Fetching the paper…
Reading the bibliography…
While automated vulnerability detection techniques have made promising progress in detecting security vulnerabilities, their scalability and applicability remain challenging.
T. Boland and P. E. Black, “Juliet 1.1 c/c++ and java test suite,” Computer , 2012
2012
Earlier work this paper cites.
P. Avgustinov, O. de Moor, M. P. Jones, and M. Schäfer, “Ql: Object-oriented queries on relational data,” in European Conference on Object-Oriented Programming , 2016
2016
Earlier work this paper cites.
2018
Earlier work this paper cites.
Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, Z. Chen, S. Wang, and J. Wang, “Sysevr: A framework for using deep learning to detect software vulnerabilities,” IEEE Transactions on Dependable and Secure Computing , vol. 19, pp. 2244–2258, 2018
2018
Earlier work this paper cites.
M. Miller, “Microsoft: 70 percent of all security bugs are memory safety issues,” https://www.zdnet.com/article/microsoft-70-percent-of-all-security-bugs-are-memory-safety-issues/ , 2019
2019
Earlier work this paper cites.
Y. Zhou, S. Liu, J. Siow, X. Du, and Y. Liu, “Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks,” in Neural Information Processing Systems , 2019
2019
Earlier work this paper cites.
J. Fan, Y. Li, S. Wang, and T. N. Nguyen, “A c/c++ code vulnerability dataset with code changes and cve summaries,” in Proceedings of the 17th International Conference on Mining Software Repositories , ser. MSR ’20. New York, NY, USA: Association for Computing Machinery, 2020, p. 508–512. [Online]. Available: https://doi.org/10.1145/3379597.3387501
2020
Earlier work this paper cites.
S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep learning based vulnerability detection: Are we there yet?” IEEE Transactions on Software Engineering , vol. 48, pp. 3280–3296, 2020
2020
Earlier work this paper cites.
Z. Li, D. Zou, S. Xu, Z. Chen, Y. Zhu, and H. Jin, “Vuldeelocator: A deep learning-based fine-grained vulnerability detector,” IEEE Transactions on Dependable and Secure Computing , 2020
2020
Earlier work this paper cites.
2021
Earlier work this paper cites.
G. P. Bhandari, A. Naseer, and L. Moonen, “Cvefixes: automated collection of vulnerabilities and their fixes from open-source software,” Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering , 2021
2021
Earlier work this paper cites.
S. Chakraborty, R. Krishna, Y. Ding, and B. Ray, “Deep learning based vulnerability detection: Are we there yet?” IEEE Transactions on Software Engineering , vol. 48, no. 9, pp. 3280–3296, 2021
2021
Earlier work this paper cites.
Y. Li, S. Wang, and T. N. Nguyen, “Vulnerability detection with fine-grained interpretations,” Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2021
2021
Earlier work this paper cites.
2022, https://nvd.nist.gov/vuln/detail/CVE-2022-3602
2022
Earlier work this paper cites.
2022, https://nvd.nist.gov/vuln/detail/CVE-2022-3786
2022
Earlier work this paper cites.
L. Leong, “Mindshare: When mysql cluster encounters taint analysis,” https://www.zerodayinitiative.com/blog/2022/2/10/mindshare-when-mysql-cluster-encounters-taint-analysis , 2022
2022
Earlier work this paper cites.
M. Fu and C. Tantithamthavorn, “Linevul: A transformer-based line-level vulnerability prediction,” in 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR) . IEEE, 2022
2022
Earlier work this paper cites.
C. S. Xia and L. Zhang, “Less training, more repairing please: revisiting automated program repair via zero-shot learning,” in Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2022, pp. 959–971
2022
Earlier work this paper cites.
J. Wei, Y. Tay, R. Bommasani, C. Raffel, B. Zoph, S. Borgeaud, D. Yogatama, M. Bosma, D. Zhou, D. Metzler, E. H. hsin Chi, T. Hashimoto, O. Vinyals, P. Liang, J. Dean, and W. Fedus, “Emergent abilities of large language models,” Trans. Mach. Learn. Res. , vol. 2022, 2022
2022
Earlier work this paper cites.
J. Wei, X. Wang, D. Schuurmans, M. Bosma, F. Xia, E. Chi, Q. V. Le, D. Zhou et al. , “Chain-of-thought prompting elicits reasoning in large language models,” Advances in neural information processing systems , vol. 35, pp. 24 824–24 837, 2022
2022
Cited alongside, same era.
D. Hin, A. Kan, H. Chen, and M. A. Babar, “Linevd: Statement-level vulnerability detection using graph neural networks,” 2022 IEEE/ACM 19th International Conference on Mining Software Repositories (MSR) , 2022
2022
Cited alongside, same era.
X. Cheng, G. Zhang, H. Wang, and Y. Sui, “Path-sensitive code embedding via contrastive learning for software vulnerability detection,” Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis , 2022
2022
Cited alongside, same era.
C. Thapa, S. I. Jang, M. E. Ahmed, S. A. Çamtepe, J. Pieprzyk, and S. Nepal, “Transformer-based language models for software vulnerability detection,” Proceedings of the 38th Annual Computer Security Applications Conference , 2022
2023, https://samate.nist.gov/SARD/test-suites/111
2023
Closest in time.
Y. Chen, Z. Ding, L. Alowain, X. Chen, and D. A. Wagner, “Diversevul: A new vulnerable source code dataset for deep learning based vulnerability detection,” Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses , 2023
2023
Closest in time.
W. Wang, T. N. Nguyen, S. Wang, Y. Li, J. Zhang, and A. Yadavally, “Deepvd: Toward class-separation features for neural network vulnerability detection,” in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) , 2023
2023
Closest in time.
2023, https://huggingface.co/
2023
Closest in time.
2023. [Online]. Available: https://cwe.mitre.org/top25/archive/2023/2023_top25_list.html
2023
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2022
Cited alongside, same era.
Semgrep, “The semgrep platform,” https://semgrep.dev/ , 2023
2023
Cited alongside, same era.
Semmle, “Vulnerabilities discovered by CodeQL,” https://securitylab.github.com/advisories/ , 2023
2023
Cited alongside, same era.
GitHub, “The bug slayer,” 2023, https://securitylab.github.com/bounties
2023
Cited alongside, same era.
C. S. Xia, Y. Wei, and L. Zhang, “Automated program repair in the era of large pre-trained language models,” in Proceedings of the 45th International Conference on Software Engineering (ICSE 2023). Association for Computing Machinery , 2023
2023
Cited alongside, same era.
H. Joshi, J. C. Sanchez, S. Gulwani, V. Le, G. Verbruggen, and I. Radiček, “Repair is nearly generation: Multilingual program repair with llms,” in Proceedings of the AAAI Conference on Artificial Intelligence , 2023
2023
Cited alongside, same era.
C. Lemieux, J. P. Inala, S. K. Lahiri, and S. Sen, “Codamosa: Escaping coverage plateaus in test generation with pre-trained large language models,” in International conference on software engineering (ICSE) , 2023
2023
Cited alongside, same era.
Y. Deng, C. S. Xia, H. Peng, C. Yang, and L. Zhang, “Large language models are zero-shot fuzzers: Fuzzing deep-learning libraries via large language models,” in Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis , 2023, pp. 423–435
2023
Cited alongside, same era.
J. Zhang, P. Nie, J. J. Li, and M. Gligoric, “Multilingual code co-evolution using large language models,” in Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , 2023, pp. 695–707
2023
Cited alongside, same era.
2023. [Online]. Available: https://dwheeler.com/flawfinder
2023
Closest in time.
2023, https://cppcheck.sourceforge.io/
2023
Closest in time.
2023, https://fbinfer.com/
2023
Closest in time.
2023, https://github.com/Ericsson/codechecker
2023
Closest in time.
B. Steenhoek, H. Gao, and W. Le, “Dataflow analysis-inspired deep learning for efficient vulnerability detection,” in Proceedings of the 46th IEEE/ACM International Conference on Software Engineering , 2024, pp. 1–13
2024
Closest in time.
A. Z. Yang, C. Le Goues, R. Martins, and V. Hellendoorn, “Large language models for test-free fault localization,” in Proceedings of the 46th IEEE/ACM International Conference on Software Engineering , 2024, pp. 1–12
2024
Closest in time.
X. Zhou, T. Zhang, and D. Lo, “Large language model for vulnerability detection: Emerging results and future directions,” in Proceedings of the 2024 ACM/IEEE 44th International Conference on Software Engineering: New Ideas and Emerging Results , 2024, pp. 47–51
2024
Closest in time.
2024
Closest in time.
S. Ullah, M. Han, S. Pujar, H. Pearce, A. Coskun, and G. Stringhini, “Llms cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks,” in 2024 IEEE Symposium on Security and Privacy (SP) . Los Alamitos, CA, USA: IEEE Computer Society, may 2024, pp. 862–880. [Online]. Available: https://doi.ieeecomputersociety.org/10.1109/SP54263.2024.00210
2024
Closest in time.
2024
Closest in time.
L. Salewski, S. Alaniz, I. Rio-Torto, E. Schulz, and Z. Akata, “In-context impersonation reveals large language models’ strengths and biases,” Advances in Neural Information Processing Systems , vol. 36, 2024
2024
Closest in time.
2024, https://github.com/ISU-PAAL/DeepDFA/tree/master
2024
Closest in time.
H. Li, Y. Hao, Y. Zhai, and Z. Qian, “Enhancing static analysis for practical bug detection: An llm-integrated approach,” Proceedings of the ACM on Programming Languages , vol. 8, no. OOPSLA1, 2024
2024
Closest in time.