Fetching the paper…
Reading the bibliography…
Large Language Models (LLMs) have been suggested for use in automated vulnerability repair, but benchmarks showing they can consistently identify security-related bugs are lacking.
J. L. Fleiss, B. Levin, and M. C. Paik, Statistical methods for rates and proportions . Wiley-Interscience, 2003
2003
Earlier work this paper cites.
C. Y. Lin, “ROUGE: A package for automatic evaluation of summaries.” Association for Computational Linguistics, Jul. 2004
2004
Earlier work this paper cites.
F. Yamaguchi, N. Golde, D. Arp, and K. Rieck, “Modeling and discovering vulnerabilities with code property graphs,” in IEEE Symposium on Security and Privacy , 2014
2014
Earlier work this paper cites.
G. Grieco, G. L. Grinblat, L. Uzal, S. Rawat, J. Feist, and L. Mounier, “Toward large-scale vulnerability discovery using machine learning,” 2016
2016
Earlier work this paper cites.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. u. Kaiser, and I. Polosukhin, “Attention is all you need,” in Advances in Neural Information Processing Systems , 2017
2017
Earlier work this paper cites.
G. Lin, J. Zhang, W. Luo, L. Pan, and Y. Xiang, “Poster: Vulnerability discovery with function representation learning from unlabeled projects,” in Proceedings of ACM SIGSAC Conference on Computer and Communications Security , 2017
2017
Earlier work this paper cites.
Z. Li, D. Zou, S. Xu, X. Ou, H. Jin, S. Wang, Z. Deng, and Y. Zhong, “Vuldeepecker: A deep learning-based system for vulnerability detection,” Proceedings of Network and Distributed System Security Symposium , 2018
2018
Earlier work this paper cites.
D. Votipka, R. Stevens, E. Redmiles, J. Hu, and M. Mazurek, “Hackers vs. testers: A comparison of software vulnerability discovery processes,” in IEEE Symposium on Security and Privacy , 2018
2018
Earlier work this paper cites.
R. Russell, L. Kim, L. Hamilton, T. Lazovich, J. Harer, O. Ozdemir, P. Ellingwood, and M. McConley, “Automated vulnerability detection in source code using deep representation learning,” in 17th IEEE International Conference on Machine Learning and Applications (ICMLA) , 2018
2018
Earlier work this paper cites.
Y. Zhou, S. Liu, J. Siow, X. Du, and Y. Liu, “Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks,” in Advances in Neural Information Processing Systems , 2019
2019
Earlier work this paper cites.
A. Rahman, C. Parnin, and L. Williams, “The seven sins: Security smells in infrastructure as code scripts,” in IEEE/ACM 41st International Conference on Software Engineering (ICSE) , 2019
2019
Earlier work this paper cites.
T. Brown, B. Mann, N. Ryder, M. Subbiah, J. D. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell, S. Agarwal, A. Herbert-Voss, G. Krueger, T. Henighan, R. Child, A. Ramesh, D. Ziegler, J. Wu, C. Winter, C. Hesse, M. Chen, E. Sigler, M. Litwin, S. Gray, B. Chess, J. Clark, and Berner, “Language models are few-shot learners,” in Advances in Neural Information Processing Systems , 2020
2020
Earlier work this paper cites.
D. Votipka, S. Rabin, K. Micinski, J. S. Foster, and M. L. Mazurek, “An observational investigation of reverse Engineers’ processes,” in 29th USENIX Security Symposium , 2020
2020
Earlier work this paper cites.
2021
Earlier work this paper cites.
L. Phan, H. Tran, D. Le, H. Nguyen, J. Annibal, A. Peltekian, and Y. Ye, “CoTexT: Multi-task learning with code-text transformer,” in Proceedings of the 1st Workshop on Natural Language Processing for Programming (NLP4Prog) , 2021
2021
Earlier work this paper cites.
W. Ahmad, S. Chakraborty, B. Ray, and K.-W. Chang, “Unified pre-training for program understanding and generation,” in Proceedings of Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies , 2021
2021
Earlier work this paper cites.
2021
Earlier work this paper cites.
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, “Asleep at the keyboard? assessing the security of github copilot’s code contributions,” in IEEE Symposium on Security and Privacy , 2022
2022
Cited alongside, same era.
J. Wei, X. Wang, D. Schuurmans, M. Bosma, B. Ichter, F. Xia, E. Chi, Q. V. Le, and D. Zhou, “Chain-of-thought prompting elicits reasoning in large language models,” in Advances in Neural Information Processing Systems , 2022
2022
Cited alongside, same era.
J. Wei, Y. Tay, R. Bommasani, C. Raffel, B. Zoph, S. Borgeaud, D. Yogatama, M. Bosma, D. Zhou, D. Metzler, E. H. Chi, T. Hashimoto, O. Vinyals, P. Liang, J. Dean, and W. Fedus, “Emergent abilities of large language models,” Transactions on Machine Learning Research , 2022
2022
Cited alongside, same era.
Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, and Z. Chen, “Sysevr: A framework for using deep learning to detect software vulnerabilities,” IEEE Transactions on Dependable and Secure Computing , 2022
2022
N. Perry, M. Srivastava, D. Kumar, and D. Boneh, “Do users write more insecure code with ai assistants?” in Proceedings of ACM SIGSAC Conference on Computer and Communications Security , 2023
2023
Closest in time.
“Diffblue cover: Autonomous java unit test writing with ai for code,” https://www.diffblue.com/products/
2023
Closest in time.
“OWASP List.” https://owasp.org/www-community/Source_Code_Analysis_Tools
2023
Closest in time.
Y. Mirsky, G. Macon, M. Brown, C. Yagemann, M. Pruett, E. Downing, S. Mertoguno, and W. Lee, “VulChecker: Graph-based vulnerability localization in source code,” in 32nd USENIX Security Symposium , 2023
2023
Closest in time.
“Pysa.” https://engineering.fb.com/2020/08/07/security/pysa/
2023
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
D. Guo, S. Lu, N. Duan, Y. Wang, M. Zhou, and J. Yin, “UniXcoder: Unified cross-modal pre-training for code representation,” in Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics , May 2022
2022
Cited alongside, same era.
H. Hanif and S. Maffeis, “Vulberta: Simplified source code pre-training for vulnerability detection,” in International Joint Conference on Neural Networks (IJCNN) , 2022
2022
Cited alongside, same era.
D. Arp, E. Quiring, F. Pendlebury, A. Warnecke, F. Pierazzi, C. Wressnegger, L. Cavallaro, and K. Rieck, “Dos and don’ts of machine learning in computer security,” in 31st USENIX Security Symposium , 2022
2022
Cited alongside, same era.
C. Thapa, S. I. Jang, M. E. Ahmed, S. Camtepe, J. Pieprzyk, and S. Nepal, “Transformer-based language models for software vulnerability detection,” in Proceedings of the 38th Annual Computer Security Applications Conference , 2022
2022
Cited alongside, same era.
T. Kojima, S. S. Gu, M. Reid, Y. Matsuo, and Y. Iwasawa, “Large language models are zero-shot reasoners,” in Advances in Neural Information Processing Systems , 2022, pp. 22 199–22 213
2022
Cited alongside, same era.
2022
Cited alongside, same era.
R. Anil, A. M. Dai, O. Firat, M. Johnson, and D. Lepikhin, “Palm 2 technical report,” 2023
2023
Cited alongside, same era.
2023
Cited alongside, same era.
“Bandit.” https://bandit.readthedocs.io/en/latest/
2023
Closest in time.
“Cppcheck.” https://cppcheck.sourceforge.io/
2023
Closest in time.
“Infer.” https://fbinfer.com/
2023
Closest in time.
2023
Closest in time.
“Microsoft codexglue leaderboard.” https://microsoft.github.io/CodeXGLUE/
2023
Closest in time.
“Best practices for prompt engineering with OpenAI API,” https://help.openai.com/en/articles/6654000-best-practices-for-prompt-engineering-with-openai-api
2023
Closest in time.
“Introduction to prompt design,” https://developers.generativeai.google/guide/prompt_best_practices
2023
Closest in time.
“MITRE Top 25 Most Dangerous Software Weaknesses.” https://cwe.mitre.org/data/definitions/1387.html
2023
Closest in time.
2023
Closest in time.
2023
Closest in time.
“OpenAI Chat Completion API Reference,” https://platform.openai.com/docs/api-reference/completions/create
2023
Closest in time.