{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T16:33:37Z","timestamp":1775579617434,"version":"3.50.1"},"publisher-location":"Cham","reference-count":40,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032006462","type":"print"},{"value":"9783032006448","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-00644-8_8","type":"book-chapter","created":{"date-parts":[[2025,8,8]],"date-time":"2025-08-08T04:06:17Z","timestamp":1754625977000},"page":"135-152","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Evaluating Large Language Models for\u00a0Vulnerability Detection Under Realistic Conditions"],"prefix":"10.1007","author":[{"given":"Vincenzo","family":"Carletti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pasquale","family":"Foggia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Carlo","family":"Mazzocca","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giuseppe","family":"Parrella","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mario","family":"Vento","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,9]]},"reference":[{"key":"8_CR1","unstructured":"Achiam, J., et\u00a0al.: GPT-4 technical report. arXiv preprint arXiv:2303.08774 (2023)"},{"key":"8_CR2","doi-asserted-by":"crossref","unstructured":"Akhoundali, J., Nouri, S.R., Rietveld, K., Gadyatskaya, O.: Morefixes: A large-scale dataset of CVE fix commits mined through enhanced repository discovery. In: Proceedings of the 20th International Conference on Predictive Models and Data Analytics in Software Engineering, pp. 42\u201351 (2024)","DOI":"10.1145\/3663533.3664036"},{"key":"8_CR3","unstructured":"Arteau, P.: Spotbugs. SpotBugs (2025). https:\/\/spotbugs.github.io. Accessed 22 April 2025"},{"key":"8_CR4","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1007\/978-3-031-87775-9_2","volume-title":"Advanced Information Networking and Applications","author":"N Capuano","year":"2025","unstructured":"Capuano, N., Carletti, V., Foggia, P., Parrella, G., Vento, M.: Leveraging open-source LLMs for zero-shot vulnerability detection: a comparative analysis. In: Barolli, L. (ed.) Advanced Information Networking and Applications, pp. 13\u201325. Springer Nature Switzerland, Cham (2025)"},{"key":"8_CR5","doi-asserted-by":"publisher","first-page":"103639","DOI":"10.1016\/j.cose.2023.103639","volume":"137","author":"V Casola","year":"2024","unstructured":"Casola, V., De Benedictis, A., Mazzocca, C., Orbinato, V.: Secure software development and testing: a model-based methodology. Comput. Secur. 137, 103639 (2024)","journal-title":"Comput. Secur."},{"issue":"9","key":"8_CR6","doi-asserted-by":"publisher","first-page":"3280","DOI":"10.1109\/TSE.2021.3087402","volume":"48","author":"S Chakraborty","year":"2021","unstructured":"Chakraborty, S., Krishna, R., Ding, Y., Ray, B.: Deep learning based vulnerability detection: are we there yet? IEEE Trans. Software Eng. 48(9), 3280\u20133296 (2021)","journal-title":"IEEE Trans. Software Eng."},{"key":"8_CR7","doi-asserted-by":"crossref","unstructured":"Chen, Y., Ding, Z., Alowain, L., Chen, X., Wagner, D.: DiverseVul: a new vulnerable source code dataset for deep learning based vulnerability detection. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, p. 654 668. RAID \u201923, Association for Computing Machinery, New York, NY, USA (2023)","DOI":"10.1145\/3607199.3607242"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"Croft, R., Newlands, D., Chen, Z.: An empirical study of rule-based and learning-based approaches for static application security testing. In: Association for Computing Machinery, pp. 1\u201312. New York, NY, USA (2021)","DOI":"10.1145\/3475716.3475781"},{"key":"8_CR9","doi-asserted-by":"crossref","unstructured":"Croft, R., Babar, M.A., Kholoosi, M.M.: Data quality for software vulnerability datasets. In: 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE), pp. 121\u2013133. IEEE (2023)","DOI":"10.1109\/ICSE48619.2023.00022"},{"key":"8_CR10","unstructured":"Devlin, J., Chang, M., Lee, K., Toutanova, K.: BERT: pre-training of deep bidirectional transformers for language understanding (2018). https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"8_CR11","doi-asserted-by":"crossref","unstructured":"Ding, Y., et al.: VELVET: a noVel Ensemble learning approach to automatically locate VulnErable sTatements. In: 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER), pp. 959\u2013970 (2022)","DOI":"10.1109\/SANER53432.2022.00114"},{"key":"8_CR12","doi-asserted-by":"publisher","unstructured":"Ding, Y., et