{"id":"https://openalex.org/W4415821081","doi":"https://doi.org/10.1109/access.2025.3627919","title":"Multi-Modal Machine Learning for Automated CVSS Severity Prediction for Conservative Vulnerability Assessment","display_name":"Multi-Modal Machine Learning for Automated CVSS Severity Prediction for Conservative Vulnerability Assessment","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4415821081","doi":"https://doi.org/10.1109/access.2025.3627919"},"language":"en","primary_location":{"id":"doi:10.1109/access.2025.3627919","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3627919","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1109/access.2025.3627919","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007358895","display_name":"Su-Chang Lim","orcid":"https://orcid.org/0009-0009-4891-4745"},"institutions":[{"id":"https://openalex.org/I199143407","display_name":"Sunchon National University","ror":"https://ror.org/043jqrs76","country_code":"KR","type":"education","lineage":["https://openalex.org/I199143407"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Su-Chang Lim","raw_affiliation_strings":["Department of Computer Engineering, Sunchon National University, Suncheon, Republic of Korea","Department of Computer Engineering, Adjunct Professor (Ph.D), Sunchon National University, Suncheon, Republic of Korea"],"raw_orcid":"https://orcid.org/0009-0009-4891-4745","affiliations":[{"raw_affiliation_string":"Department of Computer Engineering, Sunchon National University, Suncheon, Republic of Korea","institution_ids":["https://openalex.org/I199143407"]},{"raw_affiliation_string":"Department of Computer Engineering, Adjunct Professor (Ph.D), Sunchon National University, Suncheon, Republic of Korea","institution_ids":["https://openalex.org/I199143407"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5036579800","display_name":"Jong-Chan Kim","orcid":"https://orcid.org/0000-0002-8219-4501"},"institutions":[{"id":"https://openalex.org/I199143407","display_name":"Sunchon National University","ror":"https://ror.org/043jqrs76","country_code":"KR","type":"education","lineage":["https://openalex.org/I199143407"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Jong-Chan Kim","raw_affiliation_strings":["Department of Computer Engineering, Sunchon National University, Suncheon, Republic of Korea","Department of Computer Engineering, Associate Professor (Tenured), Sunchon National University, Suncheon, Republic of Korea"],"raw_orcid":"https://orcid.org/0000-0002-8219-4501","affiliations":[{"raw_affiliation_string":"Department of Computer Engineering, Sunchon National University, Suncheon, Republic of Korea","institution_ids":["https://openalex.org/I199143407"]},{"raw_affiliation_string":"Department of Computer Engineering, Associate Professor (Tenured), Sunchon National University, Suncheon, Republic of Korea","institution_ids":["https://openalex.org/I199143407"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.42361115,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"13","issue":null,"first_page":"189344","last_page":"189357"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.4726000130176544,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.4726000130176544,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.07940000295639038,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.06430000066757202,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.59579998254776},{"id":"https://openalex.org/keywords/consistency","display_name":"Consistency (knowledge bases)","score":0.49239999055862427},{"id":"https://openalex.org/keywords/logistic-regression","display_name":"Logistic regression","score":0.4918000102043152},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.49070000648498535},{"id":"https://openalex.org/keywords/vulnerability-assessment","display_name":"Vulnerability assessment","score":0.36719998717308044},{"id":"https://openalex.org/keywords/regression","display_name":"Regression","score":0.3601999878883362},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.3578999936580658},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.35589998960494995}],"concepts":[{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.7750999927520752},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.766700029373169},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6680999994277954},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.59579998254776},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.49239999055862427},{"id":"https://openalex.org/C151956035","wikidata":"https://www.wikidata.org/wiki/Q1132755","display_name":"Logistic