VulnTrain
VulnTrain offers a suite of commands to generate diverse AI datasets and train models using comprehensive vulnerability data from Vulnerability-Lookup. It harnesses over one million JSON records from all supported advisory sources (CVE, GitHub advisories, CSAF, PySecDB, CNVD) to build high-quality, domain-specific models.
Additionally, data from the vulnerability-lookup:meta container, including enrichment sources such as vulnrichment and Fraunhofer FKIE,
is incorporated to enhance model quality.
Check out the datasets and models on Hugging Face:
For more information about the use of AI in Vulnerability-Lookup, please refer to the user manual.
Installation
pipx install VulnTrain
For development:
git clone https://github.com/vulnerability-lookup/VulnTrain.git
cd VulnTrain/
poetry install
Usage
Three types of commands are available:
- Dataset generation: Create and prepare datasets from vulnerability sources.
- Model training: Train models using the prepared datasets.
- Model validation: Assess the performance of trained models (validations, benchmarks, etc.).
CLI commands
| Command | Purpose |
|---|---|
vulntrain-dataset-generation |
Generate datasets from vulnerability sources |
vulntrain-train-severity-classification |
Train severity classifier (RoBERTa/DistilBERT) |
vulntrain-train-severity-cnvd-classification |
Train severity classifier for CNVD data |
vulntrain-train-description-generation |
Train GPT-2 vulnerability description generator |
vulntrain-train-cwe-classification |
Train CWE classifier from patches |
vulntrain-validate-severity-classification |
Validate severity model |
vulntrain-validate-text-generation |
Validate text generation model |
Models
Distributed training on HPC clusters
VulnTrain supports distributed multi-GPU training via SLURM, making it suitable for EuroHPC-style GPU clusters. See the HPC documentation for Conda environment setup, single-node and multi-node SLURM job scripts, and NCCL configuration.
Documentation
Check out the full documentation for detailed usage instructions, dataset generation examples, and training recipes.
How to cite
For the severity classification work:
Bonhomme, C., & Dulaunoy, A. (2025). VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification (Version 1.4.0) [Computer software]. https://doi.org/10.48550/arXiv.2507.03607
@misc{bonhomme2025vlai,
title={VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification},
author={Cédric Bonhomme and Alexandre Dulaunoy},
year={2025},
eprint={2507.03607},
archivePrefix={arXiv},
primaryClass={cs.CR}
}
For the ATT&CK technique mapping work:
Bonhomme, C., & Dulaunoy, A. (2026). Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion. https://doi.org/10.48550/arXiv.2607.25572
@misc{bonhomme2026mappingcvesmitreattck,
title={Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion},
author={Cédric Bonhomme and Alexandre Dulaunoy},
year={2026},
eprint={2607.25572},
archivePrefix={arXiv},
primaryClass={cs.CR},
url={https://arxiv.org/abs/2607.25572},
}
License
VulnTrain is licensed under GNU General Public License version 3
Copyright (c) 2025-2026 Computer Incident Response Center Luxembourg (CIRCL)
Copyright (C) 2025-2026 Cédric Bonhomme - https://github.com/cedricbonhomme
Copyright (C) 2025 Léa Ulusan - https://github.com/3LS3-1F
Release files for VulnTrain 3.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vulntrain-3.2.0.tar.gz | 78.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vulntrain-3.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 173.6 kB
Release files / vulntrain-3.2.0.tar.gz
| Download URL | vulntrain-3.2.0.tar.gz |
|---|---|
| Size | 78.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
71684df587f6fa9985bcf4e503912123a608c0736bee26ad125da8d226841e86
|
|
BLAKE2b-256 checksum How to use checksums |
7191f36325a6371c44dd117b2baad8c6ff40f8344905789f3567a054ffe84df0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 6, 2026.
Transparency logRelease files / vulntrain-3.2.0-py3-none-any.whl
| Download URL | vulntrain-3.2.0-py3-none-any.whl |
|---|---|
| Size | 95.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
840c1815d291e2cac26c4b55adc795d33e63b2e99a9a6b37e7483848a2544360
|
|
BLAKE2b-256 checksum How to use checksums |
21c0feab78099fa673a8202890e1d6a9326737b99c2b8a9082a806fcb3bb3bd1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 6, 2026.
Transparency log