{"slug": "mapping-cves-to-mitre-att-ck-techniques", "title": "Mapping CVEs to Mitre ATT&CK Techniques", "summary": "Researchers trained a multi-label classifier on a curated gold dataset of 1,207 CVEs from expert MITRE Center for Threat-Informed Defense mappings, achieving recall@5 of 0.673 ± 0.019 for mapping CVEs to MITRE ATT&CK techniques. LLM-assisted label expansion with approximately 0.39 agreement with expert annotations provided no reliable improvement and reduced rare-technique coverage, with macro-F1 decreasing by 0.04 at around 1,000 added CVEs. The study concludes that the classifier is limited by label quality rather than dataset size, and all datasets, models, code, and training logs are publicly released.", "body_md": "# Computer Science > Cryptography and Security\n\n[Submitted on 28 Jul 2026]\n\n# Title:Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion\n\n[View PDF](/pdf/2607.25572)\n\n[HTML (experimental)](https://arxiv.org/html/2607.25572v1)\n\nAbstract:We present a reproducible pipeline for mapping Common Vulnerabilities and Exposures (CVEs) to MITRE ATT&CK Enterprise techniques from free-text vulnerability descriptions. Rather than relying on the CWE->CAPEC->ATT&CK derivation chain, whose table-expansion artifacts we quantify, we train a multi-label classifier on a curated gold dataset of 1,207 CVEs from expert MITRE Center for Threat-Informed Defense mappings. The resulting model approximately doubles recall@5 compared with a zero-shot embedding-similarity baseline and improves every ranking metric. We then investigate whether LLM-assisted labeling can extend the gold dataset. Initial experiments suggest contradictory conclusions: a single run indicates degraded performance, while averaging over five random seeds suggests a small gain. However, an independent replication and an expansion-size study (100--984 additional CVEs) show that the apparent improvement is an evaluation artifact. LLM-generated labels, with approximately 0.39 agreement with expert annotations, provide no reliable improvement at any expansion size and reduce rare-technique coverage at around 1,000 added CVEs (macro-F1 decreases by 0.04). The root cause is evaluation noise. Selecting checkpoints on a small test split effectively maximizes over many noisy evaluations, producing recall@5 differences of up to 0.05 between otherwise identical runs. Using a corrected protocol based on validation-split checkpoint selection, the gold-only model achieves recall@5 of (0.673 \\pm 0.019), and repeating the decisive experiment confirms the null result for LLM expansion. A final scaling study shows that additional expert-curated data consistently improves performance, whereas LLM-labeled data does not, indicating that the classifier is limited by label quality rather than dataset size. All datasets, models, code, and training logs are publicly released.\n\n## Submission history\n\nFrom: Alexandre Dulaunoy [[view email](/show-email/200a3750/2607.25572)]\n\n**[v1]** Tue, 28 Jul 2026 10:59:04 UTC (443 KB)\n\n### References & Citations\n\nLoading...\n\n# Bibliographic and Citation Tools\n\nBibliographic Explorer\n\n*(*[What is the Explorer?](https://info.arxiv.org/labs/showcase.html#arxiv-bibliographic-explorer))\nConnected Papers\n\n*(*[What is Connected Papers?](https://www.connectedpapers.com/about))\nLitmaps\n\n*(*[What is Litmaps?](https://www.litmaps.co/))\nscite Smart Citations\n\n*(*[What are Smart Citations?](https://www.scite.ai/))# Code, Data and Media Associated with this Article\n\nalphaXiv\n\n*(*[What is alphaXiv?](https://alphaxiv.org/))\nCatalyzeX Code Finder for Papers\n\n*(*[What is CatalyzeX?](https://www.catalyzex.com))\nDagsHub\n\n*(*[What is DagsHub?](https://dagshub.com/))\nGotit.pub\n\n*(*[What is GotitPub?](http://gotit.pub/faq))\nHugging Face\n\n*(*[What is Huggingface?](https://huggingface.co/huggingface))\nScienceCast\n\n*(*[What is ScienceCast?](https://sciencecast.org/welcome))# Demos\n\n# Recommenders and Search Tools\n\nInfluence Flower\n\n*(*[What are Influence Flowers?](https://influencemap.cmlab.dev/))\nCORE Recommender\n\n*(*[What is CORE?](https://core.ac.uk/services/recommender))# arXivLabs: experimental projects with community collaborators\n\narXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.\n\nBoth individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.\n\nHave an idea for a project that will add value for arXiv's community? [ Learn more about arXivLabs](https://info.arxiv.org/labs/index.html).", "url": "https://wpnews.pro/news/mapping-cves-to-mitre-att-ck-techniques", "canonical_source": "https://arxiv.org/abs/2607.25572", "published_at": "2026-07-29 05:53:36+00:00", "updated_at": "2026-07-29 06:22:25.683182+00:00", "lang": "en", "topics": ["machine-learning", "natural-language-processing", "ai-research"], "entities": ["MITRE Center for Threat-Informed Defense", "MITRE ATT&CK", "CVE", "Alexandre Dulaunoy"], "alternates": {"html": "https://wpnews.pro/news/mapping-cves-to-mitre-att-ck-techniques", "markdown": "https://wpnews.pro/news/mapping-cves-to-mitre-att-ck-techniques.md", "text": "https://wpnews.pro/news/mapping-cves-to-mitre-att-ck-techniques.txt", "jsonld": "https://wpnews.pro/news/mapping-cves-to-mitre-att-ck-techniques.jsonld"}}