AI 中文总结
研究汽车CVE到ATM映射问题,提出通过分层上下文学习生成候选映射,融合多种信号到校准元模型,以校准置信度分数分类候选映射,在评估集上显著提高精度,支持选择性自动化。
AI 中文摘要
公共CVE描述报告漏洞的技术条件和影响,而汽车威胁矩阵(ATM)表达对手的策略和技术。由于两者表示不直接对齐,安全关键环境中的错误自动映射可能扭曲威胁解读和缓解优先级,因此需要一种置信度感知方法来区分可自动确认的映射和不确定情况。本文将汽车CVE到ATM映射重新表述为选择性自动化问题。所提出的框架通过分层上下文学习生成候选映射,然后将自一致性和基于大语言模型的证据验证信号融合到校准的元模型中。由此产生的校准置信度分数将每个候选映射分类为自动、审核或保留。在评估集上,该系统在匹配召回率方面显著提高了候选集精度。在高置信度操作模式下,自动层级的精度达到0.878,校准置信度分数在区分正确与错误候选映射时的AUROC为0.868。这些结果表明该框架可通过将可自动确认的映射与需要分析师审核的映射区分开来支持选择性自动化。
英文摘要
Public CVE descriptions report the technical conditions and impact of vulnerabilities, whereas the Auto-ISAC Automotive Threat Matrix (ATM) expresses an adversary's tactics and techniques. Because the two representations are not directly aligned, incorrect automated mappings in safety-critical environments may distort threat interpretation and mitigation prioritization, motivating a confidence-aware approach that distinguishes auto-confirmable mappings from uncertain cases. This paper reformulates automotive CVE-to-ATM mapping as a selective automation problem. The proposed framework generates candidate mappings via hierarchical in-context learning, then fuses self-consistency and LLM-based evidence verification signals into a calibrated meta-model. The resulting calibrated confidence score routes each candidate into AUTO, REVIEW, or HOLD. On the evaluation set, the proposed system substantially improved candidate-set precision at matched recall over a Flat zero-shot GPT-5.2 baseline. In the High-Confidence operating mode, the AUTO tier achieved a precision of 0.878, more than double the candidate-set base rate, and the calibrated confidence score achieved an AUROC of 0.868 in distinguishing correct from incorrect candidates. These results show that the framework can support selective automation by isolating auto-confirmable mappings from those requiring analyst review.
Comments11 pages, 2 figures, 3 tables; Accepted at ESCAR EUROPE 2026