Fetching the paper…
Reading the bibliography…
Various approaches are proposed to help under-resourced security researchers to detect and analyze software vulnerabilities.
T. Brown, B. Mann, N. Ryder, M. Subbiah, J. D. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell et al. , “Language models are few-shot learners,” in the Advances in Neural Information Processing Systems , vol. 33, 2020, pp. 1877–1901
1901
Earlier work this paper cites.
M. Dowd, J. McDonald, and J. Schuh, The art of software security assessment: Identifying and preventing software vulnerabilities . Pearson Education, 2006
2006
Earlier work this paper cites.
T. Parr and K. Fisher, “Ll (*) the foundation of the antlr parser generator,” in the 32nd ACM SIGPLAN Conference on Programming Language Design and Implementation , 2011, pp. 425–436
2011
Earlier work this paper cites.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in the 3rd International Conference on Learning Representations , 2015, pp. 1–15
2015
Earlier work this paper cites.
Z. Qi, F. Long, S. Achour, and M. Rinard, “An analysis of patch plausibility and correctness for generate-and-validate patch generation systems,” in the 2015 International Symposium on Software Testing and Analysis , 2015, pp. 24–36
2015
Earlier work this paper cites.
M. Böhme, V.-T. Pham, and A. Roychoudhury, “Coverage-based greybox fuzzing as markov chain,” in 2016 ACM SIGSAC Conference on Computer and Communications Security , 2016, pp. 1032–1043
2016
Earlier work this paper cites.
C. Tantithamthavorn, S. McIntosh, A. E. Hassan, and K. Matsumoto, “Automated parameter optimization of classification techniques for defect prediction models,” in the 38th International Conference on Software Engineering , 2016, pp. 321–332
2016
Earlier work this paper cites.
F. Li and V. Paxson, “A large-scale empirical study of security patches,” in the 2017 ACM SIGSAC Conference on Computer and Communications Security , 2017, pp. 2201–2215
2017
Earlier work this paper cites.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” Advances in neural information processing systems , 2017
2017
Earlier work this paper cites.
H. Yan, Y. Sui, S. Chen, and J. Xue, “Spatio-temporal context reduction: A pointer-analysis-based static approach for detecting use-after-free vulnerabilities,” in 2018 IEEE/ACM 40th International Conference on Software Engineering , 2018, pp. 327–337
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
T. Ben-Nun, A. S. Jakobovits, and T. Hoefler, “Neural code comprehension: A learnable representation of code semantics,” Advances in Neural Information Processing Systems , vol. 31, 2018
2018
Earlier work this paper cites.
J. Yi, S. H. Tan, S. Mechtaev, M. Böhme, and A. Roychoudhury, “A correlation study between automated program repair and test-suite metrics,” Empirical Software Engineering , vol. 23, no. 5, pp. 2948–2979, 2018
2018
Earlier work this paper cites.
M. Shahzad, M. Z. Shafiq, and A. X. Liu, “Large scale characterization of software vulnerability life cycles,” IEEE Transactions on Dependable and Secure Computing , vol. 17, no. 4, pp. 730–744, 2019
2019
Earlier work this paper cites.
B. Belleville, W. Shen, S. Volckaert, A. M. Azab, and M. Franz, “Kald: Detecting direct pointer disclosure vulnerabilities,” IEEE Transactions on Dependable and Secure Computing , vol. 18, no. 3, pp. 1369–1377, 2019
2019
Earlier work this paper cites.
R. Duan, A. Bijlani, Y. Ji, O. Alrawi, Y. Xiong, M. Ike, B. Saltaformaggio, and W. Lee, “Automating patching of vulnerable open-source software versions in application binaries.” in 26th Annual Network and Distributed System Security Symposium , 2019
2019
Earlier work this paper cites.
Z. Chen, S. Kommrusch, M. Tufano, L.-N. Pouchet, D. Poshyvanyk, and M. Monperrus, “Sequencer: Sequence-to-sequence learning for end-to-end program repair,” IEEE Transactions on Software Engineering , vol. 47, no. 9, pp. 1943–1959, 2019
2019
Earlier work this paper cites.
A. Radford, J. Wu, R. Child, D. Luan, D. Amodei, and I. Sutskever, “Language models are unsupervised multitask learners,” 2019
2019
Earlier work this paper cites.
M. Tufano, C. Watson, G. Bavota, M. D. Penta, M. White, and D. Poshyvanyk, “An empirical study on learning bug-fixing patches in the wild via neural machine translation,” ACM Transactions on Software Engineering and Methodology , vol. 28, no. 4, pp. 1–29, 2019
2019
Earlier work this paper cites.
J. Zhang, X. Wang, H. Zhang, H. Sun, K. Wang, and X. Liu, “A novel neural source code representation based on abstract syntax tree,” in 2019 IEEE/ACM 41st International Conference on Software Engineering . IEEE, 2019, pp. 783–794
2019
Earlier work this paper cites.
Y. Li, S. Wang, T. N. Nguyen, and S. Van Nguyen, “Improving bug detection via context-based code representation learning and attention-based neural networks,” the ACM on Programming Languages , vol. 3, no. OOPSLA, pp. 1–30, 2019
2019
Earlier work this paper cites.
B. Liu, G. Meng, W. Zou, Q. Gong, F. Li, M. Lin, D. Sun, W. Huo, and C. Zhang, “A large-scale empirical study on vulnerability distribution within projects and the lessons learned,” in 2020 IEEE/ACM 42nd International Conference on Software Engineering , 2020, pp. 1547–1559
2020
Earlier work this paper cites.
Z. Feng, D. Guo, D. Tang, N. Duan, X. Feng, M. Gong, L. Shou, B. Qin, T. Liu, D. Jiang et al. , “Codebert: A pre-trained model for programming and natural languages,” in Findings of the Association for Computational Linguistics , 2020, pp. 1536–1547
2020
Earlier work this paper cites.
Y. Movahedi, M. Cukier, and I. Gashi, “Predicting the discovery pattern of publically known exploited vulnerabilities,” IEEE Transactions on Dependable and Secure Computing , 2020
2020
Cited alongside, same era.
C. Raffel, N. Shazeer, A. Roberts, K. Lee, S. Narang, M. Matena, Y. Zhou, W. Li, and P. J. Liu, “Exploring the limits of transfer learning with a unified text-to-text transformer,” Journal of Machine Learning Research , vol. 21, pp. 1–67, 2020
2020
Cited alongside, same era.
T. Brown, B. Mann, N. Ryder, M. Subbiah, J. D. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell et al. , “Language models are few-shot learners,” Advances in neural information processing systems , vol. 33, pp. 1877–1901, 2020
2020
Cited alongside, same era.
C. Raffel, N. Shazeer, A. Roberts, K. Lee, S. Narang, M. Matena, Y. Zhou, W. Li, and P. J. Liu, “Exploring the limits of transfer learning with a unified text-to-text transformer,” The Journal of Machine Learning Research , vol. 21, no. 1, pp. 5485–5551, 2020
X. Zhu, S. Wen, S. Camtepe, and Y. Xiang, “Fuzzing: a survey for roadmap,” ACM Computing Surveys , vol. 54, no. 11s, pp. 1–36, 2022
2022
Later among the works it cites.
Y. Zhang, X. Gao, G. J. Duck, and A. Roychoudhury, “Program vulnerability repair via inductive inference,” in the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis , 2022, pp. 691–702
2022
Later among the works it cites.
“Security Magazine: Average time to fix security software vulnerabilities,” site: https://www.securitymagazine.com/articles/95929-average-time-to-fix-severe-vulnerabilities-is-256-days , 2022, Lasted accessed November 20, 2022
2022
Later among the works it cites.
Z. Chen, S. J. Kommrusch, and M. Monperrus, “Neural transfer learning for repairing security vulnerabilities in c code,” IEEE Transactions on Software Engineering , 2022
2022
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2020
Cited alongside, same era.
J. Fan, Y. Li, S. Wang, and T. N. Nguyen, “A c/c++ code vulnerability dataset with code changes and cve summaries,” in the 17th International Conference on Mining Software Repositories , 2020, pp. 508–512
2020
Cited alongside, same era.
G. Ye, Z. Tang, H. Wang, D. Fang, J. Fang, S. Huang, and Z. Wang, “Deep program structure modeling through multi-relational graph-based learning,” in the ACM International conference on parallel architectures and compilation techniques , 2020, pp. 111–123
2020
Cited alongside, same era.
