MARATTO

article · Computer Science and Information Systems

Mitigating out-of-vocabulary challenges in embedded devices vulnerability classification: An ensemble embedding approach with bidirectional context modeling

Abstract

Critical infrastructure is increasingly reliant on embedded systems, which are particularly vulnerable to cyberattacks due to their inherent complexity and interconnectivity. Accurate classification of vulnerabilities in these systems is essential for targeted analysis and mitigation strategies. While pre-trained word embeddings such as Word2Vec, GloVe, and FastText are commonly used for this purpose, their effectiveness is limited by reliance on training corpora that lack domainspecific terminology, leading to challenges with Out-of-Vocabulary words and reduced classification performance. To address this limitation, we propose a novel ensemble embedding technique that combines multiple pre-trained embeddings to improve vulnerability classification in embedded systems. Evaluated on benchmark datasets, including the National Vulnerability Database and the China National Vulnerability Database, our method achieves a 91.50% F1-score on unseen data, outperforming traditional single-embedding approaches. This advancement demonstrates significant potential for enhancing cybersecurity in critical infrastructure applications.

Research topics

  • Information and Cyber Security
  • Advanced Malware Detection Techniques
  • Web Application Security Vulnerabilities

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.2298/csis250314079b

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.