CAV-STIXGen · Jul 17, 2026

Evaluating Open-Weight LLMs for Generating Structured Threat Information for Autonomous Vehicle Vulnerabilities

A study evaluated 11 open-source large language models (4B to 120B parameters) for converting CVE vulnerability descriptions of connected autonomous vehicles (CAVs) into STIX structured threat information, constructed the CAV-STIXGen dataset, and reported F1 scores for single-model configurations.

What happened

Researchers built the CAV-STIXGen dataset to map CAV vulnerability descriptions to STIX domain objects, relationship objects, CWE, and MITRE ATT&CK techniques, and evaluated 11 open-source LLMs under different prompt strategies and temperatures, achieving F1 scores with single-model configurations.

Technical significance

Open-source LLMs can extract and generate structured threat intelligence from unstructured CVE text, but performance is affected by model size, prompt strategy, and temperature; F1 scores indicate room for improvement.

Industry impact

This research provides a feasible path for automated threat intelligence generation in autonomous vehicle security operations; it remains to be seen whether security vendors or automakers will adopt similar methods.

What to watch

Future work may include more fine-tuning of LLMs for specific vertical domains and integration of such methods into security orchestration, automation, and response (SOAR) platforms.

Decision value

Automated generation of STIX-format threat intelligence can reduce manual workload for security analysts, accelerate vulnerability response, and has potential to improve efficiency and reduce costs in connected vehicle security operations.

Evidence