al.: Vulnerability detection with code language models: how far are we? . In: 2025 IEEE\/ACM 47th International Conference on Software Engineering (ICSE), pp. 469\u2013481. IEEE Computer Society, Los Alamitos, CA, USA (2025). https:\/\/doi.org\/10.1109\/ICSE55347.2025.00038 , https:\/\/doi.org\/10.1109\/ICSE55347.2025.00038","DOI":"10.1109\/ICSE55347.2025.00038"},{"key":"8_CR13","doi-asserted-by":"publisher","unstructured":"Fan, J., Li, Y., Wang, S., Nguyen, T.N.: A c\/c++ code vulnerability dataset with code changes and cve summaries. In: 2020 IEEE\/ACM 17th International Conference on Mining Software Repositories (MSR), pp. 508\u2013512 (2020). https:\/\/doi.org\/10.1145\/3379597.3387501","DOI":"10.1145\/3379597.3387501"},{"key":"8_CR14","unstructured":"GitHub: GitHub copilot (2025). https:\/\/github.com\/copilot. Accessed 16 April 2025"},{"key":"8_CR15","doi-asserted-by":"publisher","unstructured":"Guo, Y., Bettaieb, S.: An investigation of quality issues in vulnerability detection datasets. In: 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW), pp. 29\u201333 (2023). https:\/\/doi.org\/10.1109\/EuroSPW59978.2023.00008","DOI":"10.1109\/EuroSPW59978.2023.00008"},{"key":"8_CR16","doi-asserted-by":"crossref","unstructured":"Hanif, H., Maffeis, S.: VulBERTa: simplified source code pre-training for vulnerability detection. In: Proceedings of the International Joint Conference on Neural Networks (2022)","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"issue":"2","key":"8_CR17","first-page":"3","volume":"1","author":"E.J Hu","year":"2022","unstructured":"Hu, E..J., et al.: LoRa: low-rank adaptation of large language models. ICLR 1(2), 3 (2022)","journal-title":"ICLR"},{"key":"8_CR18","unstructured":"Jiang, J., Wang, F., Shen, J., Kim, S., Kim, S.: A survey on large language models for code generation. arXiv preprint arXiv:2406.00515 (2024)"},{"issue":"7","key":"8_CR19","doi-asserted-by":"publisher","first-page":"654","DOI":"10.1109\/TSE.2002.1019480","volume":"28","author":"T Kamiya","year":"2002","unstructured":"Kamiya, T., Kusumoto, S., Inoue, K.: CCFinder: a multilinguistic token-based code clone detection system for large scale source code. IEEE Trans. Software Eng. 28(7), 654\u2013670 (2002)","journal-title":"IEEE Trans. Software Eng."},{"key":"8_CR20","unstructured":"Khare, A., Dutta, S., Li, Z., Solko-Breslin, A., Alur, R., Naik, M.: Understanding the effectiveness of large language models in detecting security vulnerabilities. arXiv preprint arXiv:2311.16169 (2023)"},{"key":"8_CR21","unstructured":"LDRA: LDRA software quality, software testing, software standards (2025). https:\/\/ldra.com\/. Accessed 22 April 2025"},{"key":"8_CR22","unstructured":"Li, R., et\u00a0al.: StarCoder: may the source be with you!. arXiv preprint arXiv:2305.06161 (2023)"},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"Li, Z., et al.: On the effectiveness of function-level vulnerability detectors for inter-procedural vulnerabilities. In: Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering, pp. 1\u201312 (2024)","DOI":"10.1145\/3597503.3639218"},{"key":"8_CR24","unstructured":"MITRE Corporation: CWE 2024 Top 25 Most Dangerous Software Weaknesses (2025). https:\/\/cwe.mitre.org\/top25\/archive\/2024\/2024_kev_list.html. Accessed April 16 2025"},{"key":"8_CR25","unstructured":"National Institute of Standards and Technology (NIST): Common Vulnerabilities and Exposures (CVE). https:\/\/nvd.nist.gov\/. Accessed April 16 2025"},{"key":"8_CR26","doi-asserted-by":"publisher","unstructured":"Nethercote, N., Seward, J.: Valgrind: a framework for heavyweight dynamic binary instrumentation. SIGPLAN Not. 42(6), 89 100 (2007). https:\/\/doi.org\/10.1145\/1273442.1250746, https:\/\/doi.org\/10.1145\/1273442.1250746","DOI":"10.1145\/1273442.1250746"},{"issue":"140","key":"8_CR27","first-page":"1","volume":"21","author":"C Raffel","year":"2020","unstructured":"Raffel, C., et al.: Exploring the limits of transfer learning with a unified text-to-text transformer. J. Mach. Learn. Res. 21(140), 1\u201367 (2020)","journal-title":"J. Mach. Learn. Res."},{"key":"8_CR28","unstructured":"Roziere, B., et\u00a0al.: Code Llama: open foundation models for code. arXiv preprint arXiv:2308.12950 (2023)"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Shestov, A., et al.: Finetuning large language models for vulnerability detection. IEEE Access 13, 38889\u201338900 (2025)","DOI":"10.1109\/ACCESS.2025.3546700"},{"key":"8_CR30","doi-asserted-by":"crossref","unstructured":"Steenhoek