discovery Grant","award":["RGPIN-2020-04734"],"award-info":[{"award-number":["RGPIN-2020-04734"]}]},{"name":"The Natural Sciences and Engineering Research Council of Canada (NSERC) NSERC Alliance Grant","award":["ALLRP 558365-20"],"award-info":[{"award-number":["ALLRP 558365-20"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3772318.3790409","type":"proceedings-article","created":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T04:12:36Z","timestamp":1776053556000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Tool-Assisted CVSS Vulnerability Scoring: A Controlled Quantitative Study of Human Assessment"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-4490-8671","authenticated-orcid":false,"given":"Siqi","family":"Zhang","sequence":"first","affiliation":[{"name":"Department of Computer Science, Vrije Universiteit Amsterdam, Amsterdam, NH, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-3452-7292","authenticated-orcid":false,"given":"Minjie","family":"Cai","sequence":"additional","affiliation":[{"name":"School of Computer Science, Carleton University, Ottawa, Ontario, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6376-4062","authenticated-orcid":false,"given":"Lianying","family":"Zhao","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, Ontario, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2664-3963","authenticated-orcid":false,"given":"Xavier","family":"de Carn\u00e9 de Carnavalet","sequence":"additional","affiliation":[{"name":"Digital Security group, Radboud University, Nijmegen, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1091-8486","authenticated-orcid":false,"given":"Fabio","family":"Massacci","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Vrije Universiteit Amsterdam, Amsterdam, NH, Netherlands and DISI, University of Trento, Trento, TN, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7457-5198","authenticated-orcid":false,"given":"Mengyuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Vrije Universiteit Amsterdam, Amsterdam, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,4,13]]},"reference":[{"key":"e_1_3_3_3_2_2","unstructured":"S. Alex. 2024. More data stolen in 2023 MOVEit attacks comes to light. https:\/\/www.computerweekly.com\/news\/366615522\/More-data-stolen-in-2023-MOVEit-attacks-comes-to-light."},{"key":"e_1_3_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468920.3468942"},{"key":"e_1_3_3_3_4_2","doi-asserted-by":"crossref","unstructured":"Luca Allodi Marco Cremonini Fabio Massacci and Woohyun Shim. 2020. Measuring the accuracy of software vulnerability assessments: experiments with students and professionals. Empir. Softw. Eng. 25 2 (2020) 1063\u20131094.","DOI":"10.1007\/s10664-019-09797-4"},{"key":"e_1_3_3_3_5_2","doi-asserted-by":"crossref","unstructured":"Luca Allodi Marco Cremonini Fabio Massacci and Woohyun Shim. 2020. Measuring the accuracy of software vulnerability assessments: experiments with students and professionals. Empir. Softw. Eng. 25 2 (2020) 1063\u20131094.","DOI":"10.1007\/s10664-019-09797-4"},{"key":"e_1_3_3_3_6_2","unstructured":"SPSS Analysis. 2025. Cronbach\u2019s Alpha using SPSS. https:\/\/spssanalysis.com\/cronbachs-alpha-in-spss\/."},{"key":"e_1_3_3_3_7_2","doi-asserted-by":"crossref","unstructured":"Richard\u00a0A. Armstrong. 2014. When to use the Bonferroni correction. Ophthalmic & Physiological Optics 34 5 (2014) 502\u2013508.","DOI":"10.1111\/opo.12131"},{"key":"e_1_3_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467159"},{"key":"e_1_3_3_3_9_2","unstructured":"Robert\u00a0A. Bridges Corinne\u00a0L. Jones Michael\u00a0D. Iannacone and John\u00a0R. Goodall. 2013. Automatic Labeling for Entity Extraction in Cyber Security. CoRR abs\/1308.4941 (2013) 1\u201313."},{"key":"e_1_3_3_3_10_2","unstructured":"CBC News. 2014. CSEC knew about Heartbleed bug day before CRA website shutdown. https:\/\/www.cbc.ca\/news\/politics\/csec-aware-of-heartbleed-bug-day-before-cra-website-shutdown-1.2613058."