Fetching the paper…
Reading the bibliography…
Security vulnerability repair is a difficult task that is in dire need of automation.
Exploring the Limits of Transfer Learning with a Unified Text-to-Text Transformer
Colin Raffel, Noam Shazeer, Adam Roberts, Katherine Lee, Sharan Narang, Michael Matena, Yanqi Zhou, Wei Li, and Peter J. Liu. 2019 · 1910
Earlier work this paper cites.
CodeBERT: A Pre-Trained Model for Programming and Natural Languages
Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, Daxin Jiang, and Ming Zhou. 2020 · 2002
Earlier work this paper cites.
Language Models are Few-Shot Learners
Tom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, Sandhini Agarwal, Ariel Herbert-Voss, Gretchen Krueger, Tom Henighan, Rewon Child, Aditya Ramesh, Daniel M. Ziegler, Jeffrey Wu, Clemens Winter, Christopher Hesse, Mark Chen, Eric Sigler, Mateusz Litwin, Scott Gray, Benjamin Chess, Jack Clark, Christopher Berner, Sam McCandlish, Alec Radford, Ilya Sutskever, and Dario Amodei. 2020 · 2005
Earlier work this paper cites.
Countering network worms through automatic patch generation
Stelios Sidiroglou and Angelos D Keromytis. 2005 · 2005
Earlier work this paper cites.
AutoPaG: towards automated software patch generation with source code root cause identification and repair. In Proceedings of the 2nd ACM symposium on Information, computer and communications security . 329–340
Zhiqiang Lin, Xuxian Jiang, Dongyan Xu, Bing Mao, and Li Xie. 2007 · 2007
Earlier work this paper cites.
GraphCodeBERT: Pre-training Code Representations with Data Flow
Daya Guo, Shuo Ren, Shuai Lu, Zhangyin Feng, Duyu Tang, Shujie Liu, Long Zhou, Nan Duan, Alexey Svyatkovskiy, Shengyu Fu, Michele Tufano, Shao Kun Deng, Colin B. Clement, Dawn Drain, Neel Sundaresan, Jian Yin, Daxin Jiang, and Ming Zhou. 2020 · 2009
Earlier work this paper cites.
Automatically patching errors in deployed software. In Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles . 87–102
Jeff H Perkins, Sunghun Kim, Sam Larsen, Saman Amarasinghe, Jonathan Bachrach, Michael Carbin, Carlos Pacheco, Frank Sherwood, Stelios Sidiroglou, Greg Sullivan, et al · 2009
Earlier work this paper cites.
Juliet 1. 1 C/C++ and java test suite
Tim Boland and Paul E Black. 2012 · 2012
Earlier work this paper cites.
Defects4J: A database of existing faults to enable controlled testing studies for Java programs. In Proceedings of the 2014 International Symposium on Software Testing and Analysis . 437–440
René Just, Darioush Jalali, and Michael D Ernst. 2014 · 2014
Earlier work this paper cites.
Diagnosis and emergency patch generation for integer overflow exploits. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment . Springer, 255–275
Tielei Wang, Chengyu Song, and Wenke Lee. 2014 · 2014
Earlier work this paper cites.
Safe memory-leak fixing for c programs. In 2015 IEEE/ACM 37th IEEE International Conference on Software Engineering , Vol. 1. IEEE, 459–470
Qing Gao, Yingfei Xiong, Yaqing Mi, Lu Zhang, Weikun Yang, Zhaoping Zhou, Bing Xie, and Hong Mei. 2015 · 2015
Earlier work this paper cites.
Fuzzbomb: Autonomous cyber vulnerability detection and repair. In Fourth International Conference on Communications, Computation, Networks and Technologies
David J Musliner, SE Friedman, M Boldt, J Benton, M Schuchard, P Keller, and S McCamant. 2015 · 2015
Earlier work this paper cites.
Online defect prediction for imbalanced data. In 2015 IEEE/ACM 37th IEEE International Conference on Software Engineering , Vol. 2. IEEE, 99–108
Ming Tan, Lin Tan, Sashank Dara, and Caleb Mayeux. 2015 · 2015
Earlier work this paper cites.
Cdrep: Automatic repair of cryptographic misuses in android applications. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security . 711–722
Siqi Ma, David Lo, Teng Li, and Robert H Deng. 2016 · 2016
Earlier work this paper cites.
A novel approach for software vulnerability classification. In 2017 Annual Reliability and Maintainability Symposium (RAMS) . IEEE, 1–7
Xiaodan Li, Xiaolin Chang, John A Board, and Kishor S Trivedi. 2017 · 2017
Earlier work this paper cites.
QuixBugs: A multi-lingual program repair benchmark set based on the Quixey Challenge. In Proceedings Companion of the 2017 ACM SIGPLAN international conference on systems, programming, languages, and applications: software for humanity . 55–56
Derrick Lin, James Koppel, Angela Chen, and Armando Solar-Lezama. 2017 · 2017
Earlier work this paper cites.
Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, Lukasz Kaiser, and Illia Polosukhin. 2017 · 2017
Earlier work this paper cites.
The mayhem cyber reasoning system
Thanassis Avgerinos, David Brumley, John Davis, Ryan Goulden, Tyler Nighswander, Alex Rebert, and Ned Williamson. 2018 · 2018
Earlier work this paper cites.
Memfix: static analysis-based repair of memory deallocation errors for c. In 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering . 95–106
Junhee Lee, Seongjoon Hong, and Hakjoo Oh. 2018 · 2018
Earlier work this paper cites.
Are vulnerabilities discovered and resolved like other defects?
Patrick J Morrison, Rahul Pandita, Xusheng Xiao, Ram Chillarege, and Laurie Williams. 2018 · 2018
Earlier work this paper cites.
Bugs. jar: a large-scale, diverse dataset of real-world java bugs. In Proceedings of the 15th international conference on mining software repositories . 10–13
Ripon K Saha, Yingjun Lyu, Wing Lam, Hiroaki Yoshida, and Mukul R Prasad. 2018 · 2018
Earlier work this paper cites.
Sequencer: Sequence-to-sequence learning for end-to-end program repair
Zimin Chen, Steve Kommrusch, Michele Tufano, Louis-Noël Pouchet, Denys Poshyvanyk, and Martin Monperrus. 2019 · 2019
Earlier work this paper cites.
Using safety properties to generate vulnerability patches. In 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 539–554
Zhen Huang, David Lie, Gang Tan, and Trent Jaeger. 2019 · 2019
Earlier work this paper cites.
Bears: An extensible java bug benchmark for automatic program repair studies. In 2019 IEEE 26th International Conference on Software Analysis, Evolution and Reengineering (SANER) . IEEE, 468–478
Fernanda Madeiral, Simon Urli, Marcelo Maia, and Martin Monperrus. 2019 · 2019
Earlier work this paper cites.
Intrepair: Informed repairing of integer overflows
Paul Muntean, Martin Monperrus, Hao Sun, Jens Grossklags, and Claudia Eckert. 2019 · 2019
Earlier work this paper cites.
A manually-curated dataset of fixes to vulnerabilities of open-source software. In 2019 IEEE/ACM 16th International Conference on Mining Software Repositories (MSR) . IEEE, 383–387
Serena Elisa Ponta, Henrik Plate, Antonino Sabetta, Michele Bezzi, and Cédric Dangremont. 2019 · 2019
Cited alongside, same era.
Language Models are Unsupervised Multitask Learners
Alec Radford, Jeff Wu, Rewon Child, David Luan, Dario Amodei, and Ilya Sutskever. 2019 · 2019
Cited alongside, same era.
Do we train on test data? purging cifar of near-duplicates
Björn Barz and Joachim Denzler. 2020 · 2020
Cited alongside, same era.
Hoppity: Learning Graph Transformations to Detect and Fix Bugs in Programs. In 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26-30, 2020 . OpenReview.net
Elizabeth Dinella, Hanjun Dai, Ziyang Li, Mayur Naik, Le Song, and Ke Wang. 2020 · 2020
Cited alongside, same era.
AC/C++ code vulnerability dataset with code changes and CVE summaries. In Proceedings of the 17th International Conference on Mining Software Repositories . 508–512
Neural Transfer Learning for Repairing Security Vulnerabilities in C Code
Zimin Chen, Steve James Kommrusch, and Martin Monperrus. 2022 · 2022
Later among the works it cites.
