Week Ending 7.19.2026
Summary
Connected and Autonomous Vehicles (CAVs) face vulnerabilities often buried in unstructured CVE text. This paper evaluates 11 open-weight LLMs (4B to 120B parameters) for converting CAV vulnerability descriptions into structured STIX threat objects, CWE weaknesses, and MITRE ATT&CK mappings, using the new CAV-STIXGen dataset. Single-model configurations achieved F1 scores of 0.94 for STIX Domain Objects (SDO), 0.63 for STIX Relationship Objects (SRO), and 0.99 for CWE mapping. Complete MITRE ATT&CK mapping remained challenging. Multi-agent setups, like Gemma-4-31B and Codestral-22B, achieved F1 scores of 0.91 for SDOs and 0.43 for SROs.
Key takeaway
For AI Security Engineers managing Connected and Autonomous Vehicle vulnerabilities, consider integrating open-weight LLMs to automate the conversion of unstructured CVEs into STIX, CWE, and MITRE ATT&CK formats. This can streamline threat intelligence and prioritize defense strategies, though full attack chain mapping still requires human oversight for accuracy.
Key insights
LLMs can structure CAV vulnerability data, but struggle with full attack chains.
Principles
- Open-weight LLMs achieve high F1 for SDO (0.94) and CWE (0.99) mapping.
- Multi-agent LLMs like Gemma-4-31B perform well on SDOs (0.91 F1).
Method
Evaluate 11 open-weight LLMs on CAV-STIXGen dataset, mapping CAV vulnerability descriptions to STIX, CWE, and MITRE ATT&CK.
In practice
- Automate threat intelligence pipelines for transportation security.
- Prioritize patching and defense strategies for CAVs.
Topics
- Autonomous Vehicles
- Cybersecurity
- Threat Intelligence
- Large Language Models
- STIX
- MITRE ATT&CK
- Vulnerability Management
Code references
Best for: NLP Engineer, Research Scientist, AI Scientist, AI Security Engineer, Robotics Engineer
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Research Watch - Eye On AI.