Fetching the paper…
Reading the bibliography…
Software vulnerability detection is generally supported by automated static analysis tools, which have recently been reinforced by deep learning (DL) models.
Language models are few-shot learners
Brown, T., Mann, B., Ryder, N., Subbiah, M., Kaplan, J.D., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., Askell, A., et al., 2020 · 1901
Earlier work this paper cites.
Seven pernicious kingdoms: A taxonomy of software security errors
Tsipenyuk, K., Chess, B., McGraw, G., 2005 · 2005
Earlier work this paper cites.
An empirical analysis of the impact of software vulnerability announcements on firm stock price
Telang, R., Wattal, S., 2007 · 2007
Earlier work this paper cites.
What developers want and need from program analysis: An empirical study, in: Proceedings of the 31st IEEE/ACM International Conference on Automated Software Engineering (ASE), ACM. pp. 332–343
Christakis, M., Bird, C., 2016 · 2016
Earlier work this paper cites.
A map of threats to validity of systematic literature reviews in software engineering, in: Proceedings of the 23rd IEEE International Conference on Asia-Pacific Software Engineering Conference (APSEC), IEEE. pp. 153–160
Zhou, X., Jin, Y., Zhang, H., Li, S., Huang, X., 2016 · 2016
Earlier work this paper cites.
A novel approach for software vulnerability classification, in: Proceedings of the 64th IEEE/ACM International Conference on Reliability and Maintainability Symposium (RAMS), IEEE. pp. 1–7
Li, X., Chang, X., Board, J.A., Trivedi, K.S., 2017 · 2017
Earlier work this paper cites.
Vuldeepecker: A deep learning-based system for vulnerability detection, in: Proceedings of the 25th ACM Annual Network and Distributed System Security Symposium (NDSS), The Internet Society
Li, Z., Zou, D., Xu, S., Ou, X., Jin, H., Wang, S., Deng, Z., Zhong, Y., 2018 · 2018
Earlier work this paper cites.
Classification from positive, unlabeled and biased negative data, in: Proceedings of the 36th ACM International Conference on Machine Learning (ICML), PMLR. pp. 2820–2829
Hsieh, Y.G., Niu, G., Sugiyama, M., 2019 · 2019
Earlier work this paper cites.
On the role of data balancing for machine learning-based code smell detection, in: Proceedings of the 3rd ACM SIGSOFT International Workshop on Machine Learning Techniques for Software Quality Evaluation (MaLTeSQuE), ACM. pp. 19–24
Pecorelli, F., Di Nucci, D., De Roover, C., De Lucia, A., 2019 · 2019
Earlier work this paper cites.
An empirical study on culture, automation, measurement, and sharing of devsecops, in: 2019 International Conference on Cyber Security and Protection of Digital Services (Cyber Security), IEEE. pp. 1–8
Tomas, N., Li, J., Huang, H., 2019 · 2019
Earlier work this paper cites.
Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks
Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y., 2019 · 2019
Earlier work this paper cites.
μ \mu vuldeepecker: A deep learning-based system for multiclass vulnerability detection
Zou, D., Wang, S., Xu, S., Li, Z., Jin, H., 2019 · 2019
Earlier work this paper cites.
Automated identification of libraries from vulnerability data, in: Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering: Software Engineering in Practice (SEIP), ACM. pp. 90–99
Chen, Y., Santosa, A.E., Sharma, A., Lo, D., 2020 · 2020
Earlier work this paper cites.
A c/c++ code vulnerability dataset with code changes and cve summaries, in: Proceedings of the 17th IEEE/ACM International Conference on Mining Software Repositories (MSR), ACM. pp. 508–512
Fan, J., Li, Y., Wang, S., Nguyen, T.N., 2020 · 2020
Earlier work this paper cites.
Evaluating large language models trained on code
Chen, M., Tworek, J., Jun, H., Yuan, Q., Pinto, H.P.d.O., Kaplan, J., Edwards, H., Burda, Y., Joseph, N., Brockman, G., et al., 2021 · 2021
Earlier work this paper cites.
Anomalicious: Automated detection of anomalous and potentially malicious commits on github, in: Proceedings of 43rd IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), IEEE. pp. 258–267
Gonzalez, D., Zimmermann, T., Godefroid, P., Schäfer, M., 2021 · 2021
Cited alongside, same era.
Sysevr: A framework for using deep learning to detect software vulnerabilities
Li, Z., Zou, D., Xu, S., Jin, H., Zhu, Y., Chen, Z., 2021 · 2021
Cited alongside, same era.
A comprehensive study on security bug characteristics
Wei, Y., Sun, X., Bo, L., Cao, S., Xia, X., Li, B., 2021 · 2021
Cited alongside, same era.
Constitutional ai: Harmlessness from ai feedback
Bai, Y., Kadavath, S., Kundu, S., Askell, A., Kernion, J., Jones, A., Chen, A., Goldie, A., Mirhoseini, A., McKinnon, C., et al., 2022 · 2022
Cited alongside, same era.
Deep learning based vulnerability detection: Are we there yet
Chakraborty, S., Krishna, R., Ding, Y., Ray, B., 2022 · 2022
Evaluation of chatgpt model for vulnerability detection
Cheshkov, A., Zadorozhny, P., Levichev, R., 2023 · 2023
Later among the works it cites.
Palm: Scaling language modeling with pathways
Chowdhery, A., Narang, S., Devlin, J., Bosma, M., Mishra, G., Roberts, A., Barham, P., Chung, H.W., Sutton, C., Gehrmann, S., et al., 2023 · 2023
Later among the works it cites.
