Fetching the paper…
Reading the bibliography…
Many ML-based approaches have been proposed to automatically detect, localize, and repair software vulnerabilities.
CVSS (2003) Common vulnerability scoring system (cvss). https://nvd.nist.gov/vuln-metrics/cvss
2003
Earlier work this paper cites.
Checkmarx (2006) Checkmarx. https://checkmarx.com/
2006
Earlier work this paper cites.
CWE (2006) Common weakness enumeration (cwe). https://cwe.mitre.org/index.html
2006
Earlier work this paper cites.
Marjamäki D (2007) Cppcheck. https://cppcheck.sourceforge.io/
2007
Earlier work this paper cites.
Kitchenham BA, Pfleeger SL (2008) Personal opinion surveys. In: Guide to Advanced Empirical Software Engineering, Springer, pp 63–92
2008
Earlier work this paper cites.
CWE (2009) Cwe-787. https://cwe.mitre.org/data/definitions/787.html
2009
Earlier work this paper cites.
Johnson A, Dempsey K, Ross R, Gupta S, Bailey D, et al (2011) Guide for security-focused configuration management of information systems. NIST special publication 800(128):16–16
2011
Earlier work this paper cites.
Shuai B, Li H, Li M, Zhang Q, Tang C (2013) Automatic classification for vulnerability based on machine learning. In: 2013 IEEE International Conference on Information and Automation (ICIA), IEEE, pp 312–318
2013
Earlier work this paper cites.
Na S, Kim T, Kim H (2016) A study on the classification of common vulnerabilities and exposures using naïve bayes. In: International Conference on Broadband and Wireless Computing, Communication and Applications, Springer, pp 657–662
2016
Earlier work this paper cites.
Tantithamthavorn C, McIntosh S, Hassan AE, Matsumoto K (2016) Automated Parameter Optimization of Classification Techniques for Defect Prediction Models. In: ICSE, pp 321–332
2016
Earlier work this paper cites.
Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez AN, Kaiser Ł, Polosukhin I (2017) Attention is all you need. In: Advances in neural information processing systems (NeurIPS), pp 5998–6008
2017
Earlier work this paper cites.
Chen Z, Badrinarayanan V, Lee CY, Rabinovich A (2018) Gradnorm: Gradient normalization for adaptive loss balancing in deep multitask networks. In: International conference on machine learning, PMLR, pp 794–803
2018
Earlier work this paper cites.
Kendall A, Gal Y, Cipolla R (2018) Multi-task learning using uncertainty to weigh losses for scene geometry and semantics. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 7482–7491
2018
Earlier work this paper cites.
Loshchilov I, Hutter F (2018) Decoupled weight decay regularization. In: International Conference on Learning Representations
2018
Earlier work this paper cites.
Renaud A (2018) A vulnerable c function. https://github.com/AndreRenaud/PDFGen/commit/8f9b3202f67feb386c9974520d9bcc4531350fff
2018
Earlier work this paper cites.
Sener O, Koltun V (2018) Multi-task learning as multi-objective optimization. Advances in neural information processing systems 31
2018
Earlier work this paper cites.
Spanos G, Angelis L (2018) A multi-target approach to estimate software vulnerability characteristics and severity scores. Journal of Systems and Software 146:152–166
2018
Earlier work this paper cites.
Devlin J, Chang MW, Lee K, Toutanova K (2019) Bert: Pre-training of deep bidirectional transformers for language understanding. In: Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers), pp 4171–4186
2019
Earlier work this paper cites.
Gong X, Xing Z, Li X, Feng Z, Han Z (2019) Joint prediction of multiple vulnerability characteristics through multi-task learning. In: 2019 24th International Conference on Engineering of Complex Computer Systems (ICECCS), IEEE, pp 31–40
2019
Earlier work this paper cites.
Nguyen V, Le T, Le T, Nguyen K, DeVel O, Montague P, Qu L, Phung D (2019) Deep domain adaptation for vulnerable code function identification. In: The International Joint Conference on Neural Networks (IJCNN)
2019
Earlier work this paper cites.
NVD (2019) Cvss version 3.1. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
2019
Earlier work this paper cites.
