AI

HARP: Hierarchical Adaptive Ranking with Preference-Adaptive Fusion for Query-Based CVE Prioritization

Researchers propose a new framework called HARP for prioritizing vulnerabilities based on specific operational preferences. Unlike existing methods that assume a fixed criterion, HARP takes into account the current preference scenario and uses a graph-grounded multi-view approach to rank candidates from a natural-language query. The framework retrieves evidence from a vulnerability knowledge graph and scores candidates with different views, including policy-conditioned global
Researchers propose a new framework called HARP for prioritizing vulnerabilities based on specific operational preferences. Unlike existing methods that assume a fixed criterion, HARP takes into account the current preference scenario and uses a graph-grounded multi-view approach to rank candidates from a natural-language query. The framework retrieves evidence from a vulnerability knowledge graph and scores candidates with different views, including policy-conditioned global, enterprise, and user perspectives. Experiments show that HARP outperforms multiple baselines in three different preference scenarios. --- Why it matters: This matters because existing vulnerability prioritization methods often fail to account for the nuances of specific operational preferences, leading to inefficient remediation efforts. HARP's ability to adapt to different scenarios can help organizations prioritize vulnerabilities more effectively and allocate resources better. Source: https://arxiv.org/abs/2608.19430

This article was originally published at: https://arxiv.org/abs/2608.19430