{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,20]],"date-time":"2025-07-20T03:56:05Z","timestamp":1752983765035,"version":"3.40.3"},"publisher-location":"Cham","reference-count":40,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031641701"},{"type":"electronic","value":"9783031641718"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-64171-8_18","type":"book-chapter","created":{"date-parts":[[2024,7,10]],"date-time":"2024-07-10T11:02:33Z","timestamp":1720609353000},"page":"350-369","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Pairing Security Advisories with\u00a0Vulnerable Functions Using Open-Source LLMs"],"prefix":"10.1007","author":[{"given":"Trevor","family":"Dunlap","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John Speed","family":"Meyers","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bradley","family":"Reaves","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Enck","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,9]]},"reference":[{"key":"18_CR1","unstructured":"Alahmadi, B.A., Axon, L., Martinovic, I.: 99% false positives: a qualitative study of SOC analysts\u2019 perspectives on security alarms. In: 31st USENIX Security Symposium (USENIX Security 2022), pp. 2783\u20132800. USENIX Association (2022)"},{"key":"18_CR2","unstructured":"Alomar, N., Wijesekera, P., Qiu, E., Egelman, S.: \u201cYou\u2019ve got your nice list of bugs, now what?\u201d Vulnerability discovery and management processes in the wild. In: Proceedings of the Sixteenth USENIX Conference on Usable Privacy and Security, SOUPS 2020. USENIX Association (2020)"},{"key":"18_CR3","unstructured":"Arora, A.: Understanding logits, sigmoid, softmax, and cross-entropy loss in deep learning\u2014wandb.ai (2023). https:\/\/wandb.ai\/amanarora\/Written-Reports\/reports\/Understanding-Logits-Sigmoid-Softmax-and-Cross-Entropy-Loss-in-Deep-Learning--Vmlldzo0NDMzNTU3"},{"key":"18_CR4","doi-asserted-by":"publisher","unstructured":"Bhandari, G., Naseer, A., Moonen, L.: CVEfixes: automated collection of vulnerabilities and their fixes from open-source software. In: Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering, PROMISE 2021, pp. 30\u201339. Association for Computing Machinery, New York (2021). https:\/\/doi.org\/10.1145\/3475960.3475985","DOI":"10.1145\/3475960.3475985"},{"key":"18_CR5","unstructured":"Bi, X., et al.: DeepSeek LLM: scaling open-source language models with longtermism. arXiv preprint arXiv:2401.02954 (2024)"},{"key":"18_CR6","unstructured":"Brown, T.B., et al.: Language models are few-shot learners. In: Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS 2020. Curran Associates Inc. (2020)"},{"issue":"09","key":"18_CR7","doi-asserted-by":"publisher","first-page":"3280","DOI":"10.1109\/TSE.2021.3087402","volume":"48","author":"S Chakraborty","year":"2022","unstructured":"Chakraborty, S., Krishna, R., Ding, Y., Ray, B.: Deep learning based vulnerability detection: are we there yet? IEEE Trans. Softw. Eng. 48(09), 3280\u20133296 (2022). https:\/\/doi.org\/10.1109\/TSE.2021.3087402","journal-title":"IEEE Trans. Softw. Eng."},{"key":"18_CR8","doi-asserted-by":"publisher","unstructured":"Chen, Y., Ding, Z., Alowain, L., Chen, X., Wagner, D.: DiverseVul: a new vulnerable source code dataset for deep learning based vulnerability detection. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2023, pp. 654\u2013668. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3607199.3607242","DOI":"10.1145\/3607199.3607242"},{"key":"18_CR9","doi-asserted-by":"publisher","unstructured":"Croft, R., Babar, M.A., Kholoosi, M.M.: Data quality for software vulnerability datasets. In: Proceedings of the 45th International Conference on Software Engineering, ICSE 2023, pp. 121\u2013133 (2023). https:\/\/doi.org\/10.1109\/ICSE48619.2023.00022","DOI":"10.1109\/ICSE48619.2023.00022"},{"issue":"09","key":"18_CR10","doi-asserted-by":"publisher","first-page":"3613","DOI":"10.1109\/TSE.2021.3101739","volume":"48","author":"A Dann","year":"2022","unstructured":"Dann, A., Plate, H., Hermann, B., Ponta, S., Bodden, E.: Identifying challenges for OSS vulnerability scanners - a study & test suite. IEEE Trans. Softw. Eng. 48(09), 3613\u20133625 (2022). https:\/\/doi.org\/10.1109\/TSE.2021.3101739","journal-title":"IEEE Trans. Softw. Eng."