← Back to brief
ModelsOfficialPreprintarXiv Cryptography and Security

LLM-Generated Labels Fail to Improve CVE-to-ATT&CK Mapping Classifiers, Study Finds

A new arXiv preprint presents a reproducible pipeline for mapping CVEs to MITRE ATT&CK techniques using a multi-label classifier trained on expert-curated data. The study finds that expanding the training set with LLM-generated labels does not reliably improve classifier performance and can even reduce accuracy for rare techniques. Only additional expert-curated data consistently enhances model results. All resources from the study are publicly released.

Why it matters: This work underscores the limitations of using LLMs for automated label expansion in security-critical tasks, reinforcing the need for expert curation.

Full story at: arXiv Cryptography and Security