Controlled CVE Triage Stability Benchmark Dataset
收藏资源简介:
This record contains the dataset artefacts for the Controlled CVE Triage Stability Benchmark, a controlled benchmark for evaluating whether large language models preserve vulnerability-triage decisions under meaning-preserving presentation changes. The dataset joins public vulnerability signals per CVE: CVE descriptions and CVSS information from the NVD CVE API 2.0, exploitation probabilities and percentiles from FIRST EPSS, and known-exploitation indicators from the CISA Known Exploited Vulnerabilities catalogue. Each CVE is assigned one synthetic asset context and a policy-derived triage label: ACT, ATTEND, or TRACK. The released dataset.csv file contains 320 CVE records sampled across four strata: KEV-listed vulnerabilities, high-severity/low-probability vulnerabilities, high-probability non-KEV vulnerabilities, and lower-priority cases. The labels are deterministic policy-derived reference labels, not expert-adjudicated ground truth. The paraphrase.json file contains the fixed paraphrase condition used in the benchmark. These paraphrases were generated once using GPT-based rewriting and then frozen before evaluation. They are included to make the benchmark deterministic and reproducible. The paraphrasing changes surface wording only; CVSS, EPSS, KEV status, asset context, and policy labels remain unchanged. This dataset is intended for research on LLM robustness, vulnerability triage, cybersecurity decision support, and dependability under meaning-preserving input perturbations.