Tantithamthavorn C, McIntosh S, Hassan AE, Matsumoto K (2019) The Impact of Automated Parameter Optimization on Defect Prediction Models. TSE
2019
Earlier work this paper cites.
WhiteSource (2019) What are the most secure programming languages? https://www.mend.io/most-secure-programming-languages/
2019
Cited alongside, same era.
Zhou Y, Liu S, Siow J, Du X, Liu Y (2019) Devign: effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In: Proceedings of the 33rd International Conference on Neural Information Processing Systems, pp 10,197–10,207
2019
Cited alongside, same era.
Aghaei E, Shadid W, Al-Shaer E (2020) Threatzoom: Hierarchical neural network for cves to cwes classification. In: International Conference on Security and Privacy in Communication Systems, Springer, pp 23–41
2020
Cited alongside, same era.
Aota M, Kanehara H, Kubo M, Murata N, Sun B, Takahashi T (2020) Automation of vulnerability classification from its description using machine learning. In: 2020 IEEE Symposium on Computers and Communications (ISCC), IEEE, pp 1–7
2020
Cited alongside, same era.
Pornprasit C, Tantithamthavorn C (2021) JITLine: A Simpler, Better, Faster, Finer-grained Just-In-Time Defect Prediction. In: Proceedings of the International Conference on Mining Software Repositories (MSR)
2021
Later among the works it cites.
Pornprasit C, Tantithamthavorn C, Jiarpakdee J, Fu M, Thongtanunam P (2021) Pyexplainer: Explaining the predictions of just-in-time defect models. In: 2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE), IEEE, pp 407–418
2021
Later among the works it cites.
Rajapaksha D, Tantithamthavorn C, Bergmeir C, Buntine W, Jiarpakdee J, Grundy J (2021) Sqaplanner: Generating data-informed software quality improvement plans. IEEE Transactions on Software Engineering
2021
Later among the works it cites.
Tantithamthavorn C, Jiarpakdee J, Grundy J (2021) Actionable analytics: Stop telling me what it is; please tell me what to do. IEEE Software 38(4):115–120
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Fan J, Li Y, Wang S, Nguyen TN (2020) A c/c++ code vulnerability dataset with code changes and cve summaries. In: Proceedings of the 17th International Conference on Mining Software Repositories, pp 508–512
2020
Cited alongside, same era.
Feng Z, Guo D, Tang D, Duan N, Feng X, Gong M, Shou L, Qin B, Liu T, Jiang D, et al (2020) Codebert: A pre-trained model for programming and natural languages. In: Findings of the Association for Computational Linguistics: EMNLP 2020, pp 1536–1547
2020
Cited alongside, same era.
Jiarpakdee J, Tantithamthavorn C, Dam HK, Grundy J (2020) An Empirical Study of Model-Agnostic Techniques for Defect Prediction Models. IEEE Transactions on Software Engineering (TSE) p To Appear
2020
Cited alongside, same era.
Khanan C, Luewichana W, Pruktharathikoon K, Jiarpakdee J, Tantithamthavorn C, Choetkiertikul M, Ragkhitwetsagul C, Sunetnanta T (2020) Jitbot: An explainable just-in-time defect prediction bot. In: 2020 35th IEEE/ACM International Conference on Automated Software Engineering (ASE), IEEE, pp 1336–1339
2020
Cited alongside, same era.
Nguyen V, Le T, De Vel O, Montague P, Grundy J, Phung D (2020) Dual-component deep domain adaptation: A new approach for cross project software vulnerability detection. Pacific-Asia Conference on Knowledge Discovery and Data Mining
2020
Cited alongside, same era.
Wang X, Wang S, Sun K, Batcheller A, Jajodia S (2020) A machine learning approach to classify security patches into vulnerability types. In: 2020 IEEE Conference on Communications and Network Security (CNS), IEEE, pp 1–9
2020
Cited alongside, same era.
Wattanakriengkrai S, Thongtanunam P, Tantithamthavorn C, Hata H, Matsumoto K (2020) Predicting defective lines using a model-agnostic technique. IEEE Transactions on Software Engineering (TSE)
2020
Cited alongside, same era.
