Researchers have conducted an industrial case study on predicting CVSS v3.1 scores for software vulnerabilities using in-context learning with locally deployable, open-source Large Language Models (LLMs). The study compared proprietary data with the Big-Vul dataset, finding them sufficiently aligned to use Big-Vul as a proxy for industrial data. Results indicated that medium-sized open-source code models, specifically CodeLlama2-7B, can achieve performance comparable to cloud-based models for CVSS regression when guided by lightweight, output-constraining prompts, offering a privacy-preserving solution for industrial vulnerability triage. AI
IMPACT Offers a privacy-preserving, locally deployable alternative for industrial vulnerability severity assessment.
RANK_REASON Academic paper presenting a case study on LLM application for vulnerability severity prediction. [lever_c_demoted from research: ic=1 ai=1.0]
- Big-Vul dataset
- CodeLlama2-13B
- CodeLlama2-7B
- CVSS v3.1
- Daniel Rodriguez-Cardenas
- in-context learning
- GPT4o-mini
- gpt-oss
- Mistral-7B
- open-source LLMs
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →