Fetching the paper…
Reading the bibliography…
Automatically detecting software vulnerabilities in source code is an important problem that has attracted much attention.
D. Whitfield and M. L. Soffa, “An approach for exploring code-improving transformations,” ACM Trans. Program. Lang. Syst. , vol. 19, no. 6, pp. 1053–1084, 1997
1997
Earlier work this paper cites.
J. Viega, J. T. Bloch, Y. Kohno, and G. McGraw, “ITS4: A static vulnerability scanner for C and C++ code,” in Proceedings of the 16th Annual Computer Security Applications Conference (ACSAC), New Orleans, Louisiana, USA , 2000, pp. 257–267
2000
Earlier work this paper cites.
G. Kniesel and H. Koch, “Static composition of refactorings,” Sci. Comput. Program. , vol. 52, pp. 9–51, 2004
2004
Earlier work this paper cites.
S. Neuhaus, T. Zimmermann, C. Holler, and A. Zeller, “Predicting vulnerable software components,” in Proceedings of 2007 ACM Conference on Computer and Communications Security (CCS), Alexandria, Virginia, USA , 2007, pp. 529–540
2007
Earlier work this paper cites.
C. K. Roy and J. R. Cordy, “A mutation/injection-based automatic framework for evaluating code clone detection tools,” in Proceedings of the 2nd International Conference on Software Testing Verification and Validation (ICST), Denver, Colorado, USA , 2009, pp. 157–166
2009
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. I. P. Rubinstein, and J. D. Tygar, “Adversarial machine learning,” in Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence (AISec), Chicago, IL, USA , 2011, pp. 43–58
2011
Earlier work this paper cites.
J. Jang, A. Agrawal, and D. Brumley, “ReDeBug: Finding unpatched code clones in entire OS distributions,” in Proceedings of 2012 IEEE Symposium on Security and Privacy (S&P), San Francisco, California, USA , 2012, pp. 48–62
2012
Earlier work this paper cites.
F. Yamaguchi, M. Lottmann, and K. Rieck, “Generalized vulnerability extrapolation using abstract syntax trees,” in Proceedings of the 28th Annual Computer Security Applications Conference (ACSAC), Orlando, FL, USA , 2012, pp. 359–368
2012
Earlier work this paper cites.
C. Kartsaklis, O. R. Hernandez, C. Hsu, T. Ilsche, W. Joubert, and R. L. Graham, “HERCULES: A pattern driven code transformation system,” in Proceedings of the 26th IEEE International Parallel and Distributed Processing Symposium Workshops & PhD Forum, Shanghai, China , 2012, pp. 574–583
2012
Earlier work this paper cites.
Synopsys, “The heartbleed bug,” https://heartbleed.com/ , 2014
2014
Earlier work this paper cites.
F. Yamaguchi, A. Maier, H. Gascon, and K. Rieck, “Automatic inference of search patterns for taint-style vulnerabilities,” in Proceedings of 2015 IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA , 2015, pp. 797–812
2015
Earlier work this paper cites.
F. Yamaguchi, “Pattern-based vulnerability discovery,” Ph.D. dissertation, University of Göttingen, 2015
2015
Earlier work this paper cites.
Z. Li, D. Zou, S. Xu, H. Jin, H. Qi, and J. Hu, “VulPecker: An automated vulnerability detection system based on code similarity analysis,” in Proceedings of the 32nd Annual Conference on Computer Security Applications (ACSAC), Los Angeles, CA, USA , 2016, pp. 201–213
2016
Earlier work this paper cites.
B. Shastry, F. Yamaguchi, K. Rieck, and J. Seifert, “Towards vulnerability discovery using staged program analysis,” in Proceedings of the 13th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), San Sebastián, Spain , 2016, pp. 78–97
2016
Earlier work this paper cites.
G. Grieco, G. L. Grinblat, L. C. Uzal, S. Rawat, J. Feist, and L. Mounier, “Toward large-scale vulnerability discovery using machine learning,” in Proceedings of the 6th ACM on Conference on Data and Application Security and Privacy (CODASPY), New Orleans, LA, USA , 2016, pp. 85–96
2016
Earlier work this paper cites.
M. Böhme, V. Pham, M. Nguyen, and A. Roychoudhury, “Directed greybox fuzzing,” in Proceedings of 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS), Dallas, TX, USA , 2017, pp. 2329–2344
2017
Earlier work this paper cites.
S. Kim, S. Woo, H. Lee, and H. Oh, “VUDDY: A scalable approach for vulnerable code clone discovery,” in Proceedings of 2017 IEEE Symposium on Security and Privacy (S&P), San Jose, CA, USA , 2017, pp. 595–614
2017
Earlier work this paper cites.
G. Lin, J. Zhang, W. Luo, L. Pan, and Y. Xiang, “POSTER: Vulnerability discovery with function representation learning from unlabeled projects,” in Proceedings of 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS), Dallas, TX, USA , 2017, pp. 2539–2541
2017
Earlier work this paper cites.
