{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T23:38:15Z","timestamp":1783553895628,"version":"3.55.0"},"publisher-location":"Cham","reference-count":56,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031708787","type":"print"},{"value":"9783031708794","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70879-4_14","type":"book-chapter","created":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T19:02:20Z","timestamp":1725476540000},"page":"271-289","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":41,"title":["Outside the\u00a0Comfort Zone: Analysing LLM Capabilities in\u00a0Software Vulnerability Detection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5535-2420","authenticated-orcid":false,"given":"Yuejun","family":"Guo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4460-9331","authenticated-orcid":false,"given":"Constantinos","family":"Patsakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8251-1669","authenticated-orcid":false,"given":"Qiang","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6153-4255","authenticated-orcid":false,"given":"Qiang","family":"Tang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4296-2876","authenticated-orcid":false,"given":"Fran","family":"Casino","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,9,5]]},"reference":[{"key":"14_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103135","volume":"190","author":"F Casino","year":"2021","unstructured":"Casino, F., Lykousas, N., Homoliak, I., Patsakis, C., Hernandez-Castro, J.: Intercepting hail hydra: real-time detection of algorithmically generated domains. J. Netw. Comput. Appl. 190, 103135 (2021)","journal-title":"J. Netw. Comput. Appl."},{"key":"14_CR2","unstructured":"CERN Computer Security Team: RATS: rough auditing tool for security (2024). https:\/\/security.web.cern.ch\/recommendations\/en\/codetools\/rats.shtml, Accessed 16 April 2024"},{"issue":"09","key":"14_CR3","doi-asserted-by":"publisher","first-page":"3280","DOI":"10.1109\/TSE.2021.3087402","volume":"48","author":"S Chakraborty","year":"2022","unstructured":"Chakraborty, S., Krishna, R., Ding, Y., Ray, B.: Deep learning based vulnerability detection: are we there yet? IEEE Trans. Software Eng. 48(09), 3280\u20133296 (2022). https:\/\/doi.org\/10.1109\/TSE.2021.3087402","journal-title":"IEEE Trans. Software Eng."},{"key":"14_CR4","unstructured":"Charalambous, Y., Tihanyi, N., Jain, R., Sun, Y., Ferrag, M.A., Cordeiro, L.C.: A new era in software security: towards self-healing software via large language models and formal verification. arXiv preprint arXiv:2305.14752 (2023)"},{"key":"14_CR5","doi-asserted-by":"publisher","unstructured":"Chen, Y., Ding, Z., Alowain, L., Chen, X., Wagner, D.: Diversevul: a new vulnerable source code dataset for deep learning based vulnerability detection. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2023, pp. 654-668. Association for Computing Machinery, New York (2023).https:\/\/doi.org\/10.1145\/3607199.3607242","DOI":"10.1145\/3607199.3607242"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"Choi, M.J., Jeong, S., Oh, H., Choo, J.: End-to-end prediction of buffer overruns from raw source code via neural memory networks. In: Proceedings of the 26th International Joint Conference on Artificial Intelligence, IJCAI 2017, pp. 1546-1553. AAAI Press (2017)","DOI":"10.24963\/ijcai.2017\/214"},{"key":"14_CR7","unstructured":"Cppcheck team: Cppcheck (2024). https:\/\/cppcheck.sourceforge.io\/, Accessed 16 April 2024"},{"key":"14_CR8","doi-asserted-by":"publisher","unstructured":"Croft, R., Newlands, D., Chen, Z., Babar, M.A.: An empirical study of rule-based and learning-based approaches for static application security testing. In: Proceedings of the 15th ACM \/ IEEE International Symposium on Empirical Software Engineering and Measurement ESEM 2021. Association for Computing Machinery, New York (2021). https:\/\/doi.org\/10.1145\/3475716.3475781","DOI":"10.1145\/3475716.3475781"},{"key":"14_CR9","unstructured":"Dettmers, T., Pagnoni, A., Holtzman, A., Zettlemoyer, L.: Qlora: efficient finetuning of quantized llms. Adv. Neural Inform. Process. Syst. 36 (2024)"},{"key":"14_CR10","unstructured":"Ding, Y., et al.: Vulnerability detection with code language models: how far are we? arXiv