Diaeddin Rimawi

dblp:336/4411 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0003-3791-399XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 From attack descriptions to vulnerabilities: A sentence transformer-based approach
abstract
In the domain of security, vulnerabilities frequently remain undetected even after their exploitation. In this work, vulnerabilities refer to publicly disclosed flaws documented in Common Vulnerabilities and Exposures (CVE) reports. Establishing a connection between attacks and vulnerabilities is essential for enabling timely incident response, as it provides defenders with immediate, actionable insights. However, manually mapping attacks to CVEs is infeasible, thereby motivating the need for automation. This paper evaluates 14 state-of-the-art (SOTA) sentence transformers for automatically identifying vulnerabilities from textual descriptions of attacks. Our results demonstrate that the multi-qa-mpnet-base-dot-v1 (MMPNet) model achieves superior classification performance when using attack Technique descriptions, with an F 1 -score of 89.0, precision of 84.0, and recall of 94.7. Furthermore, it was observed that, on average, 56% of the vulnerabilities identified by the MMPNet model are also represented within the CVE repository in conjunction with an attack, while 61% of the vulnerabilities detected by the model correspond to those cataloged in the CVE repository. A manual inspection of the results revealed the existence of 275 predicted links that were not documented in the MITRE repositories. Consequently, the automation of linking attack techniques to vulnerabilities not only enhances the detection and response capabilities related to software security incidents but also diminishes the duration during which vulnerabilities remain exploitable, thereby contributing to the development of more secure systems. • Automated vulnerability detection using 14 state-of-the-art sentence transformer models. • multi-qa-mpnet-base-dot-v1 achieves an F1 score of 89.0, outperforming other models (e.g., MiniLM, BERT). • Attack technique information yields the highest accuracy (57.3%) for vulnerability prediction. • 275 missing links between attack techniques and vulnerabilities identified through manual validation. • Open-source code and dataset provided to enable reproducible mapping from attacks to CVEs.
Refat Othman, Diaeddin Rimawi, Bruno Rossi 0001, Barbara Russo
J. Syst. Softw.2
2024 Modeling Resilience of Collaborative AI Systems
abstract
A Collaborative Artificial Intelligence System (CAIS) performs actions in collaboration with the human to achieve a common goal. CAISs can use a trained AI model to control human-system interaction, or they can use human interaction to dynamically learn from humans in an online fashion. In online learning with human feedback, the AI model evolves by monitoring human interaction through the system sensors in the learning state, and actuates the autonomous components of the CAIS based on the learning in the operational state. Therefore, any disruptive event affecting these sensors may affect the AI model's ability to make accurate decisions and degrade the CAIS performance. Consequently, it is of paramount importance for CAIS managers to be able to automatically track the system performance to understand the resilience of the CAIS upon such disruptive events. In this paper, we provide a new framework to model CAIS performance when the system experiences a disruptive event. With our framework, we introduce a model of performance evolution of CAIS. The model is equipped with a set of measures that aim to support CAIS managers in the decision process to achieve the required resilience of the system. We tested our framework on a real-world case study of a robot collaborating online with the human, when the system is experiencing a disruptive event. The case study shows that our framework can be adopted in CAIS and integrated into the online execution of the CAIS activities.
Diaeddin Rimawi, Antonio Liotta, Marco Todescato, Barbara Russo
CAIN1
2023 CAIS-DMA: A Decision-Making Assistant for Collaborative AI Systems
Diaeddin Rimawi, Antonio Liotta, Marco Todescato, Barbara Russo
PROFES (1)1
2023 GResilience: Trading Off Between the Greenness and the Resilience of Collaborative AI Systems
Diaeddin Rimawi, Antonio Liotta, Marco Todescato, Barbara Russo
ICTSS1