M. Pendleton, R. Garcia-Lebron, J. Cho, and S. Xu, “A survey on systems security metrics,” ACM Comput. Surv. , vol. 49, no. 4, pp. 62:1–62:35, 2017
2017
Earlier work this paper cites.
J. M. P. Cardoso, J. G. de Figueiredo Coutinho, and P. C. Diniz, Embedded Computing for High Performance: Efficient Mapping of Computations Using Customization, Code Transformations and Compilation . Morgan Kaufmann, 2017
2017
Earlier work this paper cites.
S. Ko, J. Choi, and H. Kim, “COAT: Code obfuscation tool to evaluate the performance of code plagiarism detection tools,” in Proceedings of 2017 International Conference on Software Security and Assurance (ICSSA), Altoona, PA, USA , 2017, pp. 32–37
2017
Earlier work this paper cites.
“Compromised npm package: event-stream,” https://medium.com/intrinsic/compromised-npm-package-event-stream-d47d08605502 , 2018
2018
Earlier work this paper cites.
S. Gan, C. Zhang, X. Qin, X. Tu, K. Li, Z. Pei, and Z. Chen, “CollAFL: Path sensitive fuzzing,” in Proceedings of 2018 IEEE Symposium on Security and Privacy (S&P), San Francisco, California, USA , 2018, pp. 679–696
2018
Earlier work this paper cites.
D. Gens, S. Schmitt, L. Davi, and A. Sadeghi, “K-Miner: Uncovering memory corruption in linux,” in Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS), San Diego, California, USA , 2018
2018
Earlier work this paper cites.
Z. Li, D. Zou, S. Xu, X. Ou, H. Jin, S. Wang, Z. Deng, and Y. Zhong, “VulDeePecker: A deep learning-based system for vulnerability detection,” in Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS), San Diego, California, USA , 2018
2018
Earlier work this paper cites.
G. Lin, J. Zhang, W. Luo, L. Pan, Y. Xiang, O. Y. de Vel, and P. Montague, “Cross-project transfer representation learning for vulnerable function discovery,” IEEE Trans. Industrial Informatics , vol. 14, no. 7, pp. 3289–3297, 2018
2018
Earlier work this paper cites.
R. L. Russell, L. Y. Kim, L. H. Hamilton, T. Lazovich, J. Harer, O. Ozdemir, P. M. Ellingwood, and M. W. McConley, “Automated vulnerability detection in source code using deep representation learning,” in Proceedings of the 17th IEEE International Conference on Machine Learning and Applications (ICMLA), Orlando, FL, USA , 2018, pp. 757–762
2018
Cited alongside, same era.
2018
Cited alongside, same era.
J. Harer, O. Ozdemir, T. Lazovich, C. P. Reale, R. L. Russell, L. Y. Kim, and S. P. Chin, “Learning to repair software vulnerabilities with generative adversarial networks,” in Proceedings of 2018 Annual Conference on Neural Information Processing Systems (NeurIPS), Montréal, Canada , 2018, pp. 7944–7954
2018
Cited alongside, same era.
“Stunnix C/C++ obfuscator,” http://stunnix.com , 2019
2019
Later among the works it cites.
“Sourceformatx,” http://www.sourceformat.com/obfuscate-code-cpp.htm , 2019
2019
Later among the works it cites.
“Coccinelle,” http://coccinelle.lip6.fr/ , 2019
2019
Later among the works it cites.
A. Shafahi, M. Najibi, A. Ghiasi, Z. Xu, J. P. Dickerson, C. Studer, L. S. Davis, G. Taylor, and T. Goldstein, “Adversarial training for free!” in Proceedings of 2019 Annual Conference on Neural Information Processing Systems (NeurIPS), Vancouver, BC, Canada , 2019, pp. 3353–3364
2019
Later among the works it cites.
J. Li, S. Ji, T. Du, B. Li, and T. Wang, “TextBugger: Generating adversarial text against real-world applications,” in Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS), San Diego, California, USA , 2019
2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
M. Fowler, Refactoring: Improving the Design of Existing Code . Addison-Wesley Professional, 2018
2018
Cited alongside, same era.
J. A. Dallal and A. Abdin, “Empirical evaluation of the impact of object-oriented code refactoring on quality attributes: A systematic literature review,” IEEE Trans. Software Eng. , vol. 44, no. 1, pp. 44–69, 2018
2018
Cited alongside, same era.
O. M. Mirza, “Style analysis for source code plagiarism detection,” Ph.D. dissertation, University of Warwick, Coventry, UK, 2018
2018
Cited alongside, same era.
V. J. M. Manès, H. Han, C. Han, S. K. Cha, M. Egele, E. J. Schwartz, and M. Woo, “The art, science, and engineering of fuzzing: A survey,” IEEE Trans. Software Eng. , 2019
2019
Cited alongside, same era.
