Fetching the paper…
Reading the bibliography…
Developers often build software on top of third-party libraries (Libs) to improve productivity, but these libraries may contain vulnerabilities that enable supply chain attacks.
Automatic discovery of api-level exploits
V. Ganapathy, S. A. Seshia, S. Jha, T. W. Reps, and R. E. Bryant · 2005
Earlier work this paper cites.
Revolutionizing the field of grey-box attack surface testing with evolutionary fuzzing
J. Demott, D. Richard, R. Enbody, D. William, and W. Punch · 2007
Earlier work this paper cites.
A survey of covert channels and countermeasures in computer network protocols
S. Zander, G. Armitage, and P. Branch · 2007
Earlier work this paper cites.
Automatic patch-based exploit generation is possible: Techniques and implications
D. Brumley, P. Poosankam, D. Song, and J. Zheng · 2008
Earlier work this paper cites.
Security test generation using threat trees
A. Marback, H. Do, K. He, S. Kondamarri, and D. Xu · 2009
Earlier work this paper cites.
Evosuite: automatic test suite generation for object-oriented software
G. Fraser and A. Arcuri · 2011
Earlier work this paper cites.
Unleashing mayhem on binary code
S. K. Cha, T. Avgerinos, A. Rebert, and D. Brumley · 2012
Earlier work this paper cites.
Sage: Whitebox fuzzing for security testing: Sage has had a remarkable impact at microsoft
P. Godefroid, M. Y. Levin, and D. Molnar · 2012
Earlier work this paper cites.
Automated security test generation with formal threat models
D. Xu, M. Tu, M. Sanford, L. Thomas, D. Woodraska, and W. Xu · 2012
Earlier work this paper cites.
The national vulnerability database (nvd): Overview
H. Booth, D. Rike, and G. A. Witte · 2013
Earlier work this paper cites.
Automatic exploit generation
T. Avgerinos, S. K. Cha, A. Rebert, E. J. Schwartz, M. Woo, and D. Brumley · 2014
Earlier work this paper cites.
Staged program repair with condition synthesis
F. Long and M. Rinard · 2015
Earlier work this paper cites.
Cognicrypt: supporting developers in using cryptography
S. Krüger, S. Nadi, M. Reif, K. Ali, M. Mezini, E. Bodden, F. Göpfert, F. Günther, C. Weinert, D. Demmler, et al · 2017
Earlier work this paper cites.
Vurle: Automatic vulnerability detection and repair by learning from examples
S. Ma, F. Thung, D. Lo, C. Sun, and R. H. Deng · 2017
Earlier work this paper cites.
Fuzzing for Software Security Testing and Quality Assurance, Second Edition
A. Takanen, J. Demott, C. Miller, and A. Kettunen · 2017
Earlier work this paper cites.
Ultra-large repair search space with automatically mined templates: The cardumen mode of astor
M. Martinez and M. Monperrus · 2018
Earlier work this paper cites.
Secure coding practices in Java: Challenges and vulnerabilities
N. Meng, S. Nagy, D. Yao, W. Zhuang, and G. A. Argoty · 2018
Earlier work this paper cites.
https://github.com/nearform/gammaray
GitHub - nearform / gammaray: Node.js vulnerability scanner · 2019
Earlier work this paper cites.
Detecting suspicious package updates
K. Garrett, G. Ferreira, L. Jia, J. Sunshine, and C. Kästner · 2019
Earlier work this paper cites.
Tbar: revisiting template-based automated program repair
K. Liu, A. Koyuncu, D. Kim, and T. F. Bissyandé · 2019
Earlier work this paper cites.
A manually-curated dataset of fixes to vulnerabilities of open-source software
S. E. Ponta, H. Plate, A. Sabetta, M. Bezzi, and C. Dangremont · 2019
Earlier work this paper cites.
Cryptoguard: High precision detection of cryptographic vulnerabilities in massive-sized Java projects
S. Rahaman, Y. Xiao, S. Afrose, F. Shaon, K. Tian, M. Frantz, M. Kantarcioglu, and D. Yao · 2019
Earlier work this paper cites.
https://owasp.org/www-project-dependency-check/
OWASP Dependency-Check · 2020
Earlier work this paper cites.
http://snyk.io/vuln
Snyk vulnerability database · 2020
Earlier work this paper cites.