},{"key":"18_CR11","doi-asserted-by":"publisher","unstructured":"Deng, Y., Xia, C.S., Peng, H., Yang, C., Zhang, L.: Large language models are zero-shot fuzzers: fuzzing deep-learning libraries via large language models. In: Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA 2023, pp. 423\u2013435. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3597926.3598067","DOI":"10.1145\/3597926.3598067"},{"key":"18_CR12","unstructured":"Douze, M., et al.: The faiss library. arXiv preprint arXiv:2401.08281 (2024)"},{"key":"18_CR13","unstructured":"Dunlap, T.: A python package for extracting commit features - patchparser (2022). https:\/\/github.com\/tdunlap607\/patchparser"},{"key":"18_CR14","unstructured":"EndorLabs: Endor Labs vs. SCA (2022). https:\/\/www.endorlabs.com\/endor-labs-vs-sca"},{"key":"18_CR15","doi-asserted-by":"publisher","unstructured":"Fan, J., Li, Y., Wang, S., Nguyen, T.N.: AC\/C++ code vulnerability dataset with code changes and CVE summaries. In: Proceedings of the 17th International Conference on Mining Software Repositories, MSR 2020, pp. 508\u2013512. Association for Computing Machinery (2020). https:\/\/doi.org\/10.1145\/3379597.3387501","DOI":"10.1145\/3379597.3387501"},{"key":"18_CR16","unstructured":"Google: Go Vulnerability Database. https:\/\/go.dev\/doc\/security\/vuln\/database"},{"key":"18_CR17","unstructured":"Google: Govulncheck. https:\/\/pkg.go.dev\/golang.org\/x\/vuln\/cmd\/govulncheck"},{"key":"18_CR18","unstructured":"Google: Handling Go Vulnerability Reports. https:\/\/github.com\/golang\/vulndb\/blob\/master\/doc\/triage.md#add-a-new-report-label-needsreport"},{"key":"18_CR19","unstructured":"Google: Vulnreport. https:\/\/pkg.go.dev\/golang.org\/x\/vulndb\/cmd\/vulnreport"},{"key":"18_CR20","doi-asserted-by":"publisher","unstructured":"Guo, Y., Bettaieb, S.: An investigation of quality issues in vulnerability detection datasets. In: 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW) (2023). https:\/\/doi.org\/10.1109\/EuroSPW59978.2023.00008","DOI":"10.1109\/EuroSPW59978.2023.00008"},{"key":"18_CR21","unstructured":"Jiang, A.Q., et al.: Mixtral of experts. arXiv preprint arXiv:2401.04088 (2024)"},{"key":"18_CR22","unstructured":"Khare, A., Dutta, S., Li, Z., Solko-Breslin, A., Alur, R., Naik, M.: Understanding the effectiveness of large language models in detecting security vulnerabilities. arXiv preprint arXiv:2311.16169 (2023)"},{"key":"18_CR23","unstructured":"LangChain: Custom example selector (2023). https:\/\/python.langchain.com\/docs\/modules\/model_io\/prompts\/example_selectors\/custom_example_selector"},{"key":"18_CR24","unstructured":"Li, H., Hao, Y., Zhai, Y., Qian, Z.: The Hitchhiker\u2019s guide to program analysis: a journey with large language models. arXiv preprint arXiv:2308.00245 (2023)"},{"key":"18_CR25","unstructured":"Liu, P., et al.: Harnessing the power of LLM to support binary taint analysis. arXiv preprint arXiv:2310.08275 (2023)"},{"key":"18_CR26","unstructured":"Luo, Z., et al.: WizardCoder: empowering code large language models with evol-instruct. arXiv preprint arXiv:2306.08568 (2023)"},{"key":"18_CR27","doi-asserted-by":"publisher","unstructured":"Nikitopoulos, G., Dritsa, K., Louridas, P., Mitropoulos, D.: CrossVul: a cross-language vulnerability dataset with commit data. In: Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/FSE 2021, pp. 1565\u20131569. Association for Computing Machinery, New York (2021). https:\/\/doi.org\/10.1145\/3468264.3473122","DOI":"10.1145\/3468264.3473122"},{"issue":"5","key":"18_CR28","doi-asserted-by":"publisher","first-page":"3175","DOI":"10.1007\/s10664-020-09830-x","volume":"25","author":"SE Ponta","year":"2020","unstructured":"Ponta, S.E., Plate, H., Sabetta, A.: Detection, assessment and mitigation of vulnerabilities in open source dependencies. Empir. Softw. Eng. 25(5), 3175\u20133215 (2020). https:\/\/doi.org\/10.1007\/s10664-020-09830-x","journal-title":"Empir. Softw. Eng."},{"key":"18_CR29","doi-asserted-by":"publisher","unstructured":"Purba, M.D., Ghosh, A., Radford, B.J., Chu, B.: Software vulnerability detection using large language models. In: 2023 IEEE 34th International Symposium on Software Reliability Engineering Workshops (ISSREW), pp. 112\u2013119 (2023). https:\/\/doi.org\/10.1109\/ISSREW60843.2023.00058","DOI":"10.1109\/ISSREW60843.2023.00058"},{"issue":"8","key":"18_CR30","first-page":"9","volume":"1","author":"A Radford","year":"2019","unstructured":"Radford, A., et al.: Language models are unsupervised multitask learners. OpenAI Blog 1(8), 9 (2019)","journal-title":"OpenAI Blog"},{"key":"18_CR31","unstructured":"Roziere, B., et al.: Code llama: open foundation models for code. arXiv preprint arXiv:2308.12950 (2023)"},{"key":"18_CR32","unstructured":"Sun, Y., et al.: LLM4Vuln: a unified evaluation framework for decoupling and enhancing LLMs\u2019 vulnerability reasoning. arXiv preprint arXiv:2401.16185 (2024)"},{"key":"18_CR33","unstructured":"TreeSitter: An incremental parsing system for programming tools - tree-sitter (2023). https:\/\/tree-sitter.github.io\/tree-sitter\/"},{"key":"18_CR34","unstructured":"Vaswani, A., et al.: Attention is all you need. In: Guyon, I., et al. (eds.) Advances in Neural Information Processing Systems, vol.\u00a030. Curran Associates, Inc. (2017)"},{"key":"18_CR35","doi-asserted-by":"crossref","unstructured":"Wang, X., Hu, R., Gao, C., Wen, X.C., Chen, Y., Liao, Q.: ReposVul: a repository-level high-quality vulnerability dataset. arXiv preprint arXiv:2401.13169 (2024)","DOI":"10.1145\/3639478.3647634"},{"key":"18_CR36","doi-asserted-by":"crossref","unstructured":"Wang, Y., Le, H., Gotmare, A.D., Bui, N.D., Li, J., Hoi, S.C.: CodeT5+: open code large language models for code understanding and generation. arXiv preprint arXiv:2305.07922 (2023)","DOI":"10.18653\/v1\/2023.emnlp-main.68"},{"key":"18_CR37","unstructured":"Wei, J., et al.: Finetuned language models are zero-shot learners. arXiv preprint arXiv:2109.01652 (2021)"},{"key":"18_CR38","unstructured":"Wei, J., et al.: Chain-of-thought prompting elicits reasoning in large language models. In: Koyejo, S., Mohamed, S., Agarwal, A., Belgrave, D., Cho, K., Oh, A. (eds.) Advances in Neural Information Processing Systems, vol.\u00a035, pp. 24824\u201324837. Curran Associates, Inc. (2022)"},{"key":"18_CR39","doi-asserted-by":"crossref","unstructured":"Zhang, C., Liu, H., Zeng, J., Yang, K., Li, Y., Li, H.: Prompt-enhanced software vulnerability detection using ChatGPT. arXiv preprint arXiv:2308.12697 (2023)","DOI":"10.1145\/3639478.3643065"},{"key":"18_CR40","unstructured":"Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y.: Devign: effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In: Wallach, H., Larochelle, H., Beygelzimer, A., d\u2019Alch\u00e9-Buc, F., Fox, E., Garnett, R. (eds.) Advances in Neural Information Processing Systems, vol.\u00a032. Curran Associates, Inc. (2019)"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-64171-8_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,10]],"date-time":"2024-07-10T11:16:06Z","timestamp":1720610166000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-64171-8_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031641701","9783031641718"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-64171-8_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"9 July 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lausanne","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Switzerland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva.org\/dimva2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}