Skip to main navigation Skip to search Skip to main content

Tool-Assisted CVSS Vulnerability Scoring: A Controlled Quantitative Study of Human Assessment

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

Quantitative vulnerability assessment is central to security management, guiding how risks are prioritized and mitigated. Yet, severity scoring relies on human judgment and is therefore subject to differences in experience, interpretation, and diligence; prior work has even shown expert disagreement. We examine an NLP-based assistive tool that visualizes keyword cues during assessment. In a controlled survey of 389 participants recruited via Amazon MTurk and Prolific, we statistically analyze how participant skills/demographics, vulnerability characteristics, and tool support affect outcomes. Results show the tool does not consistently improve assessment accuracy across expertise levels, but can help for specific vulnerability types (e.g., CWE-787) and CVSS metrics (AC, PR, Scope), and can increase user confidence. Beyond immediate performance, the tool can support training for manual assessment tasks that are hard to automate, as learning effects yield significant improvements on subsequent tasks. This work informs the design of cybersecurity decision-support tools and motivates future research on security training and human-centered security.

Original languageEnglish
Title of host publicationCHI 2026
Subtitle of host publicationProceedings of the 2026 CHI Conference on Human Factors in Computing Systems
EditorsNuria Oliver, David A. Shamma, Heloisa Candello, Pablo Cesar, Pedro Lopes, Alessandro Bozzon, Thomas Kosch, Vera Liao, Xiaojuan Ma, Valentino Artizzu, Fiona Draxler, Gustavo Lopez, Anke V. Reinschluessel, Xin Tong, Phoebe O. Toups Dugas
PublisherAssociation for Computing Machinery
Pages1-24
Number of pages24
ISBN (Electronic)9798400722783
DOIs
Publication statusPublished - 13 Apr 2026
Event2026 CHI Conference on Human Factors in Computing Systems, CHI 2026 - Barcelona, Spain
Duration: 13 Apr 202617 Apr 2026

Publication series

NameConference on Human Factors in Computing Systems - Proceedings

Conference

Conference2026 CHI Conference on Human Factors in Computing Systems, CHI 2026
Country/TerritorySpain
CityBarcelona
Period13/04/2617/04/26

Bibliographical note

Publisher Copyright:
© 2026 Copyright held by the owner/author(s).

Funding

The work was partly supported by the Nederlandse Organisatie voor Wetenschappelijk Onderzoek (NWO) under grant n. NWA.1215.18.006 (Theseus), the European Union (EU) under Horizon Europe grant n. 101120393 (Sec4AI4Sec), and by the Nederlandse Organisatie voor Wetenschappelijk Onderzoek (NWO) under grant n. KIC1.VE01.20.004 (HEWSTI), the Dutch sectorplan, NSERC Discovery Grant n. RGPIN-2020-04734, NSERC Alliance Grant n. ALLRP 558365-20, and by the Network Institute, Vrije Universiteit Amsterdam through the Research Visits program. We thank anonymous reviewers for their helpful feedback. We thank Siu Hong (Thomas) Tam for conducting the pilot study

FundersFunder number
European Commission
HEWSTI
Natural Sciences and Engineering Research Council of CanadaRGPIN-2020-04734, ALLRP 558365-20
HORIZON EUROPE Framework ProgrammeKIC1.VE01.20.004, 101120393
Nederlandse Organisatie voor Wetenschappelijk OnderzoekNWA.1215.18.006

    Keywords

    • CVE
    • CVSS
    • Human-computer Interaction
    • NLP
    • User Study

    Fingerprint

    Dive into the research topics of 'Tool-Assisted CVSS Vulnerability Scoring: A Controlled Quantitative Study of Human Assessment'. Together they form a unique fingerprint.

    Cite this