{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:02:19Z","timestamp":1780588939049,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785376","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1339-1355","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Knowing your weaknesses is your greatest strength: Mapping CVE to CWE by leveraging CWE Hierarchy and fine-tuned LLMs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9778-4019","authenticated-orcid":false,"given":"Stefano","family":"Simonetto","sequence":"first","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-4822-5142","authenticated-orcid":false,"given":"Ronan","family":"Oostveen","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3865-6390","authenticated-orcid":false,"given":"Thijs","family":"van Ede","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4434-5775","authenticated-orcid":false,"given":"Peter","family":"Bosch","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7028-2967","authenticated-orcid":false,"given":"Willem","family":"Jonker","sequence":"additional","affiliation":[{"name":"University of Twente, Enschede, Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"International Conference on Security and Privacy in Communication Systems. Springer, 39\u201356","author":"Aghaei Ehsan","year":"2022","unstructured":"Ehsan Aghaei, Xi Niu, Waseem Shadid, and Ehab Al-Shaer. 2022. Securebert: A domain-specific language model for cybersecurity. In International Conference on Security and Privacy in Communication Systems. Springer, 39\u201356."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63086-7_2"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01533"},{"key":"e_1_3_2_1_4_1","unstructured":"Massimiliano Albanese Olutola Adebiyi and Frank Onovae. [n. d.]. CVE2CWE: Automated Mapping of Software Vulnerabilities to Weaknesses Based on CVE Descriptions. ([n.d.])."},{"key":"e_1_3_2_1_5_1","unstructured":"Anonymous. 2024. Mapping CVE to CWE by leveraging CWE Hierarchy with LLMs. Accessed on November 13 2024 from https:\/\/anonymous.4open.science\/r\/2-layer-nn-C257\/README.md."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC50000.2020.9219568"},{"key":"e_1_3_2_1_7_1","volume-title":"Yingyan Celine Lin, and Pavlo Molchanov","author":"Belcak Peter","year":"2025","unstructured":"Peter Belcak, Greg Heinrich, Shizhe Diao, Yonggan Fu, Xin Dong, Saurav Muralidharan, Yingyan Celine Lin, and Pavlo Molchanov. 2025. Small Language Models are the Future of Agentic AI. arXiv preprint arXiv:2506.02153 (2025)."},{"key":"e_1_3_2_1_8_1","volume-title":"SMOTE for high-dimensional class-imbalanced data. BMC bioinformatics 14","author":"Blagus Rok","year":"2013","unstructured":"Rok Blagus and Lara Lusa. 2013. SMOTE for high-dimensional class-imbalanced data. BMC bioinformatics 14 (2013), 1\u201316."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1613\/jair.953"},{"key":"e_1_3_2_1_10_1","unstructured":"Common Vulnerabilities and Exposures. 2024. Common Vulnerabilities and Exposures. https:\/\/www.cve.org\/"},{"key":"e_1_3_2_1_11_1","volume-title":"Evaluating Zero-Shot Chatgpt Performance on Predicting CVE Data From Vulnerability Descriptions. In European Conference on Cyber Warfare and Security","volume":"23","author":"Costin Andrei","year":"2024","unstructured":"Andrei Costin, Hannu Turtiainen, Narges Yousefnezhad, Vadim Bogulean, and Timo H\u00e4m\u00e4l\u00e4inen. 2024. Evaluating Zero-Shot Chatgpt Performance on Predicting CVE Data From Vulnerability Descriptions. In European Conference on Cyber Warfare and Security, Vol. 23. 576\u2013584."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"e_1_3_2_1_14_1","volume-title":"Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)."},{"key":"e_1_3_2_1_15_1","volume-title":"Gemini: A Family of Highly Capable Multimodal Models. arXiv:2312.11805 [cs.CL] https:\/\/arxiv.org\/abs\/2312.11805","author":"Gemini Team","year":"2024","unstructured":"Gemini Team et al. 2024. Gemini: A Family of Highly Capable Multimodal Models. arXiv:2312.11805 [cs.CL] https:\/\/arxiv.org\/abs\/2312.11805"},{"key":"e_1_3_2_1_16_1","unstructured":"Hugo Touvron et al. 2023. Llama 2: Open Foundation and Fine-Tuned Chat Models. arXiv:2307.09288 [cs.CL]"},{"key":"e_1_3_2_1_17_1","unstructured":"Ian J. Goodfellow Jean Pouget-Abadie Mehdi Mirza Bing Xu David Warde-Farley Sherjil Ozair Aaron Courville and Yoshua Bengio. 2014. Generative Adversarial Networks. arXiv:1406.2661 [stat.ML] https:\/\/arxiv.org\/abs\/1406.2661"},{"key":"e_1_3_2_1_18_1","volume-title":"Allie Del Giorno, Sivakanth Gopi, Mojan Javaheripi, Piero Kauffmann, Gustavo de Rosa, Olli Saarikivi, et al.","author":"Gunasekar Suriya","year":"2023","unstructured":"Suriya Gunasekar, Yi Zhang, Jyoti Aneja, Caio C\u00e9sar Teodoro Mendes, Allie Del Giorno, Sivakanth Gopi, Mojan Javaheripi, Piero Kauffmann, Gustavo de Rosa, Olli Saarikivi, et al. 2023. Textbooks are all you need. arXiv preprint arXiv:2306.11644 (2023)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.aiopen.2021.08.002"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330232"},{"key":"e_1_3_2_1_21_1","volume-title":"Lora: Low-rank adaptation of large language models. arXiv preprint arXiv:2106.09685","author":"Hu Edward J","year":"2021","unstructured":"Edward J Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2021. Lora: Low-rank adaptation of large language models. arXiv preprint arXiv:2106.09685 (2021)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3571730"},{"key":"e_1_3_2_1_23_1","unstructured":"Albert Q. Jiang Alexandre Sablayrolles Arthur Mensch Chris Bamford Devendra Singh Chaplot Diego de las Casas Florian Bressand Gianna Lengyel Guillaume Lample Lucile Saulnier L\u00e9lio Renard Lavaud Marie-Anne Lachaux Pierre Stock Teven Le Scao Thibaut Lavril Thomas Wang Timoth\u00e9e Lacroix and William El Sayed. 