Section 01
[Introduction] Core Introduction to the CVE-LMTune Framework
This article introduces CVE-LMTune—a vulnerability classification framework for multi-taxonomy systems based on hierarchical fine-tuned language models—aimed at automating the annotation of vulnerability descriptions into three authoritative security taxonomies: MITRE ATT&CK, CWE, and CAPEC. Using a hierarchical cascading strategy and shared embedding technology, the framework achieves weighted F1 scores of 90% for CWE, 92% for CAPEC, and 93% for MITRE ATT&CK on the SecureBERT model, effectively addressing the issues of class imbalance and large label space in multi-label classification.