Papers by Michele Carminati
AutoCVSS: Assessing the Performance of LLMs for Automated Software Vulnerability Scoring (2025.emnlp-industry)
Copied to clipboard
| Challenge: | Increasing number of daily disclosed software vulnerabilities imposes significant pressure on security analysts, extending the time between disclosure and exploitation. |
| Approach: | They propose to use Large Language Models to automate vulnerability risk score prediction using the industrial CVSS standard. |
| Outcome: | The proposed model complements baselines in data-scarce settings without annotated data, highlighting their value in improving vulnerability management. |