2026· International Journal of Advanced Computer Science and Applications· Vol 17· 0 citations· 28 references
TL;DR
This study presents a knowledge-fused neural framework that reformulates this as a five-class temporal classification: 0–7 days, 8–30 days, 31–90 days, 91–365 days, and never exploited.
Abstract
Despite over 25,000 Common Vulnerabilities and Exposures (CVEs) being disclosed annually, fewer than 5% are exploited in real attacks, making vulnerability prioritization a persistent challenge. Existing methods, including the Common Vulnerability Scoring System (CVSS) and Exploit Prediction Scoring System (EPSS), treat exploitation prediction as binary classification, discarding the temporal dimension that determines whether a patch needs deployment today, next month, or later. This study presents a knowledge-fused neural framework that reformulates this as a five-class temporal classification: 0–7 days, 8–30 days, 31–90 days, 91–365 days, and never exploited. The framework constructs a cybersecurity knowledge graph that integrates 1,003 Common Weakness Enumeration (CWE) definitions and 559 Common Attack Pattern Enumeration and Classification (CAPEC) attack patterns, with 5,070 relationships. Graph embeddings from Node2Vec are fused with Bidirectional Encoder Representations from Transformers (BERT) vulnerability embeddings via cross-attention. Evaluated on 102,000+ CVEs (2002–2024), the framework achieves 78.4% temporal classification accuracy, 74.7% exploitation F1-score, and 89.1% Area Under the Receiver Operating Characteristic curve (AUC-ROC)—outperforming EPSS by 6.8 F1 points. Ablation studies confirm that knowledge graph integration with cross-attention fusion is the critical architectural contribution.
The exponential growth of cyber threats and software flaws, automated detection approaches that can recognize malicious code patterns in dynamic environments are required. Signature based and primitive machine learning theory inability to generalize when presented with new or unseen vulnerabilities is reflected in the...
Akshay Jain, Atul Agrawal· International journal of com...· 0 citations
Zero-day malware continues to pose a significant challenge in cybersecurity, primarily due to the rapid development of polymorphic and metamorphic variants that evade traditional detection methods based on signatures or machine learning (ML). Most existing ML approaches are reactive, identifying specific malware famili...
Abdulbasid S. Banga, Mazen Jamal, Tayyab Khan et al.· Discover Computing· 0 citations
The results show that the ensemble techniques are a practical approach to boost the precision of LLMs in the detection of vulnerabilities and suggest that ensemble methods offer great potential in the advancement of software security analysis.
H. Al-Ofeishat, Azhar Hussain, M. Faheem et al.· Engineering, Technology &...· 0 citations
This thesis rebuilds Real-Vul through a controlled Code Property Graph pipeline, measure and remove a 37% content leak intrinsic to whole-codebase sampling, and train a relational graph neural network with a disciplined class-imbalance recipe: focal loss, class-aware undersampling, and fine-tuning of a GraphCodeBERT no...
Smart contracts are widely used to automate blockchain-based transactions and decentralised services, but vulnerabilities in their code can expose users and systems to financial loss, service disruption, and security compromise. Detecting vulnerable smart contracts remains challenging because reliable labelling oft...
G. A. Sampedro, Yan-Hui Cheng, Arlene R. Caballero et al.· Frontiers in Blockchain· 0 citations
Smart contracts operate in decentralized environments where deployed code cannot be easily modified, making security vulnerabilities particularly critical. Even minor logical flaws may lead to severe financial and operational consequences. Although traditional static analysis and symbolic execution techniques have been...
R. S, Mahantesh Mathapati· Journal of Artificial Intell...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.