2023. Mistral 7B. arXiv:2310.06825 [cs.CL] https:\/\/arxiv.org\/abs\/2310.06825"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2024.04.111"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.229"},{"key":"e_1_3_2_1_26_1","volume-title":"Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692","author":"Liu Yinhan","year":"2019","unstructured":"Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692 (2019)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.546"},{"key":"e_1_3_2_1_28_1","unstructured":"Microsoft Research Blog. [n. d.]. Phi-2: The Surprising Power of Small Language Models. https:\/\/www.microsoft.com\/en-us\/research\/blog\/phi-2-the-surprising-power-of-small-language-models\/. Accessed:21\u20133-2024."},{"key":"e_1_3_2_1_29_1","volume-title":"National Vulnerability Database","author":"National Institute of Standards and Technology. [n.d.].","unstructured":"National Institute of Standards and Technology. [n.d.]. National Vulnerability Database. National Institute of Standards and Technology. https:\/\/nvd.nist.gov\/"},{"key":"e_1_3_2_1_30_1","unstructured":"National Vulnerability Database (NVD). 2024. NVD Data Feeds. https:\/\/nvd.nist.gov\/vuln\/data-feeds"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"crossref","unstructured":"Long Ouyang Jeffrey Wu Xu Jiang Diogo Almeida Carroll Wainwright Pamela Mishkin Chong Zhang Sandhini Agarwal Katarina Slama Alex Ray et al. 2022. Training language models to follow instructions with human feedback. Advances in neural information processing systems 35 (2022) 27730\u201327744.","DOI":"10.52202\/068431-2011"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2023.08.176"},{"key":"e_1_3_2_1_33_1","volume-title":"2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 957\u2013969","author":"Pan Shengyi","year":"2023","unstructured":"Shengyi Pan, Lingfeng Bao, Xin Xia, David Lo, and Shanping Li. 2023. Finegrained commit-level vulnerability type prediction by CWE tree structure. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 957\u2013969."},{"key":"e_1_3_2_1_34_1","volume-title":"Antonio De Domenico, and Fadhel Ayed","author":"Piovesan Nicola","year":"2024","unstructured":"Nicola Piovesan, Antonio De Domenico, and Fadhel Ayed. 2024. Telecom Language Models: Must They Be Large? arXiv preprint arXiv:2403.04666 (2024)."},{"key":"e_1_3_2_1_35_1","unstructured":"Alec Radford Karthik Narasimhan Tim Salimans Ilya Sutskever et al. 2018. Improving language understanding by generative pre-training. (2018)."},{"key":"e_1_3_2_1_36_1","first-page":"238","article-title":"Software design level vulnerability classification model","volume":"6","author":"Rehman Shabana","year":"2012","unstructured":"Shabana Rehman and Khurram Mustafa. 2012. Software design level vulnerability classification model. International Journal of Computer Science and Security (IJCSS) 6, 4 (2012), 238.","journal-title":"International Journal of Computer Science and Security (IJCSS)"},{"key":"e_1_3_2_1_37_1","volume-title":"8th IEEE European Symposium on Security and Privacy.","author":"Simonetto Stefano","year":"2023","unstructured":"Stefano Simonetto and Peter Bosch. 2023. Are we reasoning about cloud application vulnerabilities in the right way?. In 8th IEEE European Symposium on Security and Privacy."},{"key":"e_1_3_2_1_38_1","volume-title":"4th Workshop on Artificial Intelligence-Enabled Cybersecurity Analytics.","author":"Simonetto Stefano","year":"2024","unstructured":"Stefano Simonetto, Thijs Sebastiaan van Ede, Peter Bosch, and Willem Jonker. 2024. Text2Weak: mapping CVEs to CWEs using description embeddings analysis. In 4th Workshop on Artificial Intelligence-Enabled Cybersecurity Analytics."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Heydar Soudani Evangelos Kanoulas and Faegheh Hasibi. 2024. Fine Tuning vs. Retrieval Augmented Generation for Less Popular Knowledge. arXiv preprint arXiv:2403.01432(2024).","DOI":"10.1145\/3673791.3698415"},{"key":"e_1_3_2_1_40_1","unstructured":"The MITRE Corporation. [n. d.]. Common Weakness Enumeration (CWE). https:\/\/cwe.mitre.org\/. Accessed on December 15 2025."},{"key":"e_1_3_2_1_41_1","volume-title":"Attention is all you need. Advances in neural information processing systems 30","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. Advances in neural information processing systems 30 (2017)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103070"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/IRI.2018.00041"}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785376","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:25:02Z","timestamp":1780586702000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785376"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":43,"alternative-id":["10.1145\/3779208.3785376","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785376","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}