On Predicting Vulnerability Severity Using In-Context Learning: An Industrial Case Study

📅 2026-08-22
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文通过使用本地部署的开源LLM进行上下文学习,从易受攻击的C/C++代码片段中预测CVSS v3.1分数,以解决软件系统漏洞严重性评估问题。
📝 Abstract
Modern software systems require earlier and more scalable vulnerability severity assessment to reduce exposure to high-impact security flaws. Security analysts typically assign CVSS scores, but this manual triage does not scale with the growth of disclosed vulnerabilities and often depends on cloud LLM services that raise confidentiality concerns. This paper presents an industrial case study on predicting CVSS v3.1 scores directly from vulnerable C/C++ snippets using in-context learning with locally deployable, open-source LLMs. We compare proprietary data with the Big-Vul dataset, showing sufficiently aligned CVSS distributions to justify Big-Vul as a proxy for industrial data when constructing prompt-based testbeds. We then vary in-context configurations and model parameters, evaluating CodeLlama2-7B, CodeLlama2-13B, Mistral-7B, gpt-oss, and GPT4o-mini using mean squared error (MSE) and feasibility metrics. Our results show that medium-sized open-source code models, particularly CodeLlama2-7B, can approximate the best cloud performance for CVSS regression when guided by lightweight, output-constraining prompts, offering a practical, privacy-preserving building block for severity triage in industrial settings.
Problem

Research questions and friction points this paper is trying to address.

vulnerability severity
in-context learning
confidentiality concerns
CVSS scores
scalable assessment
Innovation

Methods, ideas, or system contributions that make the work stand out.

in-context learning
open-source LLMs
CVSS prediction
local deployment
privacy-preserving
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Daniel Rodriguez-Cardenas
Daniel Rodriguez-Cardenas
Universidad Nacional de Colombia
Software EngineeringMachine LearningCausal inferenceartificial life
D
David Nader Palacio
Microsoft
A
Anna Schmedding
William & Mary
Y
Yiyang Lu
William & Mary
A
Aadil Mallick
William & Mary
B
Bill Hudson
Cisco Systems
C
Chris Gourley
Cisco Systems
M
Michael Roytman
Cisco Systems
C
Chris Shenefiel
William & Mary
Evgenia Smirni
Evgenia Smirni
Professor of Computer Science, College of William and Mary
Performance EvaluationReliability
Denys Poshyvanyk
Denys Poshyvanyk
Chancellor Professor of Computer Science, William & Mary
software engineeringsoftware analyticssoftware evolutionsoftware maintenanceprogram