regression","level":2,"score":0.4918000102043152},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.49070000648498535},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.39169999957084656},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.36719998717308044},{"id":"https://openalex.org/C83546350","wikidata":"https://www.wikidata.org/wiki/Q1139051","display_name":"Regression","level":2,"score":0.3601999878883362},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.3578999936580658},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.35589998960494995},{"id":"https://openalex.org/C70153297","wikidata":"https://www.wikidata.org/wiki/Q5591907","display_name":"Gradient boosting","level":3,"score":0.3407999873161316},{"id":"https://openalex.org/C110313322","wikidata":"https://www.wikidata.org/wiki/Q7100793","display_name":"Ordinal regression","level":2,"score":0.3287000060081482},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.3208000063896179},{"id":"https://openalex.org/C2909711754","wikidata":"https://www.wikidata.org/wiki/Q7100785","display_name":"Ordinal Scale","level":2,"score":0.30149999260902405},{"id":"https://openalex.org/C49937458","wikidata":"https://www.wikidata.org/wiki/Q2599292","display_name":"Probabilistic logic","level":2,"score":0.2964000105857849},{"id":"https://openalex.org/C2778012447","wikidata":"https://www.wikidata.org/wiki/Q1034415","display_name":"Scope (computer science)","level":2,"score":0.2809000015258789},{"id":"https://openalex.org/C12267149","wikidata":"https://www.wikidata.org/wiki/Q282453","display_name":"Support vector machine","level":2,"score":0.2793000042438507},{"id":"https://openalex.org/C45804977","wikidata":"https://www.wikidata.org/wiki/Q7239673","display_name":"Predictive modelling","level":2,"score":0.25619998574256897},{"id":"https://openalex.org/C152877465","wikidata":"https://www.wikidata.org/wiki/Q208042","display_name":"Regression analysis","level":2,"score":0.2540999948978424}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2025.3627919","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3627919","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:78cfa57f5d254d79938b1a56f9ee51c5","is_oa":true,"landing_page_url":"https://doaj.org/article/78cfa57f5d254d79938b1a56f9ee51c5","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 13, Pp 189344-189357 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2025.3627919","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3627919","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W1972791208","https://openalex.org/W1985987493","https://openalex.org/W1993558273","https://openalex.org/W1997855593","https://openalex.org/W2005662348","https://openalex.org/W2065890363","https://openalex.org/W2079753286","https://openalex.org/W2119191234","https://openalex.org/W2142481192","https://openalex.org/W2148143831","https://openalex.org/W2190044943","https://openalex.org/W2360967250","https://openalex.org/W2562319768","https://openalex.org/W2619383789","https://openalex.org/W2740130862","https://openalex.org/W2861867928","https://openalex.org/W2909172538","https://openalex.org/W2957702778","https://openalex.org/W3100209521","https://openalex.org/W4247200422","https://openalex.org/W4399837262"],"related_works":[],"abstract_inverted_index":{"This":[0],"study":[1],"presents":[2],"a":[3,125],"multi-modal":[4,120],"machine":[5],"learning":[6],"framework":[7],"for":[8,54,73,113,128],"automated":[9],"CVSS":[10],"severity":[11,48,107,112],"prediction,":[12],"addressing":[13],"scalability":[14],"and":[15,41,43,50,66,76,119],"consistency":[16],"challenges":[17],"in":[18],"vulnerability":[19,93,131],"assessment.":[20],"We":[21],"integrate":[22],"semantic":[23],"code":[24],"representations":[25],"from":[26],"GraphCodeBERT":[27,63],"with":[28,64,109],"TF-IDF":[29],"features,":[30],"processed":[31],"through":[32],"class-weighted":[33],"gradient":[34],"boosting,":[35],"ordinal":[36],"regression":[37],"(Ordinal":[38],"Logistic":[39],"Regression":[40],"CORAL),":[42],"cost-sensitive":[44],"models":[45,86],"to":[46],"respect":[47],"ordering":[49],"minimize":[51],"false":[52],"negatives":[53],"critical":[55],"threats.":[56],"Evaluating":[57],"36":[58],"model":[59],"configurations,":[60],"our":[61],"optimal":[62],"Code_TFIDF_Fusion":[65],"LightGBM":[67],"achieves":[68],"66.6%":[69],"accuracy,":[70],"78.0%":[71],"F1-score":[72],"CRITICAL":[74,92],"vulnerabilities,":[75],"76.0%":[77],"recall,":[78],"reducing":[79],"manual":[80],"reviews":[81],"by":[82,90],"over":[83],"three-quarters.":[84],"Cost-sensitive":[85],"further":[87],"enhance":[88],"safety":[89],"prioritizing":[91],"detection.":[94],"A":[95],"Mean":[96],"Absolute":[97],"Error":[98],"of":[99],"0.647":[100],"ensures":[101],"errors":[102],"are":[103],"mostly":[104],"between":[105],"adjacent":[106],"levels,":[108],"45%":[110],"overestimating":[111],"conservative":[114],"safety.":[115],"Graph":[116],"structural":[117],"features":[118],"fusion":[121],"improve":[122],"performance,":[123],"establishing":[124],"robust":[126],"foundation":[127],"efficient,":[129],"security-oriented":[130],"management.":[132]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-03T00:00:00"}
