English

Automated Compliance Mapping in Cloud Security with Domain-Adapted Sentence Transformers

Computation and Language 2026-07-07 v1 Cryptography and Security

Abstract

Mapping cloud security controls to technical metrics is currently a manual process. This paper proposes domain adaptation of Sentence Transformer models to automate it. We build a training corpus of 3,499 semantic pairs from five European security standards and a set of technical metrics, then expand it via back-translation and LLM-based paraphrasing to up to 13,996 samples across four scenarios. We fine-tune five architectures and evaluate their performance on two independent tasks: control-to-metric and cross-standard controls association. All fine-tuned models outperform their zero-shot baselines. On the control-to-metric task, the best model gains up to 23 nDCG@10 points, while on the cross-standard control task, \textit{multi-qa-mpnet-dot-v1} under back-translation reaches 0.870 nDCG@10. The results show that in-domain training data is a primary driver of performance for the considered case studies.

Cite

@article{arxiv.2607.06364,
  title  = {Automated Compliance Mapping in Cloud Security with Domain-Adapted Sentence Transformers},
  author = {John Bianchi and Luca Petrillo and Fabio Martinelli and Marinella Petrocchi},
  journal= {arXiv preprint arXiv:2607.06364},
  year   = {2026}
}

Comments

10 pages, 6 figures. Submitted to the 30th International Conference on Knowledge-Based and Intelligent Information & Engineering Systems (KES 2026)