Fetching the paper…
Reading the bibliography…
Security vulnerabilities in software packages are a significant concern for developers and users alike.
American Fuzzy Lop (AFL)
Michal Zalewski. 2013 · 2013
Earlier work this paper cites.
Coverage-Based Greybox Fuzzing as Markov Chain
Marcel Böhme, Van-Thuan Pham, and Abhik Roychoudhury. 2019 · 2017
Earlier work this paper cites.
Learning to Repair Software Vulnerabilities with Generative Adversarial Networks. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018, 3-8 December 2018, Montréal, Canada. 7944–7954
Jacob Harer, Onur Ozdemir, Tomo Lazovich, Christopher P. Reale, Rebecca L. Russell, Louis Y. Kim, and Sang Peter Chin. 2018 · 2018
Earlier work this paper cites.
Evaluating Fuzz Testing. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS 2018, Toronto, ON, Canada, October 15-19, 2018 , David Lie, Mohammad Mannan, Michael Backes, and XiaoFeng Wang (Eds.). ACM, 2123–2138
George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks. 2018 · 2018
Earlier work this paper cites.
VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In NDSS
Zhen Li, Shouhuai Xu Deqing Zou and, Xinyu Ou, Hai Jin, Sujuan Wang, Zhijun Deng, and Yuyi Zhong. 2018 · 2018
Earlier work this paper cites.
Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web Servers. In USENIX Security Symposium . 361–376
Cristian-Alexandru Staicu and Michael Pradel. 2018 · 2018
Earlier work this paper cites.
Understanding and Automatically Preventing Injection Attacks on Node.js. In Network and Distributed System Security Symposium (NDSS)
Cristian-Alexandru Staicu, Michael Pradel, and Ben Livshits. 2018 · 2018
Earlier work this paper cites.
Small World with High Risks: A Study of Security Threats in the Npm Ecosystem. In 28th USENIX Security Symposium (USENIX Security 19) . 995–1010
Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019 · 2019
Earlier work this paper cites.
RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and Sanitization. In 2020 IEEE Symposium on Security and Privacy, SP 2020, San Francisco, CA, USA, May 18-21, 2020 . IEEE, 1497–1511
Sushant Dinesh, Nathan Burow, Dongyan Xu, and Mathias Payer. 2020 · 2020
Earlier work this paper cites.
Historical Analysis of Exploit Availability Timelines
Allen D Householder, Jeff Chrabaszcz, Trent Novelly, and David Warren. 2020 · 2020
Earlier work this paper cites.
Mininode: Reducing the Attack Surface of Node.js Applications. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) . USENIX Association, San Sebastian, 121–134
Igibek Koishybayev and Alexandros Kapravelos. 2020 · 2020
Earlier work this paper cites.
Deep Learning Based Vulnerability Detection: Are We There Yet?
Saikat Chakraborty, Rahul Krishna, Yangruibo Ding, and Baishakhi Ray. 2022 · 2021
Earlier work this paper cites.
Evaluating Large Language Models Trained on Code
Mark Chen, Jerry Tworek, Heewoo Jun, Qiming Yuan, Henrique Ponde de Oliveira Pinto, Jared Kaplan, Harrison Edwards, Yuri Burda, Nicholas Joseph, Greg Brockman, Alex Ray, Raul Puri, Gretchen Krueger, Michael Petrov, Heidy Khlaaf, Girish Sastry, Pamela Mishkin, Brooke Chan, Scott Gray, Nick Ryder, Mikhail Pavlov, Alethea Power, Lukasz Kaiser, Mohammad Bavarian, Clemens Winter, Philippe Tillet, Felipe Petroski Such, Dave Cummings, Matthias Plappert, Fotios Chantzis, Elizabeth Barnes, Ariel Herbert-Voss, William Hebgen Guss, Alex Nichol, Alex Paino, Nikolas Tezak, Jie Tang, Igor Babuschkin, Suchir Balaji, Shantanu Jain, William Saunders, Christopher Hesse, Andrew N. Carr, Jan Leike, Joshua Achiam, Vedant Misra, Evan Morikawa, Alec Radford, Matthew Knight, Miles Brundage, Mira Murati, Katie Mayer, Peter Welinder, Bob McGrew, Dario Amodei, Sam McCandlish, Ilya Sutskever, and Wojciech Zaremba. 2021 · 2021
Earlier work this paper cites.
