arXiv:2608.19430cs.IRcs.CL2026-08

基于历史案例与知识图谱,智能匹配安全漏洞优先级。

HARP: Hierarchical Adaptive Ranking with Preference-Adaptive Fusion for Query-Based CVE Prioritization

论文配图:HARP: Hierarchical Adaptive Ranking with Preference-Adaptive Fusion for Query-Based CVE Prioritization
图 1 · 摘自论文原文
  • 用知识图谱和历史案例构建多视角评分模型
  • 在三种偏好场景下均优于现有方法
  • 适合安全团队快速定位高危漏洞

漏洞优先级排序本质上依赖于组织偏好,同一漏洞在不同运营偏好下可能获得不同修复优先级。现有评分系统通常假设固定标准,但在实际中,组织虽已有隐含偏好,却难以书面表达,而常规排查查询也不包含该信息。过去已验证的排查案例更易获取。本文研究在此背景下基于自然语言查询的漏洞优先级排序问题,提出HARP:一种基于图结构的多视角框架,能结合自然语言查询与当前偏好场景的历史标注案例库进行候选漏洞排序,无需显式描述偏好。HARP从漏洞知识图谱中检索证据,利用政策条件化的全局、企业、用户三视角评分,并从采样支持案例中学习视图融合权重。在三个偏好场景和多种主流大模型上的实验表明,HARP显著优于多个基线方法,验证了其有效性。

原文摘要 · Abstract (English)

Vulnerability prioritization is inherently preference dependent, since the same CVE can receive different remediation priority under different operational preference scenarios. Existing scoring systems and ranking methods typically assume a fixed criterion. In practice, organizations already operate under a preference scenario, but this preference is often implicit and difficult to express as a written prompt instruction, while triage queries usually do not encode it. Past validated triage cases under the current scenario are more readily available. We study query-based CVE prioritization in this setting and propose HARP, a graph-grounded multi-view framework that ranks candidates from a natural-language query together with a support bank of historical labeled examples from the current preference scenario, without requiring an explicit textual summary of that scenario. HARP retrieves evidence from a vulnerability knowledge graph, scores candidates with policy-conditioned global, enterprise, and user views, and fits view-fusion weights from sampled supports. Experiments across three preference scenarios and multiple backbone LLMs show that HARP outperforms multiple baselines, expressing our method's effectiveness.

漏洞管理多视角排序知识图谱LLM应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。