HARP: Hierarchical Adaptive Ranking with Preference-Adaptive Fusion for Query-Based CVE Prioritization

📅 2026-08-19
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决漏洞优先级排序中的偏好依赖问题,提出HARP框架,通过历史标记案例和多视图融合自适应调整优先级,无需显式偏好描述。
📝 Abstract
Vulnerability prioritization is inherently preference dependent, since the same CVE can receive different remediation priority under different operational preference scenarios. Existing scoring systems and ranking methods typically assume a fixed criterion. In practice, organizations already operate under a preference scenario, but this preference is often implicit and difficult to express as a written prompt instruction, while triage queries usually do not encode it. Past validated triage cases under the current scenario are more readily available. We study query-based CVE prioritization in this setting and propose HARP, a graph-grounded multi-view framework that ranks candidates from a natural-language query together with a support bank of historical labeled examples from the current preference scenario, without requiring an explicit textual summary of that scenario. HARP retrieves evidence from a vulnerability knowledge graph, scores candidates with policy-conditioned global, enterprise, and user views, and fits view-fusion weights from sampled supports. Experiments across three preference scenarios and multiple backbone LLMs show that HARP outperforms multiple baselines, expressing our method's effectiveness.
Problem

Research questions and friction points this paper is trying to address.

vulnerability prioritization
preference dependent
operational preference scenarios
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hierarchical Adaptive Ranking
Preference-Adaptive Fusion
Query-Based CVE Prioritization
Vulnerability Knowledge Graph
🔎 Similar Papers
No similar papers found.