基于多门共享—私有混合专家的漏洞CVSS度量预测系统OA
A CVSS Metrics Prediction Model of Vulnerability Based on Multi-Gate Shared and Private Mixture of Experts
针对专家人工评定的通用漏洞评分系统(CVSS)主观性强、效率低下以及现有自动化预测方法无法有效利用CVSS各度量特征间的关联与差异的问题,提出一种基于多门共享—私有混合专家(MSPMoE)的漏洞CVSS度量预测模型.该模型可通过共享—私有混合专家机制,协同利用各度量间的共享特征与特有特征.首先,通过收集到的漏洞描述语料库对DistilBERT预训练模型进行微调,作为模型的特征编码器;其次,设计动态特征提取模块,以自适应地选择最优特征提取策略;最后,使用多门共享—私有混合专家作为分类器,其中共享专家网络用于捕获度量间的共享特征,私有专家网络则专注于提取各度量的私有特征,并通过门控网络动态控制不同专家的权重,使得模型能够平衡共享知识与私有知识,从而实现CVSS度量的精准预测.实验结果表明,所提模型在7个CVSS度量上的预测准确率优于现有最佳方法,在8个度量上的平均准确率达到83.32%.
To address the subjectivity and inefficiency of manual common vulnerability scoring system(CVSS)assessment and the limitations of existing automated methods in capturing inter-metric relation-ships,a CVSS metrics prediction model of vulnerability based on a multi-gate shared and private mix-ture of experts(MSPMoE)is proposed.In the model,a shared-private expert mechanism is used to em-ployed enyto jointly leverage shared and unique features across different metrics.Firstly,the Distil-BERT model is fine-tuned on a collected vulnerability description corpus as the feature encoder.Then,a dynamic feature extraction module is designed to adaptively select optimal feature representa-tion strategies.Finally,the MSPMoE classifier is adopted,where shared experts are used to capture common patterns across metrics,while private experts are used to extract metric-specific features.A gating network is used to dynamically weight each expert's contribution,to balance shared and private knowledge for accurate CVSS metrics prediction.Experiments show that the proposed model outper-forms state-of-the-art methods on seven CVSS metrics,achieving an average accuracy of 83.32%across all eight metrics.
王晓龙;杜晔;郑天帅;陈奇芳;关昌昊
北京交通大学 智能交通数据安全与隐私保护技术北京市重点实验室,北京 100044||北京交通大学 网络空间安全学院,北京 100044北京交通大学 智能交通数据安全与隐私保护技术北京市重点实验室,北京 100044||北京交通大学 网络空间安全学院,北京 100044北京交通大学 智能交通数据安全与隐私保护技术北京市重点实验室,北京 100044||北京交通大学 网络空间安全学院,北京 100044北京交通大学 电气学院,北京 100044北京交通大学 计算机科学与技术学院,北京 100044
信息技术与安全科学
CVSS度量预测漏洞评估多任务学习自然语言处理大模型
CVSS metrics predictionvulnerability assessmentmulti-task learningnatural lan-guage processinglarge language models
《信息工程大学学报》 2026 (1)
72-80,9
国家重点研发计划(2022YFB3105105)北京市自然科学基金(L254063)
评论