Babalau I, Corlatescu D, Grigorescu O, Sandescu C, Dascalu M (2021) Severity prediction of software vulnerabilities based on their text description. In: 2021 23rd International Symposium on Symbolic and Numeric Algorithms for Scientific Computing (SYNASC), IEEE, pp 171–177
2021
Cited alongside, same era.
Tantithamthavorn CK, Jiarpakdee J (2021) Explainable ai for software engineering. In: 2021 36th IEEE/ACM International Conference on Automated Software Engineering (ASE), IEEE, pp 1–2
2021
Later among the works it cites.
Touvron H, Cord M, Douze M, Massa F, Sablayrolles A, Jégou H (2021) Training data-efficient image transformers & distillation through attention. In: International Conference on Machine Learning, PMLR, pp 10,347–10,357
2021
Later among the works it cites.
Wang T, Qin S, Chow KP (2021) Towards vulnerability types classification using pure self-attention: A common weakness enumeration based approach. In: 2021 IEEE 24th International Conference on Computational Science and Engineering (CSE), IEEE, pp 146–153
2021
Later among the works it cites.
Corporation TM (2022) Att&ck. https://attack.mitre.org/
2022
Later among the works it cites.
Fu M, Tantithamthavorn C (2022b) Linevul: A transformer-based line-level vulnerability prediction. In: 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR), IEEE
2022
Later among the works it cites.
Fu M, Tantithamthavorn C, Le T, Nguyen V, Dinh P (2022) Vulrepair: A t5-based automated software vulnerability repair. In: In the Proceedings of the ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE)
2022
Later among the works it cites.
Hin D, Kan A, Chen H, Babar MA (2022) Linevd: Statement-level vulnerability detection using graph neural networks. In: 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR), IEEE
2022
Later among the works it cites.
Liu Y, Tantithamthavorn C, Li L, Liu Y (2022) Explainable AI for android malware detection: Towards understanding why the models perform so well? In: IEEE 33rd International Symposium on Software Reliability Engineering, ISSRE 2022, Charlotte, NC, USA, October 31 - Nov. 3, 2022, IEEE, pp 169–180, DOI 10.1109/ISSRE55969.2022.00026
2022
Later among the works it cites.
Pornprasit C, Tantithamthavorn C (2022) DeepLineDP: Towards a Deep Learning Approach for Line-Level Defect Prediction. IEEE Transactions on Software Engineering
2022
Later among the works it cites.
Takerngsaksiri W, Tantithamthavorn C, Li YF (2022) Syntax-aware on-the-fly code completion. arXiv preprint arXiv:221104673
2022
Later among the works it cites.
Thapa C, Jang SI, Ahmed ME, Camtepe S, Pieprzyk J, Nepal S (2022) Transformer-based language models for software vulnerability detection: Performance, model’s security and platforms. arXiv preprint arXiv:220403214
2022
Later among the works it cites.
Yuan X, Lin G, Tai Y, Zhang J (2022) Deep neural embedding for software vulnerability discovery: Comparison and optimization. Security and Communication Networks 2022
2022
Later among the works it cites.
Zettler K (2022) The devsecop tools that secure devops workflows. https://www.redhat.com/en/topics/devops/what-is-devsecops
2022
Later among the works it cites.
Zhu C, Du G, Wu T, Cui N, Chen L, Shi G (2022) Bert-based vulnerability type identification with effective program representation. In: Wireless Algorithms, Systems, and Applications: 17th International Conference, WASA 2022, Dalian, China, November 24–26, 2022, Proceedings, Part I, Springer, pp 271–282
2022
Later among the works it cites.
Cito J, Chandra S, Tantithamthavorn C, Hemmati H (2023) Expert perspectives on explainability. IEEE Software 40(3):84–88, DOI 10.1109/MS.2023.3255663
2023
Closest in time.
Liu Y, Tantithamthavorn C, Li L, Liu Y (2023) Deep learning for android malware defenses: A systematic literature review. ACM Comput Surv 55(8):153:1–153:36, DOI 10.1145/3544968
2023
Closest in time.
Tantithamthavorn C, Cito J, Hemmati H, Chandra S (2023) Explainable ai for se: Challenges and future directions. IEEE Software 40(3):29–33, DOI 10.1109/MS.2023.3246686
2023
Closest in time.