Boosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model Performance @FIRSTdotorg
Boosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model Performance  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 46 minutes ago
David Starobinski (Boston University, US), Sevval Simsek (Boston University, US), Varsha Athreya (Boston University, US)

Accurate mapping between Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) entries is critical for effective vulnerability management and risk assessment. However, public databases, such as the National Vulnerability Database (NVD), suffer from inconsistent and incomplete CVE–CWE mappings, complicating automated analysis and remediation. We introduce FixV2W, a lightweight approach that leverages knowledge graph embeddings and longitudinal trends to improve mapping accuracy of the NVD. FixV2W systematically analyzes historical remapping patterns and leverages hierarchical relationships within NVD and CWE data to predict more precise CWE mappings for vulnerabilities linked to Prohibited or Discouraged categories. We run extensive experimental evaluation of FixV2W, based on test data set collected between August 2021 and December 2024. Considering the Top-10 ranked predictions, the results show that FixV2W predicts the correct CWE mappings for 69% of exploited vulnerabilities that had invalid CWEs before they were exploited. We also show that FixV2W significantly improves the performance of ML models relying on NVD data. For instance, for a model geared at uncovering unknown CVE-CWE mappings, FixV2W improves the Mean Reciprocal Rank (MRR) from 0.174 to 0.608. These results show that FixV2W is a promising approach to identify and thwart emerging threats.

---

Prof. David Starobinski is a Professor of Electrical and Computer Engineering and of Systems Engineering at Boston University, with an affiliated appointment in the Department of Computer Science. His research interests are in cybersecurity, wireless networking, blockchain and cryptocurrency, and network economics.

Sevval Simsek is a Computer Engineering PhD candidate at Boston University. She is a part of Networking and Information Systems Lab, and has been focusing on ML for Cybersecurity, and improving cybersecurity operations with graphs and algorithms.

Varsha Athreya is an undergraduate student studying Computer Engineering with a Concentration in Machine Learning. She is working on using knowledge graphs to fix mappings in the National Vulnerability Database as well as using the New England Research Cloud for model training and deployment.
Boosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in AzureImproving Security Across Nations with FIRST: Derek Manky, FIRST CORE Founding PartnerCVE/FIRST VulnCon 2026 & Annual CNA Summit Recap VideoFighting Back Without Hacking Back: Why “Risk Management” Isn’t Enough In The Era of Cyber WarThreat From The Inside: Investigate eBPF MalwareThree Musketeers: CVE, CSAF, and VEXMaximizing the Potential of AWS-WAFHack Your Boards Mindset: Closing the Strategy-Operations Gap via Board Game Simulations
FIRST |

Boosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model Performance

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER