arXiv:2607.03887cs.CRcs.AI2026-07中稿 · the 16th Internati…

用大模型主题建模,自动分类软件漏洞,提升安全响应效率。

Advanced Topic Modeling Techniques for Categorizing Software Vulnerabilities

论文配图:Advanced Topic Modeling Techniques for Categorizing Software Vulnerabilities
图 1 · 摘自论文原文
  • 结合LLM与主题模型,从漏洞文本中提取隐含威胁模式。
  • 通过聚类分析识别出可解释的漏洞类别,支持优先级判断。
  • 适合安全团队用于自动化漏洞管理,提升处置效率。

软件漏洞的复杂性和频发性要求高效的分析与优先级排序方法。传统方法难以有效处理大量非结构化文本数据,亟需先进解决方案。本研究利用大语言模型驱动的前沿主题建模技术(如BERTopic、Top2Vec、CombinedTM、Llama2+BERTopic、Mixtral),结合降维(UMAP、PCA)与聚类算法(HDBSCAN、DBSCAN),从软件漏洞数据集的‘Threat’字段中挖掘潜在模式并生成可解释的聚类结果。该方法显著提升了威胁识别与优先级判断能力,为构建可扩展、自动化的漏洞管理体系提供支持,有助于改进网络安全实践。

原文摘要 · Abstract (English)

The increasing complexity and frequency of software vulnerabilities demand efficient methods to analyze and prioritize threats. Traditional approaches often fail to process the vast amount of unstructured textual data effectively, highlighting the need for advanced solutions. This study leverages state-of-the-art topic modeling techniques powered by large language models (LLMs) to extract meaningful insights from the 'Threat' feature of a software vulnerability dataset. Models such as BERTopic, Top2Vec, CombinedTM, Llama2 with BERTopic, and Mixtral are utilized, along with dimensionality reduction and clustering methods like UMAP, PCA, HDBSCAN, and DBSCAN. By uncovering latent patterns and generating interpretable clusters, this research enhances threat prioritization and decision-making in cybersecurity. The findings support scalable and automated solutions for vulnerability management, contributing to improved security practices.

漏洞分类主题建模LLM应用安全分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。