},{"key":"e_1_3_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3558920"},{"key":"e_1_3_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2014.254"},{"key":"e_1_3_3_3_13_2","unstructured":"MITRE Corporation. 2025. Metrics. https:\/\/www.cve.org\/About\/Metrics."},{"key":"e_1_3_3_3_14_2","first-page":"278","volume-title":"Counterbalancing","author":"Corriero Elena\u00a0F.","year":"2017","unstructured":"Elena\u00a0F. Corriero. 2017. Counterbalancing. SAGE Publications, Inc, Thousand Oaks, California, 278\u2013281."},{"key":"e_1_3_3_3_15_2","doi-asserted-by":"crossref","unstructured":"Joana\u00a0Cabral Costa Tiago Roxo Jo\u00e3o B.\u00a0F. Sequeiros Hugo Proen\u00e7a and Pedro R.\u00a0M. In\u00e1cio. 2022. Predicting CVSS Metric via Description Interpretation. IEEE Access 10 (2022) 59125\u201359134.","DOI":"10.1109\/ACCESS.2022.3179692"},{"key":"e_1_3_3_3_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380387"},{"key":"e_1_3_3_3_17_2","first-page":"869","volume-title":"Proceedings of the USENIX Security Symposium","author":"Dong Ying","year":"2019","unstructured":"Ying Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing, Yuqing Zhang, and Gang Wang. 2019. Towards the Detection of Inconsistencies in Public Security Vulnerability Reports. In Proceedings of the USENIX Security Symposium. USENIX Association, Santa Clara, CA, USA, 869\u2013885."},{"key":"e_1_3_3_3_18_2","doi-asserted-by":"crossref","unstructured":"Brett\u00a0D. Douglas Peter\u00a0J. Ewell and Markus Brauer. 2023. Data quality in online human-subjects research: Comparisons between MTurk Prolific CloudResearch Qualtrics and SONA. PLOS ONE 18 3 (2023) e0279720.","DOI":"10.1371\/journal.pone.0279720"},{"key":"e_1_3_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/2858036.2858214"},{"key":"e_1_3_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407038"},{"key":"e_1_3_3_3_21_2","unstructured":"Electronic Privacy Information Center. 2021. Equifax Data Breach. https:\/\/archive.epic.org\/privacy\/data-breach\/equifax\/. Accessed: 2026-01-15."},{"key":"e_1_3_3_3_22_2","unstructured":"FIRST. 2019. Common Vulnerability Scoring System v3.1: Specification Document. https:\/\/www.first.org\/cvss\/v3-1\/specification-document#Qualitative-Severity-Rating-Scale."},{"key":"e_1_3_3_3_23_2","unstructured":"FIRST. 2025. CVSS Special Interest Group Meetings. https:\/\/www.first.org\/cvss\/v2\/meetings."},{"key":"e_1_3_3_3_24_2","unstructured":"FIRST. 2025. FIRST Website. https:\/\/www.first.org\/cvss\/."},{"key":"e_1_3_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i28.35139"},{"key":"e_1_3_3_3_26_2","doi-asserted-by":"crossref","unstructured":"Hannes Holm and Khalid\u00a0Khan Afridi. 2015. An expert-based investigation of the Common Vulnerability Scoring System. Comput. Secur. 53 (2015) 18\u201330.","DOI":"10.1016\/j.cose.2015.04.012"},{"key":"e_1_3_3_3_27_2","doi-asserted-by":"crossref","unstructured":"Jay Jacobs Sasha Romanosky Benjamin Edwards Idris Adjerid and Michael Roytman. 2021. Exploit Prediction Scoring System (EPSS). Digital Threats 2 3 Article 20 (July 2021) 17\u00a0pages.","DOI":"10.1145\/3436242"},{"key":"e_1_3_3_3_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/CECIT53797.2021.00013"},{"key":"e_1_3_3_3_29_2","first-page":"393","volume-title":"Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI\u201918)","author":"Kleek Max\u00a0Van","year":"2018","unstructured":"Max\u00a0Van Kleek, Reuben Binns, Jun Zhao, Adam Slack, Sauyon Lee, Dean Ottewell, and Nigel Shadbolt. 2018. X-Ray Refine: Supporting the Exploration and Refinement of Information Exposure Resulting from Smartphone Apps. In Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI\u201918). ACM, Montreal, QC, Canada, 393."},{"key":"e_1_3_3_3_30_2","first-page":"5208","volume-title":"Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI\u201917)","author":"Kleek Max\u00a0Van","year":"2017","unstructured":"Max\u00a0Van Kleek, Ilaria Liccardi, Reuben Binns, Jun Zhao, Daniel\u00a0J. Weitzner, and Nigel Shadbolt. 