Fetching the paper…
Reading the bibliography…
Deep Learning (DL)-based methods have proven to be effective for software vulnerability detection, with a potential for substantial productivity enhancements for detecting vulnerabilities.
REEF: A Framework for Collecting Real-World Vulnerabilities and Fixes. In ASE . IEEE, 1952–1962
Chaozheng Wang, Zongjie Li, Yun Peng, Shuzheng Gao, Sirong Chen, Shuai Wang, Cuiyun Gao, and Michael R. Lyu. 2023 · 1962
Earlier work this paper cites.
Improving Security Using Extensible Lightweight Static Analysis
David Evans and David Larochelle. 2002 · 2002
Earlier work this paper cites.
"GNU cflow"
Sergey Poznyakoff. 2005 · 2005
Earlier work this paper cites.
An Empirical Analysis of the Impact of Software Vulnerability Announcements on Firm Stock Price
Rahul Telang and Sunil Wattal. 2007 · 2007
Earlier work this paper cites.
The Probabilistic Relevance Framework: BM25 and Beyond
Stephen E. Robertson and Hugo Zaragoza. 2009 · 2009
Earlier work this paper cites.
Improvements to BM25 and Language Models Examined. In Proceedings of the 2014 Australasian Document Computing Symposium, ADCS 2014, Melbourne, VIC, Australia, November 27-28, 2014 , J. Shane Culpepper, Laurence Anthony F. Park, and Guido Zuccon (Eds.). ACM, 58
Andrew Trotman, Antti Puurula, and Blake Burgess. 2014 · 2014
Earlier work this paper cites.
Learning similarity with cosine similarity ensemble
Peipei Xia, Li Zhang, and Fanzhang Li. 2015 · 2015
Earlier work this paper cites.
Gated Graph Sequence Neural Networks. In 4th International Conference on Learning Representations, ICLR 2016
Yujia Li, Daniel Tarlow, Marc Brockschmidt, and Richard S. Zemel. 2016 · 2016
Earlier work this paper cites.
Software Defect Prediction via Convolutional Neural Network. In QRS . IEEE, 318–328
Jian Li, Pinjia He, Jieming Zhu, and Michael R. Lyu. 2017 · 2017
Earlier work this paper cites.
Vulnerability detection with deep learning. In 2017 3rd IEEE international conference on computer and communications (ICCC) . IEEE, 1298–1302
Fang Wu, Jigang Wang, Jiqiang Liu, and Wei Wang. 2017 · 2017
Earlier work this paper cites.
Precision-guided context sensitivity for pointer analysis
Yue Li, Tian Tan, Anders Møller, and Yannis Smaragdakis. 2018a · 2018
Earlier work this paper cites.
VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018 . The Internet Society
Zhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin, Sujuan Wang, Zhijun Deng, and Yuyi Zhong. 2018b · 2018
Earlier work this paper cites.
DeepBugs: a learning approach to name-based bug detection
Michael Pradel and Koushik Sen. 2018 · 2018
Earlier work this paper cites.
Automated Vulnerability Detection in Source Code Using Deep Representation Learning. In ICMLA . IEEE, 757–762
Rebecca L. Russell, Louis Y. Kim, Lei H. Hamilton, Tomo Lazovich, Jacob Harer, Onur Ozdemir, Paul M. Ellingwood, and Marc W. McConley. 2018 · 2018
Earlier work this paper cites.
CPGVA: Code Property Graph based Vulnerability Analysis by Deep Learning. In 10th International Conference on Advanced Infocomm Technology, ICAIT 2018, Stockholm, Sweden, August 12-15, 2018 . IEEE, 184–188
Xiaomeng Wang, Tao Zhang, Runpu Wu, Wei Xin, and Changyu Hou. 2018 · 2018
Earlier work this paper cites.
Lessons learned from using a deep tree-based model for software defect prediction in practice. In MSR . IEEE / ACM, 46–57
Hoa Khanh Dam, Trang Pham, Shien Wee Ng, Truyen Tran, John C. Grundy, Aditya Ghose, Taeksu Kim, and Chul-Joo Kim. 2019 · 2019
Earlier work this paper cites.
Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019 . 10197–10207
Yaqin Zhou, Shangqing Liu, Jing Kai Siow, Xiaoning Du, and Yang Liu. 2019 · 2019
Earlier work this paper cites.
Deep Learning based Vulnerability Detection: Are We There Yet?
Saikat Chakraborty, Rahul Krishna, Yangruibo Ding, and Baishakhi Ray. 2020 · 2020
Earlier work this paper cites.
A C/C++ Code Vulnerability Dataset with Code Changes and CVE Summaries. In MSR ’20: 17th International Conference on Mining Software Repositories, Seoul, Republic of Korea, 29-30 June, 2020 , Sunghun Kim, Georgios Gousios, Sarah Nadi, and Joseph Hejderup (Eds.). ACM, 508–512
Jiahao Fan, Yi Li, Shaohua Wang, and Tien N. Nguyen. 2020 · 2020
Earlier work this paper cites.