GitHub Copilot AI pair programmer: Asset or Liability?
Arghavan Moradi Dakhel, Vahid Majdinasab, Amin Nikanjam, Foutse Khomh, Michel C Desmarais, Zhen Ming, et al · 2022
Later among the works it cites.
AI-Driven Development Is Here: Should You Worry?
Neil A Ernst and Gabriele Bavota. 2022 · 2022
Later among the works it cites.
Improving automatically generated code from Codex via Automated Program Repair
Zhiyu Fan, Xiang Gao, Abhik Roychoudhury, and Shin Hwei Tan. 2022 · 2022
Later among the works it cites.
The robots are coming: Exploring the implications of openai codex on introductory programming. In Australasian Computing Education Conference . 10–19
James Finnie-Ansley, Paul Denny, Brett A Becker, Andrew Luxton-Reilly, and James Prather. 2022 · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Jiahao Fan, Yi Li, Shaohua Wang, and Tien N Nguyen. 2020 · 2020
Cited alongside, same era.
CoCoNuT: Combining Context-Aware Neural Translation Models Using Ensemble for Program Repair. In ISSTA (Virtual Event, USA). ACM, 101–114
Thibaud Lutellier, Hung Viet Pham, Lawrence Pang, Yitong Li, Moshi Wei, and Lin Tan. 2020 · 2020
Cited alongside, same era.
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
Accessed: 2022 · 2021
Cited alongside, same era.
Understanding the Impact of Apache Log4j Vulnerability
Accessed: 2023 · 2021
Cited alongside, same era.
Unified Pre-training for Program Understanding and Generation. In Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies . Association for Computational Linguistics, Online, 2655–2668
Wasi Ahmad, Saikat Chakraborty, Baishakhi Ray, and Kai-Wei Chang. 2021 · 2021
Cited alongside, same era.
CVEfixes: automated collection of vulnerabilities and their fixes from open-source software. In Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering . 30–39
Guru Bhandari, Amara Naseer, and Leon Moonen. 2021 · 2021
Cited alongside, same era.
GPT-Neo: Large Scale Autoregressive Language Modeling with Mesh-Tensorflow
Sid Black, Gao Leo, Phil Wang, Connor Leahy, and Stella Biderman. 2021 · 2021
Cited alongside, same era.
Evaluating Large Language Models Trained on Code
Mark Chen, Jerry Tworek, Heewoo Jun, Qiming Yuan, Henrique Ponde de Oliveira Pinto, Jared Kaplan, Harrison Edwards, Yuri Burda, Nicholas Joseph, Greg Brockman, Alex Ray, Raul Puri, Gretchen Krueger, Michael Petrov, Heidy Khlaaf, Girish Sastry, Pamela Mishkin, Brooke Chan, Scott Gray, Nick Ryder, Mikhail Pavlov, Alethea Power, Lukasz Kaiser, Mohammad Bavarian, Clemens Winter, Philippe Tillet, Felipe Petroski Such, Dave Cummings, Matthias Plappert, Fotios Chantzis, Elizabeth Barnes, Ariel Herbert-Voss, William Hebgen Guss, Alex Nichol, Alex Paino, Nikolas Tezak, Jie Tang, Igor Babuschkin, Suchir Balaji, Shantanu Jain, William Saunders, Christopher Hesse, Andrew N. Carr, Jan Leike, Joshua Achiam, Vedant Misra, Evan Morikawa, Alec Radford, Matthew Knight, Miles Brundage, Mira Murati, Katie Mayer, Peter Welinder, Bob McGrew, Dario Amodei, Sam McCandlish, Ilya Sutskever, and Wojciech Zaremba. 2021 · 2021
Cited alongside, same era.
Later among the works it cites.
InCoder: A Generative Model for Code Infilling and Synthesis
Daniel Fried, Armen Aghajanyan, Jessy Lin, Sida Wang, Eric Wallace, Freda Shi, Ruiqi Zhong, Wen-tau Yih, Luke Zettlemoyer, and Mike Lewis. 2022 · 2022
Later among the works it cites.
