Taxonomy structure drives BERT performance in vulnerability classification
Researchers compared multi-class and multi-label BERT architectures for automating CVE-to-CWE vulnerability classification, a critical bottleneck in security operations. Testing three transformer variants across nested label hierarchies revealed that single-label prediction outperforms multi-label by up to 21 points on larger taxonomies, though the gap collapses to 2 points when label space shrinks. This finding matters because it shows taxonomy granularity directly shapes model error patterns in security domains, suggesting practitioners must align their formulation choice to their classification hierarchy rather than assuming one approach universally dominates.52


