CodeBERT: A Pre-Trained Model for Programming and Natural Languages. In Findings of the Association for Computational Linguistics: EMNLP 2020, Online Event, 16-20 November 2020 (Findings of ACL, Vol. EMNLP 2020) , Trevor Cohn, Yulan He, and Yang Liu (Eds.). Association for Computational Linguistics, 1536–1547
Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, Daxin Jiang, and Ming Zhou. 2020 · 2020
Cited alongside, same era.
PCA: memory leak detection using partial call-path analysis. In ESEC/FSE ’20: 28th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Virtual Event, USA, November 8-13, 2020 , Prem Devanbu, Myra B. Cohen, and Thomas Zimmermann (Eds.). ACM, 1621–1625
Wen Li, Haipeng Cai, Yulei Sui, and David Manz. 2020a · 2020
Cited alongside, same era.
A Principled Approach to Selective Context Sensitivity for Pointer Analysis
Yue Li, Tian Tan, Anders Moller, and Yannis Smaragdakis. 2020b · 2020
Cited alongside, same era.
VulCNN: An Image-inspired Scalable Vulnerability Detection System. In 44th IEEE/ACM 44th International Conference on Software Engineering, ICSE 2022, Pittsburgh, PA, USA, May 25-27, 2022 . ACM, 2365–2376
Yueming Wu, Deqing Zou, Shihan Dou, Wei Yang, Duo Xu, and Hai Jin. 2022 · 2022
Later among the works it cites.
Tree-sitter
2023 · 2023
Later among the works it cites.
DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection. In RAID . ACM, 654–668
Yizheng Chen, Zhoujie Ding, Lamya Alowain, Xinyun Chen, and David A. Wagner. 2023 · 2023
Later among the works it cites.
Data Quality for Software Vulnerability Datasets
Roland Croft, Muhammad Ali Babar, and M. Mehdi Kholoosi. 2023 · 2023
Later among the works it cites.
ChatGPT for Vulnerability Detection, Classification, and Repair: How Far Are We?
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
IntelliCode compose: code generation using transformer. In ESEC/FSE ’20: 28th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Virtual Event, USA, November 8-13, 2020 , Prem Devanbu, Myra B. Cohen, and Thomas Zimmermann (Eds.). ACM, 1433–1443
Alexey Svyatkovskiy, Shao Kun Deng, Shengyu Fu, and Neel Sundaresan. 2020 · 2020
Cited alongside, same era.
BGNN4VD : Constructing Bidirectional Graph Neural-Network for Vulnerability Detection
Sicong Cao, Xiaobing Sun, Lili Bo, Ying Wei, and Bin Li. 2021 · 2021
Cited alongside, same era.
DeepWukong: Statically Detecting Software Vulnerabilities Using Deep Graph Neural Network
Xiao Cheng, Haoyu Wang, Jiayi Hua, Guoai Xu, and Yulei Sui. 2021 · 2021
Cited alongside, same era.
Neural software vulnerability analysis using rich intermediate graph representations of programs
Seyed Mohammad Ghaffarian and Hamid Reza Shahriari. 2021 · 2021
Cited alongside, same era.
GraphCodeBERT: Pre-training Code Representations with Data Flow. In 9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7, 2021 . OpenReview.net
Daya Guo, Shuo Ren, Shuai Lu, Zhangyin Feng, Duyu Tang, Shujie Liu, Long Zhou, Nan Duan, Alexey Svyatkovskiy, Shengyu Fu, Michele Tufano, Shao Kun Deng, Colin B. Clement, Dawn Drain, Neel Sundaresan, Jian Yin, Daxin Jiang, and Ming Zhou. 2021 · 2021
Cited alongside, same era.
Vulnerability detection with fine-grained interpretations. In ESEC/SIGSOFT FSE . ACM, 292–303
Yi Li, Shaohua Wang, and Tien N. Nguyen. 2021 · 2021
Cited alongside, same era.
CrossVul: a cross-language vulnerability dataset with commit data. In ESEC/SIGSOFT FSE . ACM, 1565–1569
Georgios Nikitopoulos, Konstantina Dritsa, Panos Louridas, and Dimitris Mitropoulos. 2021 · 2021
Cited alongside, same era.
“Semgrep”
r2c. 2021 · 2021
Cited alongside, same era.
CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and Generation. In Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, EMNLP 2021, Virtual Event / Punta Cana, Dominican Republic, 7-11 November, 2021 , Marie-Francine Moens, Xuanjing Huang, Lucia Specia, and Scott Wen-tau Yih (Eds.). Association for Computational Linguistics, 8696–8708
Yue Wang, Weishi Wang, Shafiq R. Joty, and Steven C. H. Hoi. 2021 · 2021
Cited alongside, same era.
Michael Fu, Chakkrit Tantithamthavorn, Van Nguyen, and Trung Le. 2023 · 2023
Later among the works it cites.
Large Language Models for Software Engineering: A Systematic Literature Review
Xinyi Hou, Yanjie Zhao, Yue Liu, Zhou Yang, Kailong Wang, Li Li, Xiapu Luo, David Lo, John C. Grundy, and Haoyu Wang. 2023 · 2023
Later among the works it cites.
HuggingFace
Huggingface hub. 2023 · 2023
Later among the works it cites.
