Fetching the paper…
Reading the bibliography…
The use of learning-based techniques to achieve automated software vulnerability detection has been of longstanding interest within the software security domain.
M. G. Kendall, “A new measure of rank correlation,” Biometrika , vol. 30, no. 1/2, pp. 81–93, 1938
1938
Earlier work this paper cites.
H. B. Mann and D. R. Whitney, “On a test of whether one of two random variables is stochastically larger than the other,” The annals of mathematical statistics , pp. 50–60, 1947
1947
Earlier work this paper cites.
J. Cohen, “A coefficient of agreement for nominal scales,” Educational and psychological measurement , vol. 20, no. 1, pp. 37–46, 1960
1960
Earlier work this paper cites.
G. McGraw, “Software security,” IEEE Security & Privacy , vol. 2, no. 2, pp. 80–83, 2004
2004
Earlier work this paper cites.
B. Fuglede and F. Topsoe, “Jensen-shannon divergence and hilbert space embedding,” in International Symposium onInformation Theory, 2004. ISIT 2004. Proceedings. IEEE, 2004, p. 31
2004
Earlier work this paper cites.
V. Braun and V. Clarke, “Using thematic analysis in psychology,” Qualitative research in psychology , vol. 3, no. 2, pp. 77–101, 2006
2006
Earlier work this paper cites.
W. G. Cochran, Sampling techniques . John Wiley & Sons, 2007
2007
Earlier work this paper cites.
ISO/IEC, “Systems and software engineering – systems and software quality requirements and evaluation (square) – data quality model,” 2008
2008
Earlier work this paper cites.
G. M. Weinberg, Perfect Software and other illusions about testing . Dorset House Pub., 2008
2008
Earlier work this paper cites.
T. Zimmermann, N. Nagappan, and L. Williams, “Searching for a needle in a haystack: Predicting security vulnerabilities for windows vista,” in 2010 Third International Conference on Software Testing, Verification and Validation . IEEE, 2010, pp. 421–428
2010
Earlier work this paper cites.
S. Kim, H. Zhang, R. Wu, and L. Gong, “Dealing with noise in defect prediction,” in 2011 33rd international conference on software engineering (ICSE) . IEEE, 2011, pp. 481–490
2011
Earlier work this paper cites.
H. Shahriar and M. Zulkernine, “Mitigating program security vulnerabilities: Approaches and challenges,” ACM Computing Surveys (CSUR) , vol. 44, no. 3, pp. 1–46, 2012
2012
Earlier work this paper cites.
F. Sidi, P. H. S. Panahy, L. S. Affendey, M. A. Jabar, H. Ibrahim, and A. Mustapha, “Data quality: A survey of data quality dimensions,” in 2012 International Conference on Information Retrieval & Knowledge Management . IEEE, 2012, pp. 300–304
2012
Earlier work this paper cites.
T. Boland and P. E. Black, “Juliet 1.1 c/c++ and java test suite,” IEEE Computer Architecture Letters , vol. 45, no. 10, pp. 88–90, 2012
2012
Earlier work this paper cites.
S. Moshtari, A. Sami, and M. Azimi, “Using complexity metrics to improve software security,” Computer Fraud & Security , vol. 2013, no. 5, pp. 8–17, 2013
2013
Earlier work this paper cites.
M. F. Bosu and S. G. MacDonell, “A taxonomy of data quality challenges in empirical software engineering,” in 2013 22nd Australian Software Engineering Conference . IEEE, 2013, pp. 97–106
2013
Earlier work this paper cites.
K. Herzig, S. Just, and A. Zeller, “It’s not a bug, it’s a feature: how misclassification impacts bug prediction,” in 2013 35th international conference on software engineering (ICSE) . IEEE, 2013, pp. 392–401
2013
Earlier work this paper cites.
M. Shepperd, Q. Song, Z. Sun, and C. Mair, “Data quality: Some comments on the nasa software defect datasets,” IEEE Transactions on Software Engineering , vol. 39, no. 9, pp. 1208–1215, 2013
2013
Earlier work this paper cites.
K. Herzig and A. Zeller, “The impact of tangled code changes,” in 2013 10th Working Conference on Mining Software Repositories (MSR) . IEEE, 2013, pp. 121–130
2013
Earlier work this paper cites.