Up2dep: Android tool support to fix insecure code dependencies
D. C. Nguyen, E. Derr, M. Backes, and S. Bugiel · 2020
Earlier work this paper cites.
Detection, assessment and mitigation of vulnerabilities in open source dependencies
S. E. Ponta, H. Plate, and A. Sabetta · 2020
Earlier work this paper cites.
Towards using source code repositories to identify software supply chain attacks
D. L. Vu, I. Pashchenko, F. Massacci, H. Plate, and A. Sabetta · 2020
Earlier work this paper cites.
ARJA: Automated Repair of Java Programs via Multi-Objective Genetic Programming
Y. Yuan and W. Banzhaf · 2020
Earlier work this paper cites.
https://techmonitor.ai/technology/cybersecurity/supply-chain-attacks-open-source-software-grew-650-percent-2021
Supply chain attacks on open source software grew 650% in 2021 · 2021
Earlier work this paper cites.
https://www.csoonline.com/article/3191947/supply-chain-attacks-show-why-you-should-be-wary-of-third-party-providers.html, 2021
Supply chain attacks show why you should be wary of third-party providers · 2021
Earlier work this paper cites.
Fusebmc: An energy-efficient test generator for finding security vulnerabilities in C programs
K. M. Alshmrany, M. Aldughaim, A. Bhayat, and L. C. Cordeiro · 2021
Earlier work this paper cites.
Toward automated exploit generation for known vulnerabilities in open-source libraries
E. Iannone, D. Di Nucci, A. Sabetta, and A. De Lucia · 2021
Earlier work this paper cites.
https://usa.kaspersky.com/blog/log4shell-still-active-2022/27531/
Log4Shell a year on · 2022
Earlier work this paper cites.
Vulrepair: a t5-based automated software vulnerability repair
M. Fu, C. Tantithamthavorn, T. Le, V. Nguyen, and D. Phung · 2022
Earlier work this paper cites.
How do developers follow security-relevant best practices when using npm packages?
M. M. A. Kabir, Y. Wang, D. Yao, and N. Meng · 2022
Earlier work this paper cites.
Test mimicry to assess the exploitability of library vulnerabilities
H. J. Kang, T. G. Nguyen, B. Le, C. S. Păsăreanu, and D. Lo · 2022
Cited alongside, same era.
Towards the detection of malicious Java packages
P. Ladisa, H. Plate, M. Martinez, O. Barais, and S. E. Ponta · 2022
Cited alongside, same era.
Bmc+fuzz: Efficient and effective test generation
R. Metta, R. K. Medicherla, and S. Chakraborty · 2022
Cited alongside, same era.
Asleep at the keyboard? assessing the security of github copilot’s code contributions
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri · 2022
Cited alongside, same era.
Swiftdependencychecker: Detecting vulnerable dependencies declared through cocoapods, carthage and swift pm
K. Rahkema and D. Pfahl · 2022
Cited alongside, same era.
Automatic detection of Java cryptographic api misuses: Are we there yet?
https://codehaus-plexus.github.io/plexus-archiver/index.html
Plexus Archiver Component · 2023
Closest in time.
https://retirejs.github.io/retire.js/
Retire.js · 2023
Closest in time.
https://github.com/sonatype-nexus-community/auditjs
sonatype-nexus-community / auditjs: Audits an NPM package.json file to identify known vulnerabilities · 2023
Closest in time.
https://github.com/spring-projects/spring-data-commons
spring-projects / spring-data-commons · 2023
Closest in time.
https://github.com/spring-projects/spring-security
spring-projects / spring-security · 2023
Closest in time.
https://github.com/srikanth-lingala/zip4j
srikanth-lingala / zip4j · 2023
Closest in time.
https://github.com/stleary/JSON-java
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Y. Zhang, M. M. A. Kabir, Y. Xiao, D. Yao, and N. Meng · 2022
Cited alongside, same era.
Example-based vulnerability detection and repair in Java code
Y. Zhang, Y. Xiao, M. M. A. Kabir, D. D. Yao, and N. Meng · 2022
Cited alongside, same era.
https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts
About Dependabot alerts · 2023
Cited alongside, same era.
https://github.com/alibaba/fastjson
alibaba / fastjson · 2023
Cited alongside, same era.
https://lcamtuf.coredump.cx/afl/
american fuzzy lop · 2023
Cited alongside, same era.
https://github.com/apache/commons-io
apache / commons-io · 2023
Cited alongside, same era.
https://github.com/apache/cxf
apache / cxf · 2023
Cited alongside, same era.
stleary / JSON-java · 2023
Closest in time.
https://docs.snyk.io/snyk-cli/commands/test
Test - Snyk User Docs · 2023
Closest in time.
https://www.bouncycastle.org
The Legion of the Bouncy Castle · 2023
Closest in time.
https://www.synopsys.com/glossary/what-is-fuzz-testing.html
What Is Fuzz Testing and How Does It Work? — Synopsys · 2023
Closest in time.
https://github.com/xerial/snappy-java
xerial / snappy-java · 2023
Closest in time.
https://x-stream.github.io
XStream · 2023
Closest in time.
https://github.com/zeroturnaround/zt-zip
ZT Zip · 2023
Closest in time.
Neural transfer learning for repairing security vulnerabilities in C code
Z. Chen, S. Kommrusch, and M. Monperrus · 2023
Closest in time.
Seqtrans: Automatic vulnerability fix via sequence to sequence learning
J. Chi, Y. Qu, T. Liu, Q. Zheng, and H. Yin · 2023
Closest in time.
Chatgpt and software testing education: Promises & perils
S. Jalil, S. Rafi, T. D. LaToza, K. Moran, and W. Lam · 2023
Closest in time.
Codamosa: Escaping coverage plateaus in test generation with pre-trained large language models
C. Lemieux, J. P. Inala, S. K. Lahiri, and S. Sen · 2023
Closest in time.
Comparing software developers with chatgpt: An empirical investigation, 2023
N. Nascimento, P. Alencar, and D. Cowan · 2023
Closest in time.
”do anything now”: Characterizing and evaluating in-the-wild jailbreak prompts on large language models, 2023
X. Shen, Z. Chen, M. Backes, Y. Shen, and Y. Zhang · 2023
Closest in time.
An analysis of the automatic bug fixing performance of chatgpt, 2023
D. Sobania, M. Briesch, C. Hanna, and J. Petke · 2023
Closest in time.
Is chatgpt the ultimate programming assistant – how far is it?, 2023
H. Tian, W. Lu, T. O. Li, X. Tang, S.-C. Cheung, J. Klein, and T. F. Bissyandé · 2023
Closest in time.
Understanding the threats of upstream vulnerabilities to downstream projects in the maven ecosystem
Y. Wu, Z. Yu, M. Wen, Q. Li, D. Zou, and H. Jin · 2023
Closest in time.
An llm can fool itself: A prompt-based adversarial attack
X. Xu, K. Kong, N. Liu, L. Cui, D. Wang, J. Zhang, and M. Kankanhalli · 2023
Closest in time.
Universal and transferable adversarial attacks on aligned language models, 2023
A. Zou, Z. Wang, N. Carlini, M. Nasr, J. Z. Kolter, and M. Fredrikson · 2023
Closest in time.
https://github.com/soarsmu/transfer
soarsmu/transfer · 2024
Closest in time.
Amplegcg: Learning a universal and transferable generative model of adversarial suffixes for jailbreaking both open and closed llms, 2024
Z. Liao and H. Sun · 2024
Closest in time.
Large language model guided protocol fuzzing
R. Meng, M. Mirchev, M. Böhme, and A. Roychoudhury · 2024
Closest in time.
Probabilistic reasoning in generative large language models
A. Nafar, K. B. Venable, and P. Kordjamshidi · 2024
Closest in time.
Fuzz4all: Universal fuzzing with large language models
C. S. Xia, M. Paltenghi, J. Le Tian, M. Pradel, and L. Zhang · 2024
Closest in time.
Pre-trained model-based automated software vulnerability repair: How far are we?
Q. Zhang, C. Fang, B. Yu, W. Sun, T. Zhang, and Z. Chen · 2024
Closest in time.
Can llm replace stack overflow? a study on robustness and reliability of large language model code generation
L. Zhong and Z. Wang · 2024
Closest in time.
Performance and reproducibility of large language models in named entity recognition: Considerations for the use in controlled environments
J. Dietrich and A. Hollstein · 2025
Closest in time.
An empirical study of the non-determinism of chatgpt in code generation
S. Ouyang, J. M. Zhang, M. Harman, and M. Wang · 2025
Closest in time.
Common Vulnerabilities and Exposures (CVE)
The MITRE Corporation · 2025
Closest in time.