Uploaded May 2026 | Updated September 2026, 46 minutes ago
David Starobinski (Boston University, US), Sevval Simsek (Boston University, US), Varsha Athreya (Boston University, US)
Accurate mapping between Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) entries is critical for effective vulnerability management and risk assessment. However, public databases, such as the National Vulnerability Database (NVD), suffer from inconsistent and incomplete CVE–CWE mappings, complicating automated analysis and remediation. We introduce FixV2W, a lightweight approach that leverages knowledge graph embeddings and longitudinal trends to improve mapping accuracy of the NVD. FixV2W systematically analyzes historical remapping patterns and leverages hierarchical relationships within NVD and CWE data to predict more precise CWE mappings for vulnerabilities linked to Prohibited or Discouraged categories. We run extensive experimental evaluation of FixV2W, based on test data set collected between August 2021 and December 2024. Considering the Top-10 ranked predictions, the results show that FixV2W predicts the correct CWE mappings for 69% of exploited vulnerabilities that had invalid CWEs before they were exploited. We also show that FixV2W significantly improves the performance of ML models relying on NVD data. For instance, for a model geared at uncovering unknown CVE-CWE mappings, FixV2W improves the Mean Reciprocal Rank (MRR) from 0.174 to 0.608. These results show that FixV2W is a promising approach to identify and thwart emerging threats.
---
Prof. David Starobinski is a Professor of Electrical and Computer Engineering and of Systems Engineering at Boston University, with an affiliated appointment in the Department of Computer Science. His research interests are in cybersecurity, wireless networking, blockchain and cryptocurrency, and network economics.
Sevval Simsek is a Computer Engineering PhD candidate at Boston University. She is a part of Networking and Information Systems Lab, and has been focusing on ML for Cybersecurity, and improving cybersecurity operations with graphs and algorithms.
Varsha Athreya is an undergraduate student studying Computer Engineering with a Concentration in Machine Learning. She is working on using knowledge graphs to fix mappings in the National Vulnerability Database as well as using the New England Research Cloud for model training and deployment.
David Starobinski (Boston University, US), Sevval Simsek (Boston University, US), Varsha Athreya (Boston University, US)
Accurate mapping between Common Vulnerabilities and Exposures (CVE) and Common Weakness Enumeration (CWE) entries is critical for effective vulnerability management and risk assessment. However, public databases, such as the National Vulnerability Database (NVD), suffer from inconsistent and incomplete CVE–CWE mappings, complicating automated analysis and remediation. We introduce FixV2W, a lightweight approach that leverages knowledge graph embeddings and longitudinal trends to improve mapping accuracy of the NVD. FixV2W systematically analyzes historical remapping patterns and leverages hierarchical relationships within NVD and CWE data to predict more precise CWE mappings for vulnerabilities linked to Prohibited or Discouraged categories. We run extensive experimental evaluation of FixV2W, based on test data set collected between August 2021 and December 2024. Considering the Top-10 ranked predictions, the results show that FixV2W predicts the correct CWE mappings for 69% of exploited vulnerabilities that had invalid CWEs before they were exploited. We also show that FixV2W significantly improves the performance of ML models relying on NVD data. For instance, for a model geared at uncovering unknown CVE-CWE mappings, FixV2W improves the Mean Reciprocal Rank (MRR) from 0.174 to 0.608. These results show that FixV2W is a promising approach to identify and thwart emerging threats.
---
Prof. David Starobinski is a Professor of Electrical and Computer Engineering and of Systems Engineering at Boston University, with an affiliated appointment in the Department of Computer Science. His research interests are in cybersecurity, wireless networking, blockchain and cryptocurrency, and network economics.
Sevval Simsek is a Computer Engineering PhD candidate at Boston University. She is a part of Networking and Information Systems Lab, and has been focusing on ML for Cybersecurity, and improving cybersecurity operations with graphs and algorithms.
Varsha Athreya is an undergraduate student studying Computer Engineering with a Concentration in Machine Learning. She is working on using knowledge graphs to fix mappings in the National Vulnerability Database as well as using the New England Research Cloud for model training and deployment.










