遇见数据集

Point-in-Time Vulnerability Data: Reproducibility Materials for Historical Vulnerability Reconstruction

收藏
Mendeley Data2026-09-08 收录
官方服务:

资源简介:

Point-in-Time Vulnerability Data v1.0.0 This is the first archived release of the reproducibility materials accompanying the MethodsX article: A Method for Reconstructing Historical Vulnerability Data for Prospective Exploitation Prediction Release scope This release provides code, configuration, schemas, synthetic examples, provenance documentation, and validation evidence for reconstructing vulnerability information as it was available at simulated decision dates and for constructing prospective exploitation outcomes without retrospective predictor backfill. Frozen study design Data freeze: 2026-08-06 Primary training window: 2023-03-29 through 2023-12-31 Validation window: 2024-01-01 through 2024-12-31 Primary held-out 365-day test window: 2025-01-01 through 2025-07-31 Primary outcome: future CISA KEV inclusion within 365 days Index rule: first historical EPSS observation on or after official CVE publication, retained when lag is 0 to 3 calendar days Reproduced publication counts Partition CVEs Future KEV within 365 days Training 22,258 71 Validation 36,498 94 Held-out test 27,419 84 Total 86,175 249 The final production temporal audit completed 25 checks with zero violations. Reproducibility safeguards Historical CVE records are reconstructed from Git history. Current CVE records are not backfilled into earlier decision dates. CVEs already in CISA KEV at or before the index date are excluded from prospective outcome construction. Negatives are assigned only when the complete forecast horizon is observable by the frozen data date. Explicit exploitation-status text is separated from the strict prospective text representation. Primary evaluation uses chronological partitions. Third-party source archives are not redistributed. Release commit The audited GitHub commit for this release is: 67012ecdd8c6720f93e957e3e9c37bb643687b80 Repository: https://github.com/akbak1-dot/point-in-time-vulnerability-data License Repository-authored software is released under the MIT License. Third-party source data retain their original provider terms and are not relicensed or redistributed by this release.

创建时间:
2026-09-06
二维码
社区交流群
二维码
科研交流群
商业服务