J. Gama, I. Žliobaitė, A. Bifet, M. Pechenizkiy, and A. Bouchachia, “A survey on concept drift adaptation,” ACM computing surveys (CSUR) , vol. 46, no. 4, pp. 1–37, 2014
2014
Earlier work this paper cites.
P. Morrison, K. Herzig, B. Murphy, and L. Williams, “Challenges with applying vulnerability prediction models,” in Proceedings of the 2015 Symposium and Bootcamp on the Science of Security , 2015, pp. 1–9
2015
Earlier work this paper cites.
G. Liebchen and M. Shepperd, “Data sets and data quality in software engineering: Eight years on,” in Proceedings of the The 12th International Conference on Predictive Models and Data Analytics in Software Engineering , 2016, pp. 1–4
2016
Earlier work this paper cites.
K. Herzig, S. Just, and A. Zeller, “The impact of tangled code changes on defect prediction models,” Empirical Software Engineering , vol. 21, no. 2, pp. 303–336, 2016
2016
Earlier work this paper cites.
H. Sajnani, V. Saini, J. Svajlenko, C. K. Roy, and C. V. Lopes, “Sourcerercc: Scaling code clone detection to big-code,” in Proceedings of the 38th International Conference on Software Engineering , 2016, pp. 1157–1168
2016
Earlier work this paper cites.
H. Sanders and J. Saxe, “Garbage in, garbage out: how purportedly great ml models can be screwed up by bad data,” Proceedings of Blackhat , vol. 2017, 2017
2017
Cited alongside, same era.
S. M. Ghaffarian and H. R. Shahriari, “Software vulnerability analysis and discovery using machine-learning and data-mining techniques: A survey,” ACM Computing Surveys (CSUR) , vol. 50, no. 4, pp. 1–36, 2017
2017
Cited alongside, same era.
S. McIntosh and Y. Kamei, “Are fix-inducing changes a moving target? a longitudinal case study of just-in-time defect prediction,” IEEE Transactions on Software Engineering , vol. 44, no. 5, pp. 412–428, 2017
2017
Cited alongside, same era.
2018
Cited alongside, same era.
H. Hanif, M. H. N. M. Nasir, M. F. Ab Razak, A. Firdaus, and N. B. Anuar, “The rise of software vulnerability: Taxonomy of software vulnerabilities detection and machine learning approaches,” Journal of Network and Computer Applications , p. 103009, 2021
2021
Later among the works it cites.
A. Anwar, A. Abusnaina, S. Chen, F. Li, and D. Mohaisen, “Cleaning the nvd: Comprehensive quality assessment, improvements, and analyses,” IEEE Transactions on Dependable and Secure Computing , 2021
2021
Later among the works it cites.
X. Wu, W. Zheng, X. Xia, and D. Lo, “Data quality matters: A case study on data label correctness for security bug report prediction,” IEEE Transactions on Software Engineering , 2021
2021
Later among the works it cites.
F. Gualo, M. Rodríguez, J. Verdugo, I. Caballero, and M. Piattini, “Data quality certification using iso/iec 25012: Industrial experiences,” Journal of Systems and Software , vol. 176, p. 110938, 2021
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
R. Russell, L. Kim, L. Hamilton, T. Lazovich, J. Harer, O. Ozdemir, P. Ellingwood, and M. McConley, “Automated vulnerability detection in source code using deep representation learning,” in 2018 17th IEEE international conference on machine learning and applications (ICMLA) . IEEE, 2018, pp. 757–762
2018
Cited alongside, same era.
Y. Zhou, S. Liu, J. Siow, X. Du, and Y. Liu, “Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks,” Advances in neural information processing systems , vol. 32, 2019
2019
Cited alongside, same era.
A. Vogelsang and M. Borg, “Requirements engineering for machine learning: Perspectives from data scientists,” in 2019 IEEE 27th International Requirements Engineering Conference Workshops (REW) . IEEE, 2019, pp. 245–251
2019
Cited alongside, same era.
M. Jimenez, R. Rwemalika, M. Papadakis, F. Sarro, Y. Le Traon, and M. Harman, “The importance of accounting for real-world labelling when predicting software vulnerabilities,” in Proceedings of the 2019 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2019, pp. 695–705
2019
Cited alongside, same era.
M. Allamanis, “The adverse effects of code duplication in machine learning models of code,” in Proceedings of the 2019 ACM SIGPLAN International Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software , 2019, pp. 143–153
2019
Cited alongside, same era.
2019
Cited alongside, same era.