Efficient Memory Management for Large Language Model Serving with PagedAttention. In Proceedings of the 29th Symposium on Operating Systems Principles, SOSP 2023, Koblenz, Germany, October 23-26, 2023 , Jason Flinn, Margo I. Seltzer, Peter Druschel, Antoine Kaufmann, and Jonathan Mace (Eds.). ACM, 611–626
Woosuk Kwon, Zhuohan Li, Siyuan Zhuang, Ying Sheng, Lianmin Zheng, Cody Hao Yu, Joseph Gonzalez, Hao Zhang, and Ion Stoica. 2023 · 2023
Later among the works it cites.
StarCoder: may the source be with you!
Raymond Li, Loubna Ben Allal, Yangtian Zi, Niklas Muennighoff, Denis Kocetkov, Chenghao Mou, Marc Marone, Christopher Akiki, Jia Li, Jenny Chim, Qian Liu, Evgenii Zheltonozhskii, Terry Yue Zhuo, Thomas Wang, Olivier Dehaene, Mishig Davaadorj, Joel Lamy-Poirier, João Monteiro, Oleh Shliazhko, Nicolas Gontier, Nicholas Meade, Armel Zebaze, Ming-Ho Yee, Logesh Kumar Umapathi, Jian Zhu, Benjamin Lipkin, Muhtasham Oblokulov, Zhiruo Wang, Rudra Murthy V, Jason Stillerman, Siva Sankalp Patel, Dmitry Abulkhanov, Marco Zocca, Manan Dey, Zhihan Zhang, Nour Moustafa-Fahmy, Urvashi Bhattacharyya, Wenhao Yu, Swayam Singh, Sasha Luccioni, Paulo Villegas, Maxim Kunakov, Fedor Zhdanov, Manuel Romero, Tony Lee, Nadav Timor, Jennifer Ding, Claire Schlesinger, Hailey Schoelkopf, Jan Ebert, Tri Dao, Mayank Mishra, Alex Gu, Jennifer Robinson, Carolyn Jane Anderson, Brendan Dolan-Gavitt, Danish Contractor, Siva Reddy, Daniel Fried, Dzmitry Bahdanau, Yacine Jernite, Carlos Muñoz Ferrandis, Sean Hughes, Thomas Wolf, Arjun Guha, Leandro von Werra, and Harm de Vries. 2023 · 2023
Later among the works it cites.
OpenAI. 2023 · 2023
Later among the works it cites.
Generative Type Inference for Python
Yun Peng, Chaozheng Wang, Wenxuan Wang, Cuiyun Gao, and Michael R. Lyu. 2023 · 2023
Later among the works it cites.
Code Llama: Open Foundation Models for Code
Baptiste Rozière, Jonas Gehring, Fabian Gloeckle, Sten Sootla, Itai Gat, Xiaoqing Ellen Tan, Yossi Adi, Jingyu Liu, Tal Remez, Jérémy Rapin, Artyom Kozhevnikov, Ivan Evtimov, Joanna Bitton, Manish Bhatt, Cristian Canton-Ferrer, Aaron Grattafiori, Wenhan Xiong, Alexandre Défossez, Jade Copet, Faisal Azhar, Hugo Touvron, Louis Martin, Nicolas Usunier, Thomas Scialom, and Gabriel Synnaeve. 2023 · 2023
Later among the works it cites.
LLaMA: Open and Efficient Foundation Language Models
Hugo Touvron, Thibaut Lavril, Gautier Izacard, Xavier Martinet, Marie-Anne Lachaux, Timothée Lacroix, Baptiste Rozière, Naman Goyal, Eric Hambro, Faisal Azhar, Aurélien Rodriguez, Armand Joulin, Edouard Grave, and Guillaume Lample. 2023a · 2023
Later among the works it cites.
When Less is Enough: Positive and Unlabeled Learning Model for Vulnerability Detection
Xin-Cheng Wen, Xinchen Wang, Cuiyun Gao, Shaohua Wang, Yang Liu, and Zhaoquan Gu. 2023 · 2023
Later among the works it cites.
“Mend bolt”
WhiteSource. 2023 · 2023
Later among the works it cites.
Vulnerability Detection by Learning From Syntax-Based Execution Paths of Code
Junwei Zhang, Zhongxin Liu, Xing Hu, Xin Xia, and Shanping Li. 2023 · 2023
Later among the works it cites.
CodeGeeX: A Pre-Trained Model for Code Generation with Multilingual Evaluations on HumanEval-X
Qinkai Zheng, Xiao Xia, Xu Zou, Yuxiao Dong, Shan Wang, Yufei Xue, Zihan Wang, Lei Shen, Andi Wang, Yang Li, et al · 2023
Later among the works it cites.
Pre-training by Predicting Program Dependencies for Vulnerability Analysis Tasks
Zhongxin Liu, Zhijie Tang, Junwei Zhang, Xin Xia, and Xiaohu Yang. 2024 · 2024
Closest in time.
Number of common IT security vulnerabilities and exposures (CVEs) worldwide from 2009 to 2024 YTD
Statista. 2024 · 2024
Closest in time.