Fetching the paper…
Reading the bibliography…
Timely and effective vulnerability patching is essential for cybersecurity defense, for which various approaches have been proposed yet still struggle to generate valid and correct patches for real-world vulnerabilities.
Interprocedural slicing using dependence graphs
Susan Horwitz, Thomas Reps, and David Binkley · 1990
Earlier work this paper cites.
Union slices for program maintenance
Árpád Beszédes, Csaba Faragó, Z Mihaly Szabo, János Csirik, and Tibor Gyimóthy · 2002
Earlier work this paper cites.
An empirical study of static program slice size
David Binkley, Nicolas Gold, and Mark Harman · 2007
Earlier work this paper cites.
Vurle: Automatic vulnerability detection and repair by learning from examples
Siqi Ma, Ferdian Thung, David Lo, Cong Sun, and Robert H Deng · 2017
Earlier work this paper cites.
Attention is all you need
Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, Łukasz Kaiser, and Illia Polosukhin · 2017
Earlier work this paper cites.
Getafix: Learning to fix bugs automatically
Johannes Bader, Andrew Scott, Michael Pradel, and Satish Chandra · 2019
Earlier work this paper cites.
Using safety properties to generate vulnerability patches
Zhen Huang, David Lie, Gang Tan, and Trent Jaeger · 2019
Earlier work this paper cites.
https://codeql.github.com/docs/ , 2021
CodeQL documentation · 2021
Earlier work this paper cites.
CVEfixes: Automated collection of vulnerabilities and their fixes from open-source software
Guru Bhandari, Amara Naseer, and Leon Moonen · 2021
Earlier work this paper cites.
FlowDist: Multi-staged refinement-based dynamic information flow analysis for distributed software systems
Xiaoqin Fu and Haipeng Cai · 2021
Earlier work this paper cites.
Beyond tests: Program vulnerability repair via crash constraint extraction
Xiang Gao, Bo Wang, Gregory J Duck, Ruyi Ji, Yingfei Xiong, and Abhik Roychoudhury · 2021
Earlier work this paper cites.
SySeVR: A framework for using deep learning to detect software vulnerabilities
Zhen Li, Deqing Zou, Shouhuai Xu, Hai Jin, Yawei Zhu, and Zhaoxuan Chen · 2021
Earlier work this paper cites.
PatchDB: A large-scale security patch dataset
Xinda Wang, Shu Wang, Pengbin Feng, Kun Sun, and Sushil Jajodia · 2021
Earlier work this paper cites.
CodeT5: Identifier-aware unified pre-trained encoder-decoder models for code understanding and generation
Yue Wang, Weishi Wang, Shafiq Joty, and Steven CH Hoi · 2021
Earlier work this paper cites.
GPT-NeoX-20B: An open-source autoregressive language model
Sidney Black, Stella Biderman, Eric Hallahan, Quentin Anthony, Leo Gao, Laurence Golding, Horace He, Connor Leahy, Kyle McDonell, Jason Phang, et al · 2022
Earlier work this paper cites.
Neural transfer learning for repairing security vulnerabilities in C code
Zimin Chen, Steve Kommrusch, and Martin Monperrus · 2022
Earlier work this paper cites.
LineVul: A Transformer-based line-level vulnerability prediction
Michael Fu and Chakkrit Tantithamthavorn · 2022
Earlier work this paper cites.
VulRepair: A T5-based automated software vulnerability repair
Michael Fu, Chakkrit Tantithamthavorn, Trung Le, Van Nguyen, and Dinh Phung · 2022
Earlier work this paper cites.
LineVD: Statement-level vulnerability detection using graph neural networks
David Hin, Andrey Kan, Huaming Chen, and M Ali Babar · 2022
Earlier work this paper cites.
The secret life of software vulnerabilities: A large-scale empirical study
Emanuele Iannone, Roberta Guadagni, Filomena Ferrucci, Andrea De Lucia, and Fabio Palomba · 2022
Cited alongside, same era.
PolyCruise: A cross-language dynamic information flow analysis
Wen Li, Jiang Ming, Xiapu Luo, and Haipeng Cai · 2022
Cited alongside, same era.
Generating realistic vulnerabilities via neural code editing: An empirical study
Yu Nong, Yuzhe Ou, Michael Pradel, Feng Chen, and Haipeng Cai · 2022
Cited alongside, same era.
Open science in software engineering: A study on deep learning-based vulnerability detection
Yu Nong, Rainy Sharma, Abdelwahab Hamou-Lhadj, Xiapu Luo, and Haipeng Cai · 2022
Cited alongside, same era.
Chain-of-thought prompting elicits reasoning in large language models
Jason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma, Fei Xia, Ed Chi, Quoc V Le, Denny Zhou, et al · 2022
Cited alongside, same era.