Data quality for software vulnerability datasets, in: Proceedings of the 45th IEEE/ACM International Conference on Software Engineering (ICSE), IEEE. pp. 121–133
Croft, R., Babar, M.A., Kholoosi, M.M., 2023 · 2023
Later among the works it cites.
Why can gpt learn in-context? language models implicitly perform gradient descent as meta-optimizers, in: Proceedings of the 2023 ICLR Workshop on Mathematical and Empirical Understanding of Foundation Models (ME-FoMo), Association for Computational Linguistics. pp. 4005–4019
Dai, D., Sun, Y., Dong, L., Hao, Y., Ma, S., Sui, Z., Wei, F., 2023 · 2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Linevul: A transformer-based line-level vulnerability prediction, in: Proceedings of the 19th IEEE/ACM International Conference on on Mining Software Repositories (MSR), ACM. pp. 608–620
Fu, M., Tantithamthavorn, C., 2022 · 2022
Cited alongside, same era.
Automated identification of libraries from vulnerability data: Can we do better?, in: Proceedings of the 30th IEEE/ACM International Conference on Program Comprehension (ICPC), ACM. pp. 178–189
Haryono, S.A., Kang, H.J., Sharma, A., Sharma, A., Santosa, A., Yi, A.M., Lo, D., 2022 · 2022
Cited alongside, same era.
Lora: Low-rank adaptation of large language models, in: International Conference on Learning Representations (ICLR)
Hu, E.J., Wallis, P., Allen-Zhu, Z., Li, Y., Wang, S., Wang, L., Chen, W., et al., 2022 · 2022
Cited alongside, same era.
Detecting false alarms from automatic static analysis tools: How far are we?, in: Proceedings of the 44th IEEE/ACM International Conference on Software Engineering (ICSE), ACM. pp. 698–709
Kang, H.J., Aw, K.L., Lo, D., 2022 · 2022
Cited alongside, same era.
How far are we from reproducible research on code smell detection? a systematic literature review
Lewowski, T., Madeyski, L., 2022 · 2022
Cited alongside, same era.
P-tuning: Prompt tuning can be comparable to fine-tuning across scales and tasks, in: Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (ACL), Association for computational Linguistics. pp. 61–68
Liu, X., Ji, K., Fu, Y., Tam, W., Du, Z., Yang, Z., Tang, J., 2022 · 2022
Cited alongside, same era.
A large-scale study of usability criteria addressed by static analysis tools, in: Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA), ACM. pp. 532–543
Nachtigall, M., Schlichtig, M., Bodden, E., 2022 · 2022
Cited alongside, same era.
Jin, M., Shahriar, S., Tufano, M., Shi, X., Lu, S., Sundaresan, N., Svyatkovskiy, A., 2023 · 2023
Later among the works it cites.
Can large language models better predict software vulnerability?
Katsadouros, E., Patrikakis, C.Z., Hurlburt, G., 2023 · 2023
Later among the works it cites.
Enabling programming thinking in large language models toward code generation
Li, J., Li, G., Li, Y., Jin, Z., 2023 · 2023
Later among the works it cites.
Not the end of story: An evaluation of chatgpt-driven vulnerability description mappings, in: Proceedings of the 61th Annual Meeting of the Association for Computational Linguistics (ACL), Association for Computational Linguistics. pp. 3724–3731
Liu, X., Tan, Y., Xiao, Z., Zhuge, J., Zhou, R., 2023 · 2023
Later among the works it cites.
New tricks to old codes: Can ai chatbots replace static code analysis tools?, in: Proceedings of the 7th ACM European Interdisciplinary Cybersecurity Conference (EICC), ACM. pp. 13–18
Ozturk, O.S., Ekmekcioglu, E., Cetin, O., Arief, B., Hernandez-Castro, J., 2023 · 2023
Later among the works it cites.
Software vulnerability detection using large language models, in: Proceedings of the 34th IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), IEEE. pp. 112–119
Purba, M.D., Ghosh, A., Radford, B.J., Chu, B., 2023 · 2023
Later among the works it cites.
Large language models can be easily distracted by irrelevant context, in: Proceedings of the 40th ACM International Conference on Machine Learning (ICML), PMLR. pp. 31210–31227
Shi, F., Chen, X., Misra, K., Scales, N., Dohan, D., Chi, E.H., Schärli, N., Zhou, D., 2023 · 2023
Later among the works it cites.
An empirical study of deep learning models for vulnerability detection, in: Proceedings of the 45th IEEE/ACM International Conference on Software Engineering (ICSE), pp. 2237–2248
Steenhoek, B., Rahman, M.M., Jiles, R., Le, W., 2023 · 2023
Later among the works it cites.
Llama: Open and efficient foundation language models
Touvron, H., Lavril, T., Izacard, G., Martinet, X., Lachaux, M.A., Lacroix, T., Rozière, B., Goyal, N., Hambro, E., Azhar, F., et al., 2023 · 2023
Later among the works it cites.
A prompt pattern catalog to enhance prompt engineering with chatgpt
White, J., Fu, Q., Hays, S., Sandborn, M., Olea, C., Gilbert, H., Elnashar, A., Spencer-Smith, J., Schmidt, D.C., 2023 · 2023
Later among the works it cites.
Grace: Empowering llm-based software vulnerability detection with graph structure and in-context learning
Lu, G., Ju, X., Chen, X., Pei, W., Cai, Z., 2024 · 2024
Closest in time.