SecMTL-BERT: A Multi-Task Transformer Framework for Unified Information Systems Security Text Intelligence
DOI:
https://doi.org/10.15849/ijasca.v18i2.133Keywords:
Cyber-Entity Recognition, Incident Classification, Information Systems Security, BERT, Recognition, Multi-Task Learning, TransformerAbstract
Security operations teams in modern organizations must process volumes of unstructured text incident tickets, threat-intelligence advisories, vulnerability bulletins, and audit logs that far exceed human capacity for manual review. Existing natural language processing (NLP) approaches address these tasks in isolation, requiring separate models and multiple inference passes that are computationally costly and fail to exploit the mutual information shared across related security-text tasks. We propose SecMTL-BERT, a unified multi-task transformer framework that simultaneously performs security incident classification, cyber-entity recognition (CyNER), and threat urgency scoring in a single forward pass. The central architectural innovation is a Cross-Task Attention (CTA) module that enables bidirectional feature sharing between the classification and entity-recognition heads, allowing each task to exploit complementary representations learned by the other. The shared encoder is initialized from BERT-base and subjected to domain-adaptive fine-tuning on a 2.3-million-document security corpus drawn from the National Vulnerability Database, CERT advisories, threat-intelligence reports, and anonymized enterprise SOC tickets. Experiments on three benchmark datasets SecIncident-9K, DNRTI, and ThreatUrgency-8K demonstrate that SecMTL-BERT achieves macro F1 scores of 92.6%, 89.5%, and 90.5% on the three tasks respectively, outperforming the strongest single-task baseline (SecBERT) by 5.7, 6.4, and 6.5 percentage points. Ablation experiments confirm that every architectural component contributes meaningfully to performance. SecMTL-BERT also reduces total inference time by 58.7% relative to running three separate SecBERT models, making real-time deployment in operational security settings feasible. These results have direct implications for IS security managers seeking to automate alert triage, threat intelligence extraction, and advisory prioritization at scale.
Downloads
All Downloads: 9
Downloads
Published
How to Cite
Issue
Section
Categories
License
Copyright © The Author(s).
Articles published in the International Journal of Advances in Soft Computing and its Applications (IJASCA) are licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) license.
This license permits anyone to copy, redistribute, remix, transform, and build upon the material for any purpose, including commercial use, provided appropriate credit is given to the original author(s), a link to the license is provided, and any modifications are indicated.
Authors retain the copyright of their published work and grant the journal right of first publication, with the work simultaneously licensed under the terms above.
Link