--- library_name: transformers license: cc-by-4.0 base_model: roberta-base metrics: - accuracy tags: - generated_from_trainer - text-classification - classification - nlp - vulnerability model-index: - name: vulnerability-severity-classification-roberta-base results: [] datasets: - CIRCL/vulnerability-scores --- # VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification # Severity classification This model is a fine-tuned version of [roberta-base](https://huggingface.co/roberta-base) on the dataset [CIRCL/vulnerability-scores](https://huggingface.co/datasets/CIRCL/vulnerability-scores). The model was presented in the paper [VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification](https://huggingface.co/papers/2507.03607) [[arXiv](https://arxiv.org/abs/2507.03607)]. **Abstract:** VLAI is a transformer-based model that predicts software vulnerability severity levels directly from text descriptions. Built on RoBERTa, VLAI is fine-tuned on over 600,000 real-world vulnerabilities and achieves over 82% accuracy in predicting severity categories, enabling faster and more consistent triage ahead of manual CVSS scoring. The model and dataset are open-source and integrated into the Vulnerability-Lookup service. You can read [this page](https://www.vulnerability-lookup.org/user-manual/ai/) for more information. ## Model description It is a classification model and is aimed to assist in classifying vulnerabilities by severity based on their descriptions. ## How to get started with the model ```python from transformers import AutoModelForSequenceClassification, AutoTokenizer import torch labels = ["low", "medium", "high", "critical"] model_name = "CIRCL/vulnerability-severity-classification-roberta-base" tokenizer = AutoTokenizer.from_pretrained(model_name) model = AutoModelForSequenceClassification.from_pretrained(model_name) model.eval() print("Model revision:", model.config._commit_hash) test_description = "SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries \ that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system." inputs = tokenizer(test_description, return_tensors="pt", truncation=True, padding=True) # Run inference with torch.no_grad(): outputs = model(**inputs) predictions = torch.nn.functional.softmax(outputs.logits, dim=-1) # Print results print("Predictions:", predictions) predicted_class = torch.argmax(predictions, dim=-1).item() print("Predicted severity:", labels[predicted_class]) ``` ## Training procedure ### Training hyperparameters The following hyperparameters were used during training: - learning_rate: 3e-05 - train_batch_size: 32 - eval_batch_size: 32 - seed: 42 - optimizer: Use OptimizerNames.ADAMW_TORCH_FUSED with betas=(0.9,0.999) and epsilon=1e-08 and optimizer_args=No additional optimizer arguments - lr_scheduler_type: linear - num_epochs: 5 It achieves the following results on the evaluation set: - Loss: 2.0373 - Accuracy: 0.8137 - F1 Macro: 0.7424 - Low Precision: 0.6660 - Low Recall: 0.4757 - Low F1: 0.5550 - Medium Precision: 0.8348 - Medium Recall: 0.8692 - Medium F1: 0.8516 - High Precision: 0.8163 - High Recall: 0.8102 - High F1: 0.8132 - Critical Precision: 0.7602 - Critical Recall: 0.7395 - Critical F1: 0.7497 ### Training results | Training Loss | Epoch | Step | Validation Loss | Accuracy | F1 Macro | Low Precision | Low Recall | Low F1 | Medium Precision | Medium Recall | Medium F1 | High Precision | High Recall | High F1 | Critical Precision | Critical Recall | Critical F1 | |:-------------:|:-----:|:-----:|:---------------:|:--------:|:--------:|:-------------:|:----------:|:------:|:----------------:|:-------------:|:---------:|:--------------:|:-----------:|:-------:|:------------------:|:---------------:|:-----------:| | 2.6518 | 1.0 | 19049 | 2.6882 | 0.7235 | 0.6396 | 0.4169 | 0.4805 | 0.4464 | 0.7792 | 0.7764 | 0.7778 | 0.7148 | 0.7409 | 0.7276 | 0.6632 | 0.5592 | 0.6068 | | 2.5168 | 2.0 | 38098 | 2.3584 | 0.7578 | 0.6749 | 0.6350 | 0.3686 | 0.4664 | 0.8087 | 0.8128 | 0.8108 | 0.7431 | 0.7566 | 0.7498 | 0.6498 | 0.6971 | 0.6726 | | 1.9209 | 3.0 | 57147 | 2.1623 | 0.7839 | 0.6967 | 0.7067 | 0.3504 | 0.4685 | 0.8078 | 0.8563 | 0.8314 | 0.7898 | 0.7654 | 0.7774 | 0.6907 | 0.7288 | 0.7093 | | 1.4313 | 4.0 | 76196 | 2.1291 | 0.8001 | 0.7300 | 0.6197 | 0.4962 | 0.5511 | 0.8262 | 0.8599 | 0.8427 | 0.8112 | 0.7838 | 0.7973 | 0.7193 | 0.7391 | 0.7290 | | 1.6812 | 5.0 | 95245 | 2.0373 | 0.8137 | 0.7424 | 0.6660 | 0.4757 | 0.5550 | 0.8348 | 0.8692 | 0.8516 | 0.8163 | 0.8102 | 0.8132 | 0.7602 | 0.7395 | 0.7497 | ### Framework versions - Transformers 5.17.0 - Pytorch 2.14.0+cu130 - Datasets 4.8.5 - Tokenizers 0.23.2