[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84246-en":3,"doc-seo-84246-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84246,13056703019662,"Evangeline","https://ap-avatar.wpscdn.com/avatar/be000253a8e92610077?_k=1778726343310543188",8,"Research & Report","Multi-Class vs. Multi-Label BERT for CVE-to-CWE Mapping: How Taxonomy Structure Shapes the Errors","CVE-to-CWE assignment remains a largely manual step in vulnerability analysis. The study formulates CWE prediction as text classification and compares two modelling strategies: multi-class (one CWE per CVE) versus multi-label (multiple CWEs per CVE). Three transformer encoders—BERT Base, SecureBERT, and CySecBERT—are tested on nested label spaces (83, 47, 25 classes). Multi-class achieves higher macro-F1, while label-space shrink and multi-label threshold optimization reduce the gap. Error patterns align with the CWE hierarchy across all encoders, and hierarchy-relaxed evaluation boosts macro-F1 from ~81% to ~90%.","MULTI-CLASS VS . MULTI-LABEL BERT FOR CVE-TO-CWE  \nMAPPING:  \nHOW TAXONOMY STRUCTURE SHAPES THE ERRORS*  \nA PREPRINT  \nAna Schwengber Kelm   \nmindsquare AG Bielefeld, Germany [ana.luisa.kelm@mindsquare.de](ana.luisa.kelm@mindsquare.de)  \nChristian Bockermann   \nBochum University of Applied Sciences Bochum, Germany  \n[christian.bockermann@hs-bochum.de](christian.bockermann@hs-bochum.de)  \narXiv :2607 .07573v 1 [ cs .LG] 8 Jul 2026  \nJörg Frochte   \nBochum University of Applied Sciences  \nBochum, Germany  \n[joerg.frochte@hs-bochum.de](joerg.frochte@hs-bochum.de)  \nABSTRACT  \nAssigning Common Weakness Enumeration (CWE) categories to Common Vulnerabilities and Exposures (CVE) records remains an important but largely manual step in vulnerability analysis. We study this task as a text classification problem and compare two modelling choices: a multi-class formulation that predicts a single CWE per CVE and a multi-label formulation that allows multiple assignments. Three transformer encoders (BERT Base, SecureBERT, and CySecBERT) are evaluated on three nested label spaces (83, 47, and 25 classes) .  \nMulti-class training achieves higher macro-F1 across all settings, although the gap to multi-label narrows from 21 to 2 percentage points as the label space shrinks. Post-hoc threshold optimisation on the multi-label side closes this gap on the 25-class setting. Confusion analysis shows that the dominant misclassification patterns follow the CWE hierarchy and are shared across all three encoders (Pearson r > 0.92), which suggests that the error structure is driven more by taxonomy design than by encoder choice. A hierarchy-relaxed evaluation that forgives within-family confusions raises macro-F1 from ∼81% to ∼90%, indicating that strict metrics understate branch-level classifier quality.  \nCySecBERT achieves the strongest results overall, with statistically significant gains concentrated in the multi-label setting.  \nKeywords CVE · CWE · vulnerability classification · cybersecurity NLP · error analysis · multi-label classification · domain-adaptive pretraining  \n1 Introduction  \nIn today’s increasingly interconnected digital landscape, modern IT infrastructures are becoming frequent targets of cyberattacks, many of which are only made possible due to flaws and vulnerabilities in the underlying software. To address these threats systematically, the Common Vulnerabilities and Exposures (CVE) program provides a standardized mechanism for identifying and cataloging publicly disclosed vulnerabilities [17] . This system enables interoperable referencing of security-relevant software defects across tools and organizations.  \nIdentifying individual vulnerabilities is, however, only the first step: effective vulnerability management requires understanding root causes. This is where the Common Weakness Enumeration (CWE) becomes essential [18] . While  \n∗Accepted for publication at ICANN 2026 (International Conference on Artificial Neural Networks) . This is the authors’ version of the work; the final authenticated version will be published by Springer.  \nSoftware  \nBug/Defect   \nCVE-2024-37032   \nSoftware Dev. Research Concepts  \nImproper CWE-707  \nAccess Control Improper  \nNeutralization  \nCWE-20 CWE-170  \nFigure 1: A CVE mapped to a CWE taxonomy node. The hierarchy mixes abstraction levels: CWE-707 (“Pillar”) and CWE-20 (“Base”) coexist as valid targets, creating uneven supervision for classifiers.  \na CVE describes a specific incident, CWE provides a community-developed taxonomy of the underlying weakness types. Mapping CVEs to CWEs enables pattern recognition across incidents [13], systematic mitigation [9, 7], and aggregation at the level of root causes [1] .  \nThis mapping is currently performed largely by hand, and the workload is growing rapidly: annual CVE volume has risen from approximately 1,500 in 1999 to over 40,000 in 2024 [5] . Automated classification is therefore not merely convenient but operationally necessary.  \nFrom a machine-","cbCaim5ZnJwLh9Zc","https://ap.wps.com/l/cbCaim5ZnJwLh9Zc","pdf",250384,6,1,9,"English","en",105,"# Abstract\n# Introduction\n## Research questions\n## Contributions\n# Background\n## CVE, CWE, and annotation granularity","[{\"question\":\"What problem does the paper address in vulnerability analysis?\",\"answer\":\"It addresses the task of assigning CWE categories to CVE records, which is important but often performed manually.\"},{\"question\":\"How does the paper compare multi-class and multi-label modelling?\",\"answer\":\"It compares a multi-class setup that predicts a single CWE per CVE with a multi-label setup that allows multiple CWE assignments, evaluating performance across different label-space sizes.\"},{\"question\":\"What role does the CWE taxonomy hierarchy play in the model errors?\",\"answer\":\"The dominant misclassification patterns follow the CWE hierarchy and are shared across different BERT encoders, indicating the taxonomy structure drives much of the error structure.\"}]",1784194333,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"multi-class-vs-multi-label-bert-for-cve-to-cwe-mapping-how-taxonomy-structure-shapes-the-errors","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/multi-class-vs-multi-label-bert-for-cve-to-cwe-mapping-how-taxonomy-structure-shapes-the-errors/84246/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-28","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the paper address in vulnerability analysis?","Question",{"text":76,"@type":77},"It addresses the task of assigning CWE categories to CVE records, which is important but often performed manually.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the paper compare multi-class and multi-label modelling?",{"text":81,"@type":77},"It compares a multi-class setup that predicts a single CWE per CVE with a multi-label setup that allows multiple CWE assignments, evaluating performance across different label-space sizes.",{"name":83,"@type":74,"acceptedAnswer":84},"What role does the CWE taxonomy hierarchy play in the model errors?",{"text":85,"@type":77},"The dominant misclassification patterns follow the CWE hierarchy and are shared across different BERT encoders, indicating the taxonomy structure drives much of the error structure.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,115,120,123,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":107,"slug":137},19,"General","general"]