SecMTL-BERT: A Multi-Task Transformer Framework for Unified Information Systems Security Text Intelligence
DOI:
https://doi.org/10.15849/ijasca.v18i2.133Keywords:
Cyber-Entity Recognition, Incident Classification, Information Systems Security, BERT, Recognition, Multi-Task Learning, TransformerAbstract
Security operations teams in modern organizations must process volumes of unstructured text incident tickets, threat-intelligence advisories, vulnerability bulletins, and audit logs that far exceed human capacity for manual review. Existing natural language processing (NLP) approaches address these tasks in isolation, requiring separate models and multiple inference passes that are computationally costly and fail to exploit the mutual information shared across related security-text tasks. We propose SecMTL-BERT, a unified multi-task transformer framework that simultaneously performs security incident classification, cyber-entity recognition (CyNER), and threat urgency scoring in a single forward pass. The central architectural innovation is a Cross-Task Attention (CTA) module that enables bidirectional feature sharing between the classification and entity-recognition heads, allowing each task to exploit complementary representations learned by the other. The shared encoder is initialized from BERT-base and subjected to domain-adaptive fine-tuning on a 2.3-million-document security corpus drawn from the National Vulnerability Database, CERT advisories, threat-intelligence reports, and anonymized enterprise SOC tickets. Experiments on three benchmark datasets SecIncident-9K, DNRTI, and ThreatUrgency-8K demonstrate that SecMTL-BERT achieves macro F1 scores of 92.6%, 89.5%, and 90.5% on the three tasks respectively, outperforming the strongest single-task baseline (SecBERT) by 5.7, 6.4, and 6.5 percentage points. Ablation experiments confirm that every architectural component contributes meaningfully to performance. SecMTL-BERT also reduces total inference time by 58.7% relative to running three separate SecBERT models, making real-time deployment in operational security settings feasible. These results have direct implications for IS security managers seeking to automate alert triage, threat intelligence extraction, and advisory prioritization at scale.
Downloads
All Downloads: 3
Link