Q. U. Ain, W. H. Butt, M. W. Anwar, F. Azam, and B. Maqbool, “A systematic review on code clone detection,” IEEE access , vol. 7, pp. 86 121–86 144, 2019
2019
Cited alongside, same era.
V. Piantadosi, S. Scalabrino, and R. Oliveto, “Fixing of security vulnerabilities in open source projects: A case study of apache http server and apache tomcat,” in 2019 12th IEEE Conference on software testing, validation and verification (ICST) . IEEE, 2019, pp. 68–78
2019
Cited alongside, same era.
S. Nakajima and T. Nakatani, “Ai extension of square data quality model,” in 2021 IEEE 21st International Conference on Software Quality, Reliability and Security Companion (QRS-C) . IEEE, 2021, pp. 306–313
2021
Later among the works it cites.
A. Sejfia, Y. Zhao, and N. Medvidović, “Identifying casualty changes in software patches,” in Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2021, pp. 304–315
2021
Later among the works it cites.
Y. Zhao, L. Li, H. Wang, H. Cai, T. F. Bissyandé, J. Klein, and J. Grundy, “On the impact of sample duplication in machine-learning-based android malware detection,” ACM Transactions on Software Engineering and Methodology (TOSEM) , vol. 30, no. 3, pp. 1–38, 2021
2021
Later among the works it cites.
M. Fu and C. Tantithamthavorn, “Linevul: A transformer-based line-level vulnerability prediction,” in 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR) , 2022, pp. 608–620
2022
Later among the works it cites.
2022
Later among the works it cites.
R. Croft, Y. Xie, and M. A. Babar, “Data preparation for software vulnerability prediction: A systematic literature review,” IEEE Transactions on Software Engineering , 2022
2022
Later among the works it cites.
2022
Later among the works it cites.
Y. Nong, Y. Ou, M. Pradel, F. Chen, and H. Cai, “Generating realistic vulnerabilities via neural code editing: an empirical study,” in Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2022, pp. 1097–1109
2022
Later among the works it cites.
D. Arp, E. Quiring, F. Pendlebury, A. Warnecke, F. Pierazzi, C. Wressnegger, L. Cavallaro, and K. Rieck, “Dos and don’ts of machine learning in computer security,” in Proc. of the USENIX Security Symposium , 2022
2022
Later among the works it cites.
2022
Later among the works it cites.
L. Shi, F. Mu, X. Chen, S. Wang, J. Wang, Y. Yang, G. Li, X. Xia, and Q. Wang, “Are we building on the rock? on the importance of data preprocessing for code summarization,” in Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2022, pp. 107–119
2022
Later among the works it cites.
2022
Later among the works it cites.
A. Sotgiu, M. Pintor, and B. Biggio, “Explainability-based debugging of machine learning for vulnerability discovery,” in Proceedings of the 17th International Conference on Availability, Reliability and Security , 2022, pp. 1–8
2022
Later among the works it cites.
Z. Sun, L. Li, Y. Liu, X. Du, and L. Li, “On the importance of building high-quality training datasets for neural code search,” in Proceedings of the 44th International Conference on Software Engineering , 2022, pp. 1609–1620
2022
Later among the works it cites.
S. Herbold, A. Trautsch, B. Ledel, A. Aghamohammadi, T. A. Ghaleb, K. K. Chahal, T. Bossenmaier, B. Nagaria, P. Makedonski, M. N. Ahmadabadi et al. , “A fine-grained data set and analysis of tangling in bug fixing commits,” Empirical Software Engineering , vol. 27, no. 6, pp. 1–49, 2022
2022
Later among the works it cites.
R. Croft, M. A. Babar, and L. Li, “An investigation into inconsistency of software vulnerability severity across data sources,” in 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) . IEEE, 2022, pp. 338–348
2022
Later among the works it cites.
A. D. Sawadogo, T. F. Bissyandé, N. Moha, K. Allix, J. Klein, L. Li, and Y. Le Traon, “Sspcatcher: Learning to catch security patches,” Empirical Software Engineering , vol. 27, no. 6, pp. 1–32, 2022
2022
Later among the works it cites.
2022
Later among the works it cites.
R. Croft, M. A. Babar, and M. Kholoosi, “Reproduction package for “data quality for software vulnerability datasets”,” 2023. [Online]. Available: https://figshare.com/articles/software/Reproduction_Package_for_Data_Quality_for_Software_Vulnerability_Datasets_/20499924
2023
Closest in time.