“Flawfinder,” http://www.dwheeler.com/flawfinder , 2019
2019
Cited alongside, same era.
“Rough Audit Tool for Security,” https://code.google.com/archive/p/rough-auditing-tool-for-security/ , 2019
2019
Cited alongside, same era.
“Checkmarx,” https://www.checkmarx.com/ , 2019
2019
Cited alongside, same era.
“Coverity,” https://scan.coverity.com/ , 2019
2019
Cited alongside, same era.
Later among the works it cites.
D. Li and Q. Li, “Enhancing robustness of deep neural networks against adversarial malware samples: Principles, framework, and application to aics’2019 challenge,” in Proceedings of the AAAI-19 Workshop on Artificial Intelligence for Cyber Security (AICS), Honolulu, Hawaii, USA , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
“Common Vulnerabilities and Exposures,” http://cve.mitre.org/ , 2020
2020
Later among the works it cites.
“Open Source Software Supply Chain Security,” https://linuxfoundation.org/wp-content/uploads/oss_supply_chain_security.pdf , 2020
2020
Later among the works it cites.
K. K. Ispoglou, D. Austin, V. Mohan, and M. Payer, “Fuzzgen: Automatic fuzzer generation,” in Proceedings of the 29th USENIX Security Symposium , 2020, pp. 2271–2287
2020
Later among the works it cites.
S. Liu, G. Lin, L. Qu, J. Zhang, O. De Vel, P. Montague, and Y. Xiang, “CD-VulD: Cross-domain vulnerability discovery based on deep domain adaptation,” IEEE Trans. Dependable Sec. Comput. , doi: 10.1109/TDSC.2020.2984505, 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
D. Li and Q. Li, “Adversarial deep ensemble: Evasion attacks and defenses for malware detection,” IEEE Trans. Inf. Forensics Secur. , vol. 15, pp. 3886–3900, 2020
2020
Later among the works it cites.
H. Zhang, Z. Li, G. Li, L. Ma, Y. Liu, and Z. Jin, “Generating adversarial examples for holding robustness of source code processing models,” in Proceedings of the 34th AAAI Conference on Artificial Intelligence (AAAI), New York, NY, USA , 2020, pp. 1169–1176
2020
Later among the works it cites.
“National Vulnerability Database,” https://nvd.nist.gov , 2020
2020
Later among the works it cites.
“Software Assurance Reference Dataset,” https://samate.nist.gov/SRD/index.php , 2020
2020
Later among the works it cites.
“Tigress,” https://tigress.wtf/ , 2020
2020
Later among the works it cites.
X. Gao, R. K. Saha, M. R. Prasad, and A. Roychoudhury, “Fuzz testing based data augmentation to improve robustness of deep neural networks,” in Proceedings of the 42nd International Conference on Software Engineering (ICSE), Seoul, South Korea , 2020, pp. 1147–1158
2020
Later among the works it cites.
Y. Zhang, A. Albarghouthi, and L. D’Antoni, “Robustness to programmable string transformations via augmented abstract training,” in Proceedings of the 37th International Conference on Machine Learning (ICML), Virtual Event , 2020, pp. 11 023–11 032
2020
Later among the works it cites.
Y. Chen, S. Wang, D. She, and S. Jana, “On training robust PDF malware classifiers,” in Proceedings of the 29th USENIX Security Symposium (USENIX Security) , 2020, pp. 2343–2360
2020
Later among the works it cites.
H. Zhang, Z. Li, G. Li, L. Ma, Y. Liu, and Z. Jin, “Generating adversarial examples for holding robustness of source code processing models,” in Proceedings of the 34th AAAI Conference on Artificial Intelligence (AAAI), New York, NY, USA , 2020, pp. 1169–1176
2020
Later among the works it cites.
P. Bielik and M. T. Vechev, “Adversarial robustness for code,” in Proceedings of the 37th International Conference on Machine Learning (ICML), Virtual Event , 2020, pp. 896–907
2020
Later among the works it cites.
N. Yefet, U. Alon, and E. Yahav, “Adversarial examples for models of code,” Proc. ACM Program. Lang. , vol. 4, no. OOPSLA, pp. 162:1–162:30, 2020
2020
Later among the works it cites.
Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, and Z. Chen, “SySeVR: A framework for using deep learning to detect software vulnerabilities,” IEEE Trans. Dependable Sec. Comput. , doi: 10.1109/TDSC.2021.3051525, 2021
2021
Closest in time.
H. Wang, G. Ye, Z. Tang, S. H. Tan, S. Huang, D. Fang, Y. Feng, L. Bian, and Z. Wang, “Combining graph-based learning with automated data collection for code vulnerability detection,” IEEE Trans. Inf. Forensics Secur. , vol. 16, pp. 1943–1958, 2021
2021
Closest in time.