VulRepair: A T5-Based Automated Software Vulnerability Repair
Michael Fu, Chakkrit Tantithamthavorn, Trung Le, Van Nguyen, and Dinh Phung. 2022 · 2022
Later among the works it cites.
The Race to the Vulnerable: Measuring the Log4j Shell Incident. In Network Traffic Measurement and Analysis Conference (TMA)
Raphael Hiesgen, Marcin Nawrocki, Thomas C Schmidt, and Matthias Wählisch. 2022 · 2022
Later among the works it cites.
Repairing Security Vulnerabilities Using Pre-trained Programming Language Models. In 2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W) . IEEE, 111–116
Kai Huang, Su Yang, Hongyu Sun, Chengyi Sun, Xuejun Li, and Yuqing Zhang. 2022 · 2022
Later among the works it cites.
Is GitHub Copilot a Substitute for Human Pair-programming? An Empirical Study. In 2022 IEEE/ACM 44th International Conference on Software Engineering: Companion Proceedings (ICSE-Companion) . IEEE, 319–321
Saki Imai. 2022 · 2022
Later among the works it cites.
The Potential of Artificial Intelligence as a Method of Software Developer’s Productivity Improvement. In 2022 Conference of Russian Young Researchers in Electrical and Electronic Engineering (ElConRus) . IEEE, 386–390
Ekaterina A Moroz, Vladimir O Grizkevich, and Igor M Novozhilov. 2022 · 2022
Later among the works it cites.
A conversational paradigm for program synthesis
Erik Nijkamp, Bo Pang, Hiroaki Hayashi, Lifu Tu, Huan Wang, Yingbo Zhou, Silvio Savarese, and Caiming Xiong. 2022 · 2022
Later among the works it cites.
Trust Enhancement Issues in Program Repair. In Proceedings of the ACM/IEEE 44th International Conference on Software Engineering
Yannic Noller, Ridwan Shariffdeen, Xiang Gao, and Abhik Roychoudhury. 2022 · 2022
Later among the works it cites.
Maestro: a platform for benchmarking automatic program repair tools on software vulnerabilities. In International Symposium on Software Testing and Analysis . 789–792
Eduard Pinconschi, Quang-Cuong Bui, Rui Abreu, Pedro Adão, and Riccardo Scandariato. 2022 · 2022
Later among the works it cites.
Can OpenAI’s Codex Fix Bugs?: An evaluation on QuixBugs. In 2022 IEEE/ACM International Workshop on Automated Program Repair (APR) . IEEE, 69–75
Julian Aron Prenner, Hlib Babii, and Romain Robbes. 2022 · 2022
Later among the works it cites.
Playing Games with Ais: The Limits of GPT-3 and Similar Large Language Models
Adam Sobieszek and Tadeusz Price. 2022 · 2022
Later among the works it cites.
Practical Program Repair in the Era of Large Pre-trained Language Models
Chunqiu Steven Xia, Yuxiang Wei, and Lingming Zhang. 2022 · 2022
Later among the works it cites.
Neural program repair with execution-based backpropagation. In 2022 IEEE/ACM 44th International Conference on Software Engineering (ICSE) . IEEE, 1506–1518
He Ye, Matias Martinez, and Martin Monperrus. 2022 · 2022
Later among the works it cites.
NLTK Documentation
Accessed: 2023 · 2023
Closest in time.
NVD Data Feeds
Accessed: 2023 · 2023
Closest in time.
Replication package of this work
Accessed: 2023 · 2023
Closest in time.
src2abs GitHub Repository
Accessed: 2023 · 2023
Closest in time.
KNOD: Domain Knowledge Distilled Tree Decoder for Automated Program Repair. In Proceedings of the International Conference on Software Engineering
Nan Jiang, Thibaud Lutellier, Yiling Lou, Lin Tan, Dan Goldwasser, and Xiangyu Zhang. 2023b · 2023
Closest in time.
Examining Zero-Shot Vulnerability Repair with Large Language Models. In 2023 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 1–18
Hammond Pearce, Benjamin Tan, Baleegh Ahmad, Ramesh Karri, and Brendan Dolan-Gavitt. 2022 · 2023
Closest in time.