Abstract
Quantitative vulnerability assessment is central to security management, guiding how risks are prioritized and mitigated. Yet, severity scoring relies on human judgment and is therefore subject to differences in experience, interpretation, and diligence; prior work has even shown expert disagreement. We examine an NLP-based assistive tool that visualizes keyword cues during assessment. In a controlled survey of 389 participants recruited via Amazon MTurk and Prolific, we statistically analyze how participant skills/demographics, vulnerability characteristics, and tool support affect outcomes. Results show the tool does not consistently improve assessment accuracy across expertise levels, but can help for specific vulnerability types (e.g., CWE-787) and CVSS metrics (AC, PR, Scope), and can increase user confidence. Beyond immediate performance, the tool can support training for manual assessment tasks that are hard to automate, as learning effects yield significant improvements on subsequent tasks. This work informs the design of cybersecurity decision-support tools and motivates future research on security training and human-centered security.
| Original language | English |
|---|---|
| Title of host publication | CHI 2026 |
| Subtitle of host publication | Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems |
| Editors | Nuria Oliver, David A. Shamma, Heloisa Candello, Pablo Cesar, Pedro Lopes, Alessandro Bozzon, Thomas Kosch, Vera Liao, Xiaojuan Ma, Valentino Artizzu, Fiona Draxler, Gustavo Lopez, Anke V. Reinschluessel, Xin Tong, Phoebe O. Toups Dugas |
| Publisher | Association for Computing Machinery |
| Pages | 1-24 |
| Number of pages | 24 |
| ISBN (Electronic) | 9798400722783 |
| DOIs | |
| Publication status | Published - 13 Apr 2026 |
| Event | 2026 CHI Conference on Human Factors in Computing Systems, CHI 2026 - Barcelona, Spain Duration: 13 Apr 2026 → 17 Apr 2026 |
Publication series
| Name | Conference on Human Factors in Computing Systems - Proceedings |
|---|
Conference
| Conference | 2026 CHI Conference on Human Factors in Computing Systems, CHI 2026 |
|---|---|
| Country/Territory | Spain |
| City | Barcelona |
| Period | 13/04/26 → 17/04/26 |
Bibliographical note
Publisher Copyright:© 2026 Copyright held by the owner/author(s).
Funding
The work was partly supported by the Nederlandse Organisatie voor Wetenschappelijk Onderzoek (NWO) under grant n. NWA.1215.18.006 (Theseus), the European Union (EU) under Horizon Europe grant n. 101120393 (Sec4AI4Sec), and by the Nederlandse Organisatie voor Wetenschappelijk Onderzoek (NWO) under grant n. KIC1.VE01.20.004 (HEWSTI), the Dutch sectorplan, NSERC Discovery Grant n. RGPIN-2020-04734, NSERC Alliance Grant n. ALLRP 558365-20, and by the Network Institute, Vrije Universiteit Amsterdam through the Research Visits program. We thank anonymous reviewers for their helpful feedback. We thank Siu Hong (Thomas) Tam for conducting the pilot study
| Funders | Funder number |
|---|---|
| European Commission | |
| HEWSTI | |
| Natural Sciences and Engineering Research Council of Canada | RGPIN-2020-04734, ALLRP 558365-20 |
| HORIZON EUROPE Framework Programme | KIC1.VE01.20.004, 101120393 |
| Nederlandse Organisatie voor Wetenschappelijk Onderzoek | NWA.1215.18.006 |
Keywords
- CVE
- CVSS
- Human-computer Interaction
- NLP
- User Study
Fingerprint
Dive into the research topics of 'Tool-Assisted CVSS Vulnerability Scoring: A Controlled Quantitative Study of Human Assessment'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver