Fetching the paper…
Reading the bibliography…
Existing malicious code detection techniques demand the integration of multiple tools to detect different malware patterns, often suffering from high misclassification rates.
Language models are few-shot learners
1901
Earlier work this paper cites.
Identification of dependency-based attacks on node. js
2017
Earlier work this paper cites.
Attacks on package managers
2019
Earlier work this paper cites.
Detecting suspicious package updates
2019
Earlier work this paper cites.
Towards measuring supply chain attacks on package managers for interpreted languages
2020
Earlier work this paper cites.
Inverse adaptive stratified random sampling
2020
Earlier work this paper cites.
Backstabber’s knife collection: A review of open source software supply chain attacks
2020
Earlier work this paper cites.
Spellbound: Defending against package typosquatting
2020
Earlier work this paper cites.
Anomalicious: Automated detection of anomalous and potentially malicious commits on github
2021
Earlier work this paper cites.
Lastpymile: identifying the discrepancy between sources and packages
2021
Earlier work this paper cites.
On the feasibility of detecting software supply chain attacks
2021
Earlier work this paper cites.
Large language models are zero-shot reasoners, 2022
2022
Earlier work this paper cites.
Risk explorer for software supply chains: Understanding the attack surface of open-source based software development
2022
Earlier work this paper cites.
Towards the detection of malicious java packages
2022
Earlier work this paper cites.
Detecting malicious python packages in the python package index (pypi)
2022
Earlier work this paper cites.
On the feasibility of supervised machine learning for the detection of malicious software packages
2022
Earlier work this paper cites.
Towards Detection of Malicious Software Packages Through Code Reuse by Malevolent Actors
2022
Earlier work this paper cites.
On the feasibility of detecting injections in malicious npm packages
2022
Earlier work this paper cites.
Practical automated detection of malicious npm packages
2022
Earlier work this paper cites.
Chain-of-thought prompting elicits reasoning in large language models
2022
Cited alongside, same era.
What are weak links in the npm supply chain?
2022
Cited alongside, same era.
https://github.com/lmu-plai/diff-CodeQL , 2023
Diffstaticanalyzer - differential static analysis tool for npm packages to detect malicious updates · 2023
Cited alongside, same era.
Large language models suffer from their own output: An analysis of the self-consuming training loop
2023
Cited alongside, same era.
The curse of recursion: Training on generated data makes models forget
2023
Cited alongside, same era.
Differential static analysis for detecting malicious updates to open source packages
Prefer: Prompt ensemble learning via feedback-reflect-refine
2023
Later among the works it cites.
Judging llm-as-a-judge with mt-bench and chatbot arena
2023
Later among the works it cites.
Can chatgpt understand too? a comparative study on chatgpt and fine-tuned bert
2023
Later among the works it cites.
https://openai.com
OpenAI · 2024
Closest in time.
https://www.elastic.co/explore/security-without-limits/elastic-ai-assistant-analyst-report? , 2024
The Elastic AI Assistant advantage · 2024
Closest in time.
https://www.ibm.com/topics/prompt-injection , 2024
What is a prompt injection attack? · 2024
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2023
Cited alongside, same era.
An empirical study of malicious code in pypi ecosystem
2023
Cited alongside, same era.
Better zero-shot reasoning with role-play prompting
2023
Cited alongside, same era.
Summary of chatgpt-related research and perspective towards the future of large language models
2023
Cited alongside, same era.
Self-refine: Iterative refinement with self-feedback
2023
Cited alongside, same era.
Sok: Practical detection of software supply chain attacks
2023
Cited alongside, same era.
Software vulnerability detection using large language models
2023
Cited alongside, same era.
Closest in time.
Automatic semantic augmentation of language model prompts (for code summarization)
2024
Closest in time.
Malicious code in the purescript npm installer
2024
Closest in time.
Just another copy and paste? comparing the security vulnerabilities of chatgpt generated code and stackoverflow answers
2024
Closest in time.
Mysteries of mode collapse
2024
Closest in time.
Iopen-source dataset of malicious software packages
2024
Closest in time.
Introducing socket ai – chatgpt-powered threat analysis
2024
Closest in time.
Api rate limit advice
2024
Closest in time.
Malicious Code In Eslint-Plugin-Unicorn-Ts-2
2024
Closest in time.
Chatgpt prompt patterns for improving code quality, refactoring, requirements elicitation, and software design
2024
Closest in time.
Maltracker: A fine-grained npm malware tracker copiloted by llm-enhanced dataset
2024
Closest in time.
Malwarebench: Malware samples are not enough
2024
Closest in time.
Towards using source code repositories to identify software supply chain attacks
2095
Closest in time.