preprint arXiv:2403.18624 (2024)"},{"key":"14_CR11","doi-asserted-by":"publisher","unstructured":"Fan, J., Li, Y., Wang, S., Nguyen, T.N.: A c\/c++ code vulnerability dataset with code changes and cve summaries. In: Proceedings of the 17th International Conference on Mining Software Repositories, MSR 2020, pp. 508-512. Association for Computing Machinery, New York (2020). https:\/\/doi.org\/10.1145\/3379597.3387501","DOI":"10.1145\/3379597.3387501"},{"key":"14_CR12","doi-asserted-by":"publisher","unstructured":"Feng, Z., Guo, D., Tang, D., et\u00a0al.: Codebert: a pre-trained model for programming and natural languages. In: Findings of the Association for Computational Linguistics: EMNLP 2020, pp. 1536\u20131547. Association for Computational Linguistics (November 2020). https:\/\/doi.org\/10.18653\/v1\/2020.findings-emnlp.139","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"14_CR13","doi-asserted-by":"publisher","unstructured":"Fu, M., Tantithamthavorn, C.: Linevul: a transformer-based line-level vulnerability prediction. In: Proceedings of the 19th International Conference on Mining Software Repositories, pp. 608-620. MSR \u201922, Association for Computing Machinery, New York (2022). https:\/\/doi.org\/10.1145\/3524842.3528452","DOI":"10.1145\/3524842.3528452"},{"key":"14_CR14","unstructured":"Gui, Y.: Model card of starmage520\/Coderbert_finetuned_detect_vulnerability_on_MSR on hugging face (2023). https:\/\/huggingface.co\/starmage520\/Coderbert_finetuned_detect_vulnerability_on_MSR. Accessed 16 April 2024"},{"key":"14_CR15","doi-asserted-by":"publisher","unstructured":"Guo, Y., Hu, Q., Tang, Q., Traon, Y.L.: An empirical study of the imbalance issue in software vulnerability detection. In: Computer Security - ESORICS 2023: 28th European Symposium on Research in Computer Security, Proceedings, Part IV, pp. 371-390. Springer-Verlag, Berlin (2024). https:\/\/doi.org\/10.1007\/978-3-031-51482-1_19","DOI":"10.1007\/978-3-031-51482-1_19"},{"key":"14_CR16","doi-asserted-by":"publisher","unstructured":"Hanif, H., Maffeis, S.: Vulberta: simplified source code pre-training for vulnerability detection. In: International Joint Conference on Neural Networks (IJCNN), pp.\u00a01\u20138. IEEE (2022). https:\/\/doi.org\/10.1109\/IJCNN55064.2022.9892280","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"key":"14_CR17","unstructured":"Hu, E.J., et al.: LoRA: Low-rank adaptation of large language models. In: International Conference on Learning Representations (2022). https:\/\/openreview.net\/forum?id=nZeVKeeFYf9"},{"key":"14_CR18","unstructured":"Hugging Face: Hugging Face. https:\/\/huggingface.co\/, Accessed 16 April 2024"},{"key":"14_CR19","unstructured":"Husain, H., Wu, H.H., Gazit, T., Allamanis, M., Brockschmidt, M.: Codesearchnet challenge: evaluating the state of semantic code search. arXiv preprint arXiv: 1909.09436 (2020)"},{"key":"14_CR20","unstructured":"Jiang, A.Q., et al.: Mistral 7b. arXiv preprint arXiv:2310.06825 (2023)"},{"key":"14_CR21","unstructured":"Jiang, A.Q., Sablayrolles, A., Roux, A., et\u00a0al.: Mixtral of experts. arXiv preprint arXiv:2401.04088 (2024)"},{"key":"14_CR22","doi-asserted-by":"publisher","unstructured":"Lee, M., Cho, S., Jang, C., Park, H., Choi, E.: A rule-based security auditing tool for software vulnerability detection. In: International Conference on Hybrid Information Technology, vol.\u00a02, pp. 505\u2013512. IEEE (2006). https:\/\/doi.org\/10.1109\/ICHIT.2006.253653","DOI":"10.1109\/ICHIT.2006.253653"},{"key":"14_CR23","doi-asserted-by":"publisher","unstructured":"Li, H., Hao, Y., Zhai, Y., Qian, Z.: Assisting static analysis with large language models: A chatgpt experiment. In: Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/FSE 2023, pp. 2107\u20132111. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3611643.3613078","DOI":"10.1145\/3611643.3613078"},{"key":"14_CR24","doi-asserted-by":"publisher","unstructured":"Li, Z., et al.: Vuldeepecker: a deep learning-based system for vulnerability detection. In: 25th Annual Network and Distributed System Security Symposium (NDSS). The Internet Society (2018). https:\/\/doi.org\/10.14722\/ndss.2018.23158","DOI":"10.14722\/ndss.2018.23158"},{"key":"14_CR25","doi-asserted-by":"crossref","unstructured":"Li, Z., et al.: Vuldeepecker: a deep learning-based system for vulnerability detection. In: 25th Annual Network and Distributed System Security Symposium (NDSS). The Internet Society (2018). http:\/\/wp.internetsociety.org\/ndss\/wp-content\/uploads\/sites\/25\/2018\/02\/ndss2018_03A-2_Li_paper.pdf","DOI":"10.14722\/ndss.2018.23158"},{"issue":"10","key":"14_CR26","doi-asserted-by":"publisher","first-page":"1825","DOI":"10.1109\/JPROC.2020.2993293","volume":"108","author":"G Lin","year":"2020","unstructured":"Lin, G., Wen, S., Han, Q.L., Zhang, J., Xiang, Y.: Software vulnerability detection using deep neural networks: a survey. Proc. IEEE 108(10), 1825\u20131848 (2020). https:\/\/doi.org\/10.1109\/JPROC.2020.2993293","journal-title":"Proc. IEEE"},{"key":"14_CR27","doi-asserted-by":"publisher","unstructured":"Lin, G., Zhang, J., Luo, W., Pan, L., Xiang, Y.: Vulnerability discovery with function representation learning from unlabeled projects. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, pp. 2539-2541. Association for Computing Machinery, New York (2017). https:\/\/doi.org\/10.1145\/3133956.3138840","DOI":"10.1145\/3133956.3138840"},{"key":"14_CR28","unstructured":"Liu, Y., et al.: Roberta: A robustly optimized BERT pretraining approach. arXiv: 1907.11692 (2019), arXiv preprint"},{"key":"14_CR29","unstructured":"National Institute of Standards and Technology: Secure Software Development Framework (SSDF) Version 1.1: (2018)"},{"key":"14_CR30","unstructured":"Noever, D.: Can large language models find and fix vulnerable software? arXiv preprint arXiv:2308.10345 (2023)"},{"key":"14_CR31","unstructured":"OpenAI, Achiam, J., Adler, S., et\u00a0al.: Gpt-4 technical report. arXiv preprint arXiv:2303.08774 (2024)"},{"key":"14_CR32","unstructured":"OWASP: OWASP DevSecOps Guideline (2024). https:\/\/github.com\/OWASP\/DevSecOpsGuideline\/tree\/master, Accessed 16 April 2024"},{"key":"14_CR33","unstructured":"Poeplau, S., Francillon, A.: Symbolic execution with SymCC: don\u2019t interpret, compile! In: Proceedings of the 29th USENIX Conference on Security Symposium, SEC 2020, pp. 181\u2013198. USENIX Association, USA (August 2020). https:\/\/dl.acm.org\/doi\/10.5555\/3489212.3489223"},{"key":"14_CR34","doi-asserted-by":"publisher","unstructured":"Ribeiro, F., de\u00a0Macedo, J.N.C., Tsushima, K., Abreu, R., Saraiva, J.: Gpt-3-powered type error debugging: investigating the use of large language models for code repair. In: Proceedings of the 16th ACM SIGPLAN International Conference on Software Language Engineering, SLE 2023, pp. 111\u2013124. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3623476.3623522","DOI":"10.1145\/3623476.3623522"},{"key":"14_CR35","unstructured":"Rozi\u00e8re, B., et al.: Code llama: open foundation models for code. arXiv preprint arXiv:2308.12950 (2024)"},{"key":"14_CR36","doi-asserted-by":"crossref","unstructured":"Russell, R., et al.: Automated vulnerability detection in source code using deep representation learning. In: 2018 17th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 757\u2013762. IEEE (2018)","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"14_CR37","doi-asserted-by":"publisher","unstructured":"Sampaio, L., Garcia, A.: Exploring context-sensitive data flow analysis for early vulnerability detection. J. Syst. Softw. 113(C), 337-361 (2016). https:\/\/doi.org\/10.1016\/j.jss.2015.12.021","DOI":"10.1016\/j.jss.2015.12.021"},{"key":"14_CR38","unstructured":"Semgrep, Inc: Semgrep - find bugs and enforce code standards (2024). https:\/\/semgrep.dev\/, Accessed 16 April 2024"},{"key":"14_CR39","unstructured":"Semgrep Team: semgrep-rules (2024). https:\/\/github.com\/semgrep\/semgrep-rules, Accessed 21 June 2024"},{"key":"14_CR40","doi-asserted-by":"publisher","unstructured":"Senanayake, J., Kalutarage, H., Al-Kadri, M.O., Petrovski, A., Piras, L.: Android source code vulnerability detection: a systematic literature review. ACM Comput. Surv. 55(9) (2023). https:\/\/doi.org\/10.1145\/3556974","DOI":"10.1145\/3556974"},{"key":"14_CR41","unstructured":"Snyk team: Snyk code: developer focused, real-time sast (2024). https:\/\/snyk.io\/product\/snyk-code\/, Accessed 16 April 2024"},{"key":"14_CR42","unstructured":"SonarSource: Code quality, security & static analysis too with SonarQube (2024). https:\/\/www.sonarsource.com\/products\/sonarqube\/, Accessed 16 April 2024"},{"key":"14_CR43","unstructured":"Spiess, C.: Model card of claudios\/VulBERTa-MLP-D2A on Hugging Face (2024). https:\/\/huggingface.co\/claudios\/VulBERTa-MLP-D2A, Accessed 16 April 2024"},{"key":"14_CR44","unstructured":"Spiess, C.: Model card of claudios\/VulBERTa-MLP-Draper on Hugging Face (2024). https:\/\/huggingface.co\/claudios\/VulBERTa-MLP-Draper, Accessed 16 April 2024"},{"key":"14_CR45","unstructured":"Spiess, C.: Model card of claudios\/VulBERTa-MLP-MVD on hugging face (2024). https:\/\/huggingface.co\/claudios\/VulBERTa-MLP-MVD, Accessed 16 April 2024"},{"key":"14_CR46","unstructured":"Spiess, C.: Model card of claudios\/VulBERTa-MLP-ReVeal on Hugging Face (2024). https:\/\/huggingface.co\/claudios\/VulBERTa-MLP-ReVeal, Accessed 16 April 2024"},{"key":"14_CR47","unstructured":"Spiess, C.: Model card of claudios\/VulBERTa-MLP-VulDeePecker on hugging face (2024). https:\/\/huggingface.co\/claudios\/VulBERTa-MLP-VulDeePecker, Accessed 16 April 2024"},{"issue":"3","key":"14_CR48","doi-asserted-by":"publisher","first-page":"238","DOI":"10.1145\/545186.545188","volume":"5","author":"J Viega","year":"2002","unstructured":"Viega, J., Bloch, J.T., Kohno, T., McGraw, G.: Token-based scanning of source code for security problems. ACM Trans. Inform. Syst. Sec. 5(3), 238\u2013261 (2002). https:\/\/doi.org\/10.1145\/545186.545188","journal-title":"ACM Trans. Inform. Syst. Sec."},{"key":"14_CR49","unstructured":"Wheeler, D.A.: Flawfinder (2017). https:\/\/dwheeler.com\/flawfinder\/, Accessed 16 April 2024"},{"key":"14_CR50","doi-asserted-by":"publisher","unstructured":"Wolf, T., et al.: Transformers: state-of-the-art natural language processing. In: Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing: System Demonstrations, pp. 38\u201345. Association for Computational Linguistics, Online (October 2020). https:\/\/doi.org\/10.18653\/v1\/2020.emnlp-demos.6","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"14_CR51","unstructured":"Yuejun, G.: A collection of datasets for software vulnerability detection (version 1.0) (April 2024). https:\/\/zenodo.org\/records\/10975439 on Zenodo, Accessed 16 April 2024"},{"key":"14_CR52","doi-asserted-by":"publisher","unstructured":"Zheng, Y., et al.: D2a: a dataset built for ai-based vulnerability detection methods using differential analysis. In: Proceedings of the 43rd International Conference on Software Engineering: Software Engineering in Practice, ICSE-SEIP 2021, pp. 111-120. IEEE Press (2021). https:\/\/doi.org\/10.1109\/ICSE-SEIP52600.2021.00020","DOI":"10.1109\/ICSE-SEIP52600.2021.00020"},{"key":"14_CR53","unstructured":"Zheng, Z., et al.: Towards an understanding of large language models in software engineering tasks. arXiv preprint arXiv:2308.11396 (2023)"},{"key":"14_CR54","doi-asserted-by":"crossref","unstructured":"Zhou, X., Zhang, T., Lo, D.: Large language model for vulnerability detection: emerging results and future directions. arXiv preprint arXiv:2401.15468 (2024)","DOI":"10.1145\/3639476.3639762"},{"key":"14_CR55","unstructured":"Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y.: Devign: effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In: Proceedings of the 33rd International Conference on Neural Information Processing Systems, pp. 10197\u201310207. Curran Associates Inc., Red Hook, NY, USA (December 2019), https:\/\/dl.acm.org\/doi\/pdf\/10.5555\/3454287.3455202"},{"key":"14_CR56","doi-asserted-by":"publisher","unstructured":"Zou, D., Wang, S., Xu, S., Li, Z., Jin, H.: $$\\mu $$vuldeepecker: a deep learning-based system for multiclass vulnerability detection. IEEE Trans. Dependable Sec. Computi. (2019). https:\/\/doi.org\/10.1109\/TDSC.2019.2942930","DOI":"10.1109\/TDSC.2019.2942930"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70879-4_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T19:05:22Z","timestamp":1725476722000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70879-4_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031708787","9783031708794"],"references-count":56,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70879-4_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"5 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}