VulGen: Realistic vulnerable sample generation via pattern mining and deep learning
Yu Nong, Yuzhe Ou, Michael Pradel, Feng Chen, and Haipeng Cai · 2023
Later among the works it cites.
Examining zero-shot vulnerability repair with large language models
Hammond Pearce, Benjamin Tan, Baleegh Ahmad, Ramesh Karri, and Brendan Dolan-Gavitt · 2023
Later among the works it cites.
Software vulnerability detection using large language models
Moumita Das Purba, Arpita Ghosh, Benjamin J Radford, and Bill Chu · 2023
Later among the works it cites.
Gemini: A family of highly capable multimodal models
Gemini Team, Rohan Anil, Sebastian Borgeaud, Yonghui Wu, Jean-Baptiste Alayrac, Jiahui Yu, Radu Soricut, Johan Schalkwyk, Andrew M Dai, Anja Hauth, et al · 2023
Later among the works it cites.
Llama 2: Open foundation and fine-tuned chat models
Hugo Touvron, Louis Martin, Kevin Stone, Peter Albert, Amjad Almahairi, Yasmine Babaei, Nikolay Bashlykov, Soumya Batra, Prajjwal Bhargava, Shruti Bhosale, et al · 2023
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Fabian Yamaguchi · 2022
Cited alongside, same era.
Example-based vulnerability detection and repair in Java code
Ying Zhang, Ya Xiao, Md Mahir Asef Kabir, Danfeng Yao, and Na Meng · 2022
Cited alongside, same era.
Program vulnerability repair via inductive inference
Yuntong Zhang, Xiang Gao, Gregory J Duck, and Abhik Roychoudhury · 2022
Cited alongside, same era.
https://ai.meta.com/blog/code-llama-large-language-model-coding/ , 2023
Introducing Code Llama, A state-of-the-art large language model for coding · 2023
Cited alongside, same era.
Generating vulnerable code via learning-based program transformations
Haipeng Cai, Yu Nong, Yuzhe Ou, and Feng Chen · 2023
Cited alongside, same era.
Software vulnerability: Impact & ways to avoid it
Ericsson · 2023
Cited alongside, same era.
Zero-day vulnerabilities: 17 consequences and complications
Forbes Technology Council · 2023
Cited alongside, same era.
Later among the works it cites.
How effective are neural networks for fixing security vulnerabilities
Yi Wu, Nan Jiang, Hung Viet Pham, Thibaud Lutellier, Jordan Davis, Lin Tan, Petr Babkin, and Sameena Shah · 2023
Later among the works it cites.
Falcon LLM: A new frontier in natural language processing
Yoshua X ZXhang, Yann M Haxo, and Ying X Mat · 2023
Later among the works it cites.
https://qwenlm.github.io/blog/codeqwen1.5/ , 2024
Code with CodeQwen1.5 · 2024
Closest in time.
https://dwheeler.com/flawfinder/ , 2024
A fool with a tool is still a fool · 2024
Closest in time.
https://www.anthropic.com/claude , 2024
Meet claude · 2024
Closest in time.
https://codeql.github.com/docs/writing-codeql-queries/metadata-for-codeql-queries/ , 2024
Metadata for CodeQL queries · 2024
Closest in time.
An empirical study of static analysis tools for secure code review
Wachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, and Christoph Treude · 2024
Closest in time.
Enhancing static analysis for practical bug detection: An LLM-integrated approach
Haonan Li, Yu Hao, Yizhuo Zhai, and Zhiyun Qian · 2024
Closest in time.
Yu Nong, Mohammed Aldeen, Long Cheng, Hongxin Hu, Feng Chen, and Haipeng Cai · 2024
Closest in time.
VGX: Large-scale sample generation for boosting learning-based software vulnerability analyses
Yu Nong, Richard Fang, Guangbei Yi, Kunsong Zhao, Xiapu Luo, Feng Chen, and Haipeng Cai · 2024
Closest in time.
Automated software vulnerability patching using large language models
Yu Nong, Haoran Yang, Long Cheng, Hongxin Hu, and Haipeng Cai · 2024
Closest in time.
LLMs cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks
Saad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce, Ayse Coskun, and Gianluca Stringhini · 2024
Closest in time.
Large language model for vulnerability detection and repair: Literature review and roadmap
Xin Zhou, Sicong Cao, Xiaobing Sun, and David Lo · 2024
Closest in time.
DeepSeek-Coder-V2: Breaking the barrier of closed-source models in code intelligence
Qihao Zhu, Daya Guo, Zhihong Shao, Dejian Yang, Peiyi Wang, Runxin Xu, Y Wu, Yukun Li, Huazuo Gao, Shirong Ma, et al · 2024
Closest in time.