Z. Li, D. Zou, S. Xu, Z. Chen, Y. Zhu, and H. Jin, “Vuldeelocator: a deep learning-based fine-grained vulnerability detector,” IEEE Transactions on Dependable and Secure Computing , 2021
2021
Cited alongside, same era.
S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep learning based vulnerability detection: Are we there yet,” IEEE Transactions on Software Engineering , 2021
2021
Cited alongside, same era.
X. Gao, B. Wang, G. J. Duck, R. Ji, Y. Xiong, and A. Roychoudhury, “Beyond tests: Program vulnerability repair via crash constraint extraction,” ACM Transactions on Software Engineering and Methodology , vol. 30, no. 2, pp. 1–27, 2021
2021
Cited alongside, same era.
Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, and Z. Chen, “Sysevr: A framework for using deep learning to detect software vulnerabilities,” IEEE Transactions on Dependable and Secure Computing , 2021
2021
Cited alongside, same era.
Y. Wang, W. Wang, S. Joty, and S. C. Hoi, “Codet5: Identifier-aware unified pre-trained encoder-decoder models for code understanding and generation,” in the 2021 Conference on Empirical Methods in Natural Language Processing , 2021, pp. 8696–8708
2021
Cited alongside, same era.
2021
Cited alongside, same era.
2022
Later among the works it cites.
“ 2022 CWE Top 25 Most Dangerous Software Weaknesses
2022
Later among the works it cites.
M. Fu, C. Tantithamthavorn, T. Le, V. Nguyen, and D. Phung, “Vulrepair: a t5-based automated software vulnerability repair,” in the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2022, pp. 935–947
2022
Later among the works it cites.
Y. Noller, R. Shariffdeen, X. Gao, and A. Roychoudhury, “Trust enhancement issues in program repair,” in the 44th International Conference on Software Engineering , 2022, pp. 2228–2240
2022
Later among the works it cites.
“ SpotBugs: Find bugs in Java Programs
2022
Later among the works it cites.
2022
Later among the works it cites.
J. Chi, Y. Qu, T. Liu, Q. Zheng, and H. Yin, “Seqtrans: Automatic vulnerability fix via sequence to sequence learning,” IEEE Transactions on Software Engineering , 2022
2022
Later among the works it cites.
D. Guo, S. Lu, N. Duan, Y. Wang, M. Zhou, and J. Yin, “Unixcoder: Unified cross-modal pre-training for code representation,” in the 60th Annual Meeting of the Association for Computational Linguistics , 2022, pp. 7212–7225
2022
Later among the works it cites.
“ PyTorch
2022
Later among the works it cites.
“ Hugging Face
2022
Later among the works it cites.
W. Yuan, Q. Zhang, T. He, C. Fang, N. Q. V. Hung, X. Hao, and H. Yin, “Circle: Continual repair across programming languages,” in the 31th ACM SIGSOFT International Symposium on Software Testing and Analysis , 2022, pp. 427–438
2022
Later among the works it cites.
R. Tufano, S. Masiero, A. Mastropaolo, L. Pascarella, D. Poshyvanyk, and G. Bavota, “Using pre-trained models to boost code review automation,” in the 44th International Conference on Software Engineering , 2022, pp. 2291–2302
2022
Later among the works it cites.
Q. Zhang and B. Yu, “ Replication Package
2023
Closest in time.
2023
Closest in time.
OpenAI, “Chatgpt: Optimizing language models for dialogue,” https://openai.com/blog/chatgpt , 2023, Lasted accessed 2023-05-01
2023
Closest in time.
2023
Closest in time.
H. Pearce, B. Tan, B. Ahmad, R. Karri, and B. Dolan-Gavitt, “Examining zero-shot vulnerability repair with large language models,” in 2023 IEEE Symposium on Security and Privacy , 2023, pp. 1–18
2023
Closest in time.
Q. Zhang, C. Fang, T. Zhang, W. Sun, B. Yu, and Z. Chen, “Gamma: Revisiting template-based automated program repair via mask prediction,” in Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering , 2023, pp. 1–13
2023
Closest in time.