LLM-Generated Labels Fail to Improve CVE-to-ATT&CK Mapping Classifiers, Study Finds
A new arXiv preprint presents a reproducible pipeline for mapping CVEs to MITRE ATT&CK techniques using a multi-label classifier trained on expert-curated data. The study finds that expanding the training set with LLM-generated labels does not reliably improve classifier performance and can even reduce accuracy for rare techniques. Only additional expert-curated data consistently enhances model results. All resources from the study are publicly released.
Why it matters: This work underscores the limitations of using LLMs for automated label expansion in security-critical tasks, reinforcing the need for expert curation.
Full story at: arXiv Cryptography and Security ↗