Fetching the paper…
Reading the bibliography…
Achieving reproducibility, quantity, and diversity in vulnerability datasets has long been viewed as an inherent three-way trade-off, where improving one dimension often comes at the cost of the others.
OPUS: Online patches and updates for security
Gautam Altekar, Ilya Bagrak, Paul Burstein, and Andrew Schultz · 2005
Earlier work this paper cites.
GenProg: A Generic Method for Automatic Software Repair
Claire Le Goues, ThanhVu Nguyen, Stephanie Forrest, and Westley Weimer · 2012
Earlier work this paper cites.
VCCFinder: Finding potential vulnerabilities in open-source projects to assist code audits
Henning Perl, Sergej Dechand, Matthew Smith, Daniel Arp, Fabian Yamaguchi, Konrad Rieck, Sascha Fahl, and Yasemin Acar · 2015
Earlier work this paper cites.
Lava: Large-scale automated vulnerability addition
Brendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek, Andrea Mambretti, Wil Robertson, Frederick Ulrich, and Ryan Whelan · 2016
Earlier work this paper cites.
OSS-Fuzz - Google’s continuous fuzzing service for open source software
Kostya Serebryany · 2017
Earlier work this paper cites.
Adaptive android kernel live patching
Yue Chen, Yulong Zhang, Zhi Wang, Liangzhao Xia, Chenfu Bao, and Tao Wei · 2017
Earlier work this paper cites.
A Large-Scale Empirical Study of Security Patches
Frank Li and Vern Paxson · 2017
Earlier work this paper cites.
Evaluating fuzz testing
George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks · 2018
Earlier work this paper cites.
Understanding the reproducibility of crowd-reported security vulnerabilities
Dongliang Mu, Alejandro Cuevas, Limin Yang, Hang Hu, Xinyu Xing, Bing Mao, and Gang Wang · 2018
Earlier work this paper cites.
Precise and accurate patch presence test for binaries
Hang Zhang and Zhiyun Qian · 2018
Earlier work this paper cites.
Automated program repair
Claire Le Goues, Michael Pradel, and Abhik Roychoudhury · 2019
Earlier work this paper cites.
Magma: A ground-truth fuzzing benchmark
Ahmad Hazimeh, Adrian Herrera, and Mathias Payer · 2020
Cited alongside, same era.
BScout: Direct whole patch presence test for java executables
Jiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou, Junyan Chen, Xinyu Xing, Xiaohan Zhang, Xin Tan, Min Yang, and Zhemin Yang · 2020
Cited alongside, same era.
PDiff: Semantic-based patch presence testing for downstream kernels
Zheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen, Zhenghe Wang, Xiaohan Zhang, Xinyu Xing, Min Yang, and Zhemin Yang · 2020
Cited alongside, same era.
A C/C++ Code Vulnerability Dataset with Code Changes and CVE Summaries
Jiahao Fan, Yi Li, Shaohua Wang, and Tien N. Nguyen · 2020
Cited alongside, same era.
CVEfixes: automated collection of vulnerabilities and their fixes from open-source software
Guru Bhandari, Amara Naseer, and Leon Moonen · 2021
Cited alongside, same era.
Locating the security patches for disclosed OSS vulnerabilities with vulnerability-commit correlation ranking
CISA Open Source Software Security Roadmap
CISA · 2023
Later among the works it cites.
The FormAI dataset: Generative AI in software security through the lens of formal verification
Norbert Tihanyi, Tamas Bisztray, Ridhi Jain, Mohamed Amine Ferrag, Lucas C. Cordeiro, and Vasileios Mavroeidis · 2023
Later among the works it cites.
DiverseVul: A new vulnerable source code dataset for deep learning based vulnerability detection
Yizheng Chen, Zhoujie Ding, Lamya Alowain, Xinyun Chen, and David Wagner · 2023
Later among the works it cites.
CGC dataset
Cyber Grand Challenge · 2024
Closest in time.
Octoverse: AI leads Python to top language as the number of global developers surges
GitHub Staff · 2024
Closest in time.
AddressSanitizer
Google · 2024
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Xin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao, Kun Sun, Yifan Lin, and Min Yang · 2021
Cited alongside, same era.
Beyond Tests: Program Vulnerability Repair via Crash Constraint Extraction
Xiang Gao, Bo Wang, Gregory J. Duck, Ruyi Ji, Yingfei Xiong, and Abhik Roychoudhury · 2021
Cited alongside, same era.
D2A: A dataset built for AI-based vulnerability detection methods using differential analysis
Yunhui Zheng, Saurabh Pujar, Burn Lewis, Luca Buratti, Edward Epstein, Bo Yang, Jim Laredo, Alessandro Morari, and Zhong Su · 2021
Cited alongside, same era.
Automated patch transplantation
Ridwan Salihin Shariffdeen, Shin Hwei Tan, Mingyuan Gao, and Abhik Roychoudhury · 2021
Cited alongside, same era.
Automated patch backporting in Linux (experience paper)
Ridwan Shariffdeen, Xiang Gao, Gregory J. Duck, Shin Hwei Tan, Julia Lawall, and Abhik Roychoudhury · 2021
Cited alongside, same era.
https://syzkaller.appspot.com/
syzbot
Cited in the paper.
https://issues.oss-fuzz.com/issues/42486945
OSS-Fuzz issue 42486945
Cited in the paper.
Yangruibo Ding, Yanjun Fu, Omniyyah Ibrahim, Chawin Sitawarin, Xinyun Chen, Basel Alomair, David Wagner, Baishakhi Ray, and Yizheng Chen · 2024
Closest in time.
AI Cyber Challenge (AIxCC)
DARPA · 2025
Closest in time.
CyberGym: Evaluating AI agents’ cybersecurity capabilities with real-world vulnerabilities at scale, 2025
Zhun Wang, Tianneng Shi, Jingxuan He, Matthew Cai, Jialin Zhang, and Dawn Song · 2025
Closest in time.
PATCHAGENT: A practical program repair agent mimicking human expertise
Zheng Yu, Ziyi Guo, Yuhang Wu, Jiahao Yu, Meng Xu, Dongliang Mu, Yan Chen, and Xinyu Xing · 2025
Closest in time.