2017. Better the Devil You Know: Exposing the Data Sharing Practices of Smartphone Apps. In Proceedings of the CHI Conference on Human Factors in Computing Systems (CHI\u201917). ACM, Denver, CO, USA, 5208\u20135220."},{"key":"e_1_3_3_3_31_2","first-page":"1","volume-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","author":"Lee Robert\u00a0M.","year":"2016","unstructured":"Robert\u00a0M. Lee, Michael\u00a0J. Assante, and Tim Conway. 2016. Analysis of the Cyber Attack on the Ukrainian Power Grid. Technical Report 388-3. Electricity Information Sharing and Analysis Center (E-ISAC). 1\u201329 pages."},{"key":"e_1_3_3_3_32_2","doi-asserted-by":"crossref","unstructured":"Fabio Massacci Aurora Papotti and Ranindya Paramitha. 2024. Addressing combinatorial experiments and scarcity of subjects by provably orthogonal and crossover experimental designs. J. Syst. Softw. 211 (2024) 111990.","DOI":"10.1016\/j.jss.2024.111990"},{"key":"e_1_3_3_3_33_2","doi-asserted-by":"crossref","unstructured":"Andrew\u00a0D. McGettrick. 2013. Toward Effective Cybersecurity Education. IEEE Secur. Priv. 11 6 (2013) 66\u201368.","DOI":"10.1109\/MSP.2013.155"},{"key":"e_1_3_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-032-00627-1_17"},{"key":"e_1_3_3_3_35_2","unstructured":"Microsoft. 2025. What is vulnerability management?https:\/\/www.microsoft.com\/en-us\/security\/business\/security-101\/what-is-vulnerability-management."},{"key":"e_1_3_3_3_36_2","doi-asserted-by":"crossref","unstructured":"Geoff Norman. 2010. Likert scales levels of measurement and the \u201claws\u201d of statistics. Advances in Health Sciences Education 15 5 (2010) 625\u2013632.","DOI":"10.1007\/s10459-010-9222-y"},{"key":"e_1_3_3_3_37_2","doi-asserted-by":"crossref","unstructured":"Rocco Perla and James Carifio. 2008. Resolving the 50-year debate around using and misusing Likert scales. Medical Education 42 12 (2008) 1150\u20131152.","DOI":"10.1111\/j.1365-2923.2008.03172.x"},{"key":"e_1_3_3_3_38_2","doi-asserted-by":"crossref","unstructured":"Jorge Reyes Walter Fuertes Paco Ar\u00e9valo and Mayra Macas. 2022. An Environment-Specific Prioritization Model for Information-Security Vulnerabilities Based on Risk Factor Analysis. Electronics 11 9 (2022) 1334.","DOI":"10.3390\/electronics11091334"},{"key":"e_1_3_3_3_39_2","first-page":"2887","volume-title":"Proceedings of the USENIX Security Symposium","author":"Schloegel Moritz","year":"2025","unstructured":"Moritz Schloegel, Daniel Klischies, Simon Koch, David Klein, Lukas Gerlach, Malte Wessels, Leon Trampert, Martin Johns, Mathy Vanhoef, Michael Schwarz, Thorsten Holz, and Jo\u00a0Van Bulck. 2025. Confusing Value with Enumeration: Studying the Use of CVEs in Academia. In Proceedings of the USENIX Security Symposium. USENIX Association, Seattle, WA, USA, 2887\u20132906."},{"key":"e_1_3_3_3_40_2","unstructured":"SecurityScorecard. 2025. CVE Details. https:\/\/www.cvedetails.com\/browse-by-date.php."},{"key":"e_1_3_3_3_41_2","unstructured":"Sonit Singh. 2018. Natural Language Processing for Information Extraction. CoRR abs\/1807.02383 (2018) 1\u201324."},{"key":"e_1_3_3_3_42_2","doi-asserted-by":"crossref","unstructured":"Kelsey Stanton Ryan\u00a0W. Carpenter Michaela Nance Tyler Sturgeon and Maria Villalongo\u00a0Andino. 2022. A multisample demonstration of using the Prolific platform for repeated assessment and psychometric substance use research. Experimental and Clinical Psychopharmacology 30 4 (2022) 432\u2013443.","DOI":"10.1037\/pha0000545"},{"key":"e_1_3_3_3_43_2","first-page":"1","volume-title":"Proceedings of the USENIX Workshop on Cyber Security Experimentation and Test (CSET\u201917)","author":"Stransky Christian","year":"2017","unstructured":"Christian Stransky, Yasemin Acar, Duc\u00a0Cuong Nguyen, Dominik Wermke, Doowon Kim, Elissa\u00a0M. Redmiles, Michael Backes, Simson\u00a0L. Garfinkel, Michelle\u00a0L. Mazurek, and Sascha Fahl. 2017. Lessons Learned from Using an Online Platform to Conduct Large-Scale, Online Controlled Security Experiments with Software Developers. In Proceedings of the USENIX Workshop on Cyber Security Experimentation and Test (CSET\u201917). USENIX Association, Vancouver, BC, Canada, 1\u20138."