EDBT 2026 Demo / reviewers in the wild / expert
Stefano Simonetto
dblp:374/4081
· DBLP profile ↗
4ranked-venue papers
4as first author
4since 2021 · last 2026
0009-0009-9778-4019ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowing your weaknesses is your greatest strength: Mapping CVE to CWE by leveraging CWE Hierarchy and fine-tuned LLMsabstractEffective defense against threat actors requires that security professionals accurately identify the underlying weaknesses associated with common vulnerabilities and exposures (CVEs). This under standing is crucial for deploying appropriate defensive mechanisms and prioritizing remediation efforts. However, manually mapping CVEs to common weakness enumerations (CWEs) has become increasingly impractical due to the rapid increase of new CVEs and the extensive, complex CWE taxonomy. In 2025, the number of CVEs awaiting analysis exceeded 25,000. To automate the mapping between CVEs and CWEs, we propose to leverage two insights. To harness the power of large language models, we first fine-tune different language models to perform this mapping based on the vulnerability-to-weakness relation. Second, we propose a supervised framework leveraging the hierarchical structure of CWEs, where we first categorize vulnerabilities into broad CWE classes (e.g., Injection, Buffer Overflow), which helps capture high-level patterns, and then utilizes specialized subnet works to distinguish fine-grained differences within each class. Evaluated on a benchmarkthat covers 95% of all CVEs associated with a CWE, our approach improves F1-score by 5% over the best prior supervised method, demonstrating the value of combining model fine-tuning with hierarchy-aware classification. Stefano Simonetto, Ronan Oostveen, Thijs van Ede, Peter Bosch, Willem Jonker |
AsiaCCS | 1 |
| 2025 | What Matters Most in Vulnerabilities? Key Term Extraction for CVE-to-CWE Mapping with LLMs
Stefano Simonetto, Ronan Oosteven, Thijs van Ede, Peter Bosch, Willem Jonker |
CANS | 1 |
| 2025 | Beyond CWEs: Mapping Weaknesses in Unstructured Threat Intelligence Text
Stefano Simonetto, Ronan Oosteven, Thijs van Ede, Peter Bosch, Willem Jonker |
CANS | 1 |
| 2024 | Strengthening Cloud Applications: A Deep Dive into Kill Chain Identification, Scoring, and Automatic Penetration Testing
Stefano Simonetto |
RCIS (2) | 1 |