Fetching the paper…
Reading the bibliography…
Software is prone to security vulnerabilities.
Taming false alarms from a domain-unaware C analyzer by a Bayesian statistical post analysis
Yungbum Jung, Jaehwang Kim, Jaeho Shin, and Kwangkeun Yi · 2005
Earlier work this paper cites.
A model building process for identifying actionable static analysis alerts
Sarah Heckman and Laurie Williams · 2009
Earlier work this paper cites.
Merlin: Specification inference for explicit information flow problems
Benjamin Livshits, Aditya V. Nori, Sriram K Rajamani, and Anindya Banerjee · 2009
Earlier work this paper cites.
Using Datalog for fast and easy program analysis
Yannis Smaragdakis and Martin Bravenboer · 2010
Earlier work this paper cites.
Why don’t software developers use static analysis tools to find bugs?
Brittany Johnson, Yoonki Song, Emerson Murphy-Hill, and Robert Bowdidge · 2013
Earlier work this paper cites.
Finding patterns in static analysis alerts: improving actionable alert ranking
Quinn Hanam, Lin Tan, Reid Holmes, and Patrick Lam · 2014
Earlier work this paper cites.
QL: Object-oriented queries on relational data
Pavel Avgustinov, Oege de Moor, Michael Peyton Jones, and Max Schäfer · 2016
Earlier work this paper cites.
On fast large-scale program analysis in Datalog
Bernhard Scholz, Herbert Jordan, Pavle Subotić, and Till Westmann · 2016
Earlier work this paper cites.
Scalable taint specification inference with big code
Victor Chibotaru, Benjamin Bichsel, Veselin Raychev, and Martin Vechev · 2019
Earlier work this paper cites.
Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks
Yaqin Zhou, Shangqing Liu, J. Siow, Xiaoning Du, and Yang Liu · 2019
Earlier work this paper cites.
Deep learning based vulnerability detection: Are we there yet?
Saikat Chakraborty, Rahul Krishna, Yangruibo Ding, and Baishakhi Ray · 2020
Earlier work this paper cites.
Hoppity: Learning graph transformations to detect and fix bugs in programs
Elizabeth Dinella, Hanjun Dai, Ziyang Li, Mayur Naik, Le Song, and Ke Wang · 2020
Earlier work this paper cites.
An empirical study on the persistence of spotbugs issues in open-source software evolution
Luigi Lavazza, Davide Tosi, and Sandro Morasca · 2020
Earlier work this paper cites.
VulDeeLocator: A deep learning-based fine-grained vulnerability detector
Zhuguo Li, Deqing Zou, Shouhuai Xu, Zhaoxuan Chen, Yawei Zhu, and Hai Jin · 2020
Earlier work this paper cites.
Path-sensitive code embedding via contrastive learning for software vulnerability detection
Xiao Cheng, Guanqin Zhang, Haoyu Wang, and Yulei Sui · 2022
Earlier work this paper cites.
Inspectjs: Leveraging code similarity and user-feedback for effective taint specification inference for Javascript
Saikat Dutta, Diego Garbervetsky, Shuvendu K Lahiri, and Max Schäfer · 2022
Cited alongside, same era.
LineVul: A transformer-based line-level vulnerability prediction
Michael Fu and Chakkrit Tantithamthavorn · 2022
Cited alongside, same era.
Linevd: Statement-level vulnerability detection using graph neural networks
David Hin, Andrey Kan, Huaming Chen, and Muhammad Ali Babar · 2022
Cited alongside, same era.
Detecting false alarms from automatic static analysis tools: How far are we?
Hong Jin Kang, Khai Loong Aw, and David Lo · 2022
Cited alongside, same era.
An empirical study on the effectiveness of static C code analyzers for vulnerability detection
Stephan Lipp, Sebastian Banescu, and Alexander Pretschner · 2022
Cited alongside, same era.
CODAMOSA: Escaping coverage plateaus in test generation with pre-trained large language models
Caroline Lemieux, Jeevana Priya Inala, Shuvendu K Lahiri, and Siddhartha Sen · 2023
Later among the works it cites.
The Semgrep platform
Semgrep · 2023
Later among the works it cites.
Dataflow analysis-inspired deep learning for efficient vulnerability detection
Benjamin Steenhoek, Hongyang Gao, and Wei Le · 2023
Later among the works it cites.
Automated program repair in the era of large pre-trained language models
Chunqiu Steven Xia, Yuxiang Wei, and Lingming Zhang · 2023
Later among the works it cites.
Large language models for test-free fault localization
Aidan ZH Yang, Ruben Martins, Claire Le Goues, and Vincent J Hellendoorn · 2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Less training, more repairing please: revisiting automated program repair via zero-shot learning
Chunqiu Steven Xia and Lingming Zhang · 2022
Cited alongside, same era.
Improving Java deserialization gadget chain mining via overriding-guided object generation
Sicong Cao, Xiaobing Sun, Xiaoxue Wu, Lili Bo, Bin Li, Rongxin Wu, Wei Liu, Biao He, Yu Ouyang, and Jiajia Li · 2023
Cited alongside, same era.
https://github.com/Ericsson/codechecker
Code Checker, 2023 · 2023
Cited alongside, same era.
https://cppcheck.sourceforge.io/
CPPCheck, 2023 · 2023
Cited alongside, same era.
https://fbinfer.com/
FB Infer, 2023 · 2023
Cited alongside, same era.
https://dwheeler.com/flawfinder
FlawFinder, 2023 · 2023
Cited alongside, same era.
Large language models for code: Security hardening and adversarial testing
Jingxuan He and Martin Vechev · 2023
Cited alongside, same era.
https://checkerframework.org/
Checker Framework, 2024 · 2024
Closest in time.
https://www.cvedetails.com
CVE Trends, 2024 · 2024
Closest in time.
Vulnerability detection with code language models: How far are we?
Yangruibo Ding, Yanjun Fu, Omniyyah Ibrahim, Chawin Sitawarin, Xinyun Chen, Basel Alomair, David Wagner, Baishakhi Ray, and Yizheng Chen · 2024
Closest in time.
Enhancing static analysis for practical bug detection: An llm-integrated approach
Haonan Li, Yu Hao, Yizhuo Zhai, and Zhiyun Qian · 2024
Closest in time.
Lost in translation: A study of bugs introduced by large language models while translating code
Rangeet Pan, Ali Reza Ibrahimzada, Rahul Krishna, Divya Sankar, Lambert Pouguem Wassi, Michele Merler, Boris Sobolev, Raju Pavuluri, Saurabh Sinha, and Reyhaneh Jabbarvand · 2024
Closest in time.
https://snyk.io
Snyk.io, 2024 · 2024
Closest in time.
https://www.sonarsource.com/products/sonarqube
SonarQube, 2024 · 2024
Closest in time.
A comprehensive study of the capabilities of large language models for vulnerability detection
Benjamin Steenhoek, Md Mahbubur Rahman, Monoshi Kumar Roy, Mirza Sanjida Alam, Earl T Barr, and Wei Le · 2024
Closest in time.
LLMDFA: Analyzing dataflow in code with large language models
Chengpeng Wang, Wuqi Zhang, Zian Su, Xiangzhe Xu, Xiaoheng Xie, and Xiangyu Zhang · 2024
Closest in time.
Fuzz4all: Universal fuzzing with large language models
Chunqiu Steven Xia, Matteo Paltenghi, Jia Le Tian, Michael Pradel, and Lingming Zhang · 2024
Closest in time.