},{"key":"e_1_3_3_3_44_2","first-page":"367","volume-title":"Proceedings of the Symposium on Usable Privacy and Security (SOUPS\u201922)","author":"Tang Jenny","year":"2022","unstructured":"Jenny Tang, Eleanor Birrell, and Ada Lerner. 2022. Replication: How Well Do My Results Generalize Now? The External Validity of Online Privacy and Security Surveys. In Proceedings of the Symposium on Usable Privacy and Security (SOUPS\u201922). USENIX Association, Boston, MA, USA,, 367\u2013385."},{"key":"e_1_3_3_3_45_2","unstructured":"D. Verlaan. 2025. Tienduizenden verkeerslichten in Nederland te hacken lek nog jaren te misbruiken. https:\/\/www.rtl.nl\/nieuws\/artikel\/5473143\/verkeerslichten-hacken-tienduizenden-nederland-lek."},{"key":"e_1_3_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-naacl.239"},{"key":"e_1_3_3_3_47_2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"356","DOI":"10.1007\/978-3-319-17040-4_24","volume-title":"Proceedings of the International Symposium on Foundations and Practice of Security (FPS\u201914)","volume":"8930","author":"Weerawardhana Sachini\u00a0S.","year":"2014","unstructured":"Sachini\u00a0S. Weerawardhana, Subhojeet Mukherjee, Indrajit Ray, and Adele\u00a0E. Howe. 2014. Automated Extraction of Vulnerability Information for Home Computer Security. In Proceedings of the International Symposium on Foundations and Practice of Security (FPS\u201914)(Lecture Notes in Computer Science, Vol.\u00a08930). Springer, Montreal, QC, Canada, 356\u2013366."},{"key":"e_1_3_3_3_48_2","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1145\/2786805.2786816","volume-title":"Proceedings of the Joint Meeting on Foundations of Software Engineering (ESEC\/FSE\u201915)","author":"Witschey Jim","year":"2015","unstructured":"Jim Witschey, Olga\u00a0A. Zielinska, Allaire\u00a0K. Welk, Emerson\u00a0R. Murphy-Hill, Christopher\u00a0B. Mayhorn, and Thomas Zimmermann. 2015. Quantifying developers\u2019 adoption of security tools. In Proceedings of the Joint Meeting on Foundations of Software Engineering (ESEC\/FSE\u201915). ACM, Bergamo, Italy, 260\u2013271."},{"key":"e_1_3_3_3_49_2","doi-asserted-by":"crossref","unstructured":"Julia Wunder Alan Corona Andreas Hammer and Zinaida Benenson. 2024. On NVD Users\u2019 Attitudes Experiences Hopes and Hurdles. Digital Threats 5 3 Article 33 (Oct. 2024) 19\u00a0pages.","DOI":"10.1145\/3688806"},{"key":"e_1_3_3_3_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00058"},{"key":"e_1_3_3_3_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/BADGERS.2015.018"},{"key":"e_1_3_3_3_52_2","unstructured":"Junjie Ye Nuo Xu Yikun Wang Jie Zhou Qi Zhang Tao Gui and Xuanjing Huang. 2024. LLM-DA: Data Augmentation via Large Language Models for Few-Shot Named Entity Recognition. CoRR abs\/2402.14568 (2024) 1\u201314."},{"key":"e_1_3_3_3_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/CloudCom59040.2023.00039"},{"key":"e_1_3_3_3_54_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-37586-6_23"}],"event":{"name":"CHI 2026: CHI Conference on Human Factors in Computing Systems","location":"Barcelona Spain","acronym":"CHI '26","sponsor":["SIGCHI ACM Special Interest Group on Computer-Human Interaction"]},"container-title":["Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3772318.3790409","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,15]],"date-time":"2026-04-15T10:12:18Z","timestamp":1776247938000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3772318.3790409"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,13]]},"references-count":53,"alternative-id":["10.1145\/3772318.3790409","10.1145\/3772318"],"URL":"https:\/\/doi.org\/10.1145\/3772318.3790409","relation":{},"subject":[],"published":{"date-parts":[[2026,4,13]]},"assertion":[{"value":"2026-04-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}