Week Ending 7.19.2026

· Source: Research Watch - Eye On AI · Field: Technology & Digital — Artificial Intelligence & Machine Learning, Cybersecurity & Data Privacy, Robotics & Autonomous Systems · Depth: Advanced, extended

Summary

Connected and Autonomous Vehicles (CAVs) face vulnerabilities often buried in unstructured CVE text. This paper evaluates 11 open-weight LLMs (4B to 120B parameters) for converting CAV vulnerability descriptions into structured STIX threat objects, CWE weaknesses, and MITRE ATT&CK mappings, using the new CAV-STIXGen dataset. Single-model configurations achieved F1 scores of 0.94 for STIX Domain Objects (SDO), 0.63 for STIX Relationship Objects (SRO), and 0.99 for CWE mapping. Complete MITRE ATT&CK mapping remained challenging. Multi-agent setups, like Gemma-4-31B and Codestral-22B, achieved F1 scores of 0.91 for SDOs and 0.43 for SROs.

Key takeaway

For AI Security Engineers managing Connected and Autonomous Vehicle vulnerabilities, consider integrating open-weight LLMs to automate the conversion of unstructured CVEs into STIX, CWE, and MITRE ATT&CK formats. This can streamline threat intelligence and prioritize defense strategies, though full attack chain mapping still requires human oversight for accuracy.

Key insights

LLMs can structure CAV vulnerability data, but struggle with full attack chains.

Principles

Method

Evaluate 11 open-weight LLMs on CAV-STIXGen dataset, mapping CAV vulnerability descriptions to STIX, CWE, and MITRE ATT&CK.

In practice

Topics

Code references

Best for: NLP Engineer, Research Scientist, AI Scientist, AI Security Engineer, Robotics Engineer

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by Research Watch - Eye On AI.