Vulnerability detection with fine-grained interpretations. In ESEC/FSE ’21: 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Athens, Greece, August 23-28, 2021 , Diomidis Spinellis, Georgios Gousios, Marsha Chechik, and Massimiliano Di Penta (Eds.). ACM, 292–303
Yi Li, Shaohua Wang, and Tien N. Nguyen. 2021b · 2021
Earlier work this paper cites.
Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege Reduction. In CCS ’21: 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event, Republic of Korea, November 15 - 19, 2021 , Yongdae Kim, Jong Kim, Giovanni Vigna, and Elaine Shi (Eds.). ACM, 1821–1838
Nikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas, Ben Karel, André DeHon, and Michael Pradel. 2021 · 2021
Earlier work this paper cites.
D2A: A Dataset Built for AI-Based Vulnerability Detection Methods Using Differential Analysis. In 43rd IEEE/ACM International Conference on Software Engineering: Software Engineering in Practice, ICSE (SEIP) 2021, Madrid, Spain, May 25-28, 2021 . IEEE, 111–120
Yunhui Zheng, Saurabh Pujar, Burn L. Lewis, Luca Buratti, Edward A. Epstein, Bo Yang, Jim Laredo, Alessandro Morari, and Zhong Su. 2021 · 2021
Earlier work this paper cites.
LineVul: A Transformer-based Line-Level Vulnerability Prediction. In 19th IEEE/ACM International Conference on Mining Software Repositories, MSR . ACM, 608–620
Michael Fu and Chakkrit Tantithamthavorn. 2022 · 2022
Cited alongside, same era.
Demystifying the Vulnerability Propagation and Its Evolution via Dependency Trees in the NPM Ecosystem. In ICSE
Chengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen, Yang Liu, and Xin Peng. 2022 · 2022
Cited alongside, same era.
Generating Realistic Vulnerabilities via Neural Code Editing: An Empirical Study. In ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE)
Yu Nong, Yuzhe Ou, Michael Pradel, Feng Chen, and Haipeng Cai. 2022 · 2022
Cited alongside, same era.
Practical Automated Detection of Malicious npm Packages. In ICSE
Adriana Sejfia and Max Schaefer. 2022 · 2022
Cited alongside, same era.
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Soufian El Yadmani, Robin The, and Olga Gadyatskaya. 2023 · 2023
Later among the works it cites.
How Well Does LLM Generate Security Tests?
Ying Zhang, Wenjia Song, Zhengjie Ji, Danfeng, Yao, and Na Meng. 2023 · 2023
Later among the works it cites.
DeepCode AI Fix: Fixing Security Vulnerabilities with Large Language Models
Berkay Berabi, Alexey Gronskiy, Veselin Raychev, Gishor Sivanrupan, Victor Chibotaru, and Martin T. Vechev. 2024 · 2024
Later among the works it cites.
LLM-Assisted Static Analysis for Detecting Security Vulnerabilities
Ziyang Li, Saikat Dutta, and Mayur Naik. 2024 · 2024
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Nusrat Zahan, Thomas Zimmermann, Patrice Godefroid, Brendan Murphy, Chandra Maddila, and Laurie Williams. 2022 · 2022
Cited alongside, same era.
FixReverter: A Realistic Bug Injection Methodology for Benchmarking Fuzz Testing. In Proceedings of the 31st USENIX Security Symposium
Zenong Zhang, Zach Patterson, Michael Hicks, and Shiyi Wei. 2022 · 2022
Cited alongside, same era.
SecBench.Js: An Executable Security Benchmark Suite for Server-Side JavaScript. In 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE) . 1059–1070
Masudul Hasan Masud Bhuiyan, Adithya Srinivas Parthasarathy, Nikos Vasilakis, Michael Pradel, and Cristian-Alexandru Staicu. 2023 · 2023
Cited alongside, same era.
Study of JavaScript Static Analysis Tools for Vulnerability Detection in Node.Js Packages
Tiago Brito, Mafalda Ferreira, Miguel Monteiro, Pedro Lopes, Miguel Barros, José Fragoso Santos, and Nuno Santos. 2023 · 2023
Cited alongside, same era.
NodeMedic: End-to-End Analysis of Node.Js Vulnerabilities with Provenance Graphs. In 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) . 1101–1127
Darion Cassel, Wai Tuck Wong, and Limin Jia. 2023 · 2023
Cited alongside, same era.
P. V. Sai Charan, Hrushikesh Chunduri, P. Mohan Anand, and Sandeep K. Shukla. 2023 · 2023
Cited alongside, same era.
Impact of Code Language Models on Automated Program Repair. In ICSE . 1430–1442
Nan Jiang, Kevin Liu, Thibaud Lutellier, and Lin Tan. 2023 · 2023
Cited alongside, same era.
InferFix: End-to-End Program Repair with LLMs. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering . ACM, San Francisco CA USA, 1646–1656
Matthew Jin, Syed Shahriar, Michele Tufano, Xin Shi, Shuai Lu, Neel Sundaresan, and Alexey Svyatkovskiy. 2023 · 2023
Cited alongside, same era.
Dataflow Analysis-Inspired Deep Learning for Efficient Vulnerability Detection. In Proceedings of the 46th IEEE/ACM International Conference on Software Engineering . 1–13
Benjamin Steenhoek, Hongyang Gao, and Wei Le. 2024 · 2024
Later among the works it cites.
Automated Program Repair via Conversation: Fixing 162 out of 337 Bugs for $0.42 Each using ChatGPT. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2024, Vienna, Austria, September 16-20, 2024 , Maria Christakis and Michael Pradel (Eds.). ACM, 819–831
Chunqiu Steven Xia and Lingming Zhang. 2024 · 2024
Later among the works it cites.
AutoAttacker: A Large Language Model Guided System to Implement Automatic Cyber-attacks
Jiacen Xu, Jack W. Stokes, Geoff McDonald, Xuesong Bai, David Marshall, Siyue Wang, Adith Swaminathan, and Zhou Li. 2024 · 2024
Later among the works it cites.
SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024, Vancouver, BC, Canada, December 10 - 15, 2024 , Amir Globersons, Lester Mackey, Danielle Belgrave, Angela Fan, Ulrich Paquet, Jakub M. Tomczak, and Cheng Zhang (Eds.)
John Yang, Carlos E. Jimenez, Alexander Wettig, Kilian Lieret, Shunyu Yao, Karthik Narasimhan, and Ofir Press. 2024 · 2024
Later among the works it cites.
CVE: Common Vulnerabilities and Exposures
[n. d.] · 2025
Closest in time.
RepairAgent: An Autonomous, LLM-Based Agent for Program Repair. In International Conference on Software Engineering (ICSE)
Islem Bouzenia, Premkumar Devanbu, and Michael Pradel. 2025 · 2025
Closest in time.
You Name It, I Run It: An LLM Agent to Execute Tests of Arbitrary Projects. In ISSTA
Islem Bouzenia and Michael Pradel. 2025 · 2025
Closest in time.
NodeMedic-FINE: Automatic Detection and Exploit Synthesis for Node.Js Vulnerabilities. In Proceedings 2025 Network and Distributed System Security Symposium . Internet Society, San Diego, CA, USA
Darion Cassel, Nuno Sabino, Min-Chien Hsu, Ruben Martins, and Limin Jia. 2025 · 2025
Closest in time.
Vulnerability-Triggering Test Case Generation from Third-Party Libraries
Yi Gao, Xing Hu, Zirui Chen, and Xiaohu Yang. 2025 · 2025
Closest in time.
Automated Exploit Generation for Node.js Packages. In PLDI
Filipe Marques, Mafalda Ferreira, André Nascimento, Miguel E Coimbra, Nuno Santos, Limin Jia, and José Fragoso Santos. 2025 · 2025
Closest in time.
PwnGPT: Automatic Exploit Generation Based on Large Language Models. In Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers) (Vienna, Austria, 2025-07), Wanxiang Che, Joyce Nabende, Ekaterina Shutova, and Mohammad Taher Pilehvar (Eds.). Association for Computational Linguistics, 11481–11494
Wanzong Peng, Lin Ye, Xuetao Du, Hongli Zhang, Dongyang Zhan, Yunting Zhang, Yicheng Guo, and Chen Zhang. [n. d.] · 2025
Closest in time.
No Harness, No Problem: Oracle-guided Harnessing for Auto-generating C API Fuzzing Harnesses. In 2025 IEEE/ACM 47th International Conference on Software Engineering (ICSE) . IEEE Computer Society, 775–775
Gabriel Sherman and Stefan Nagy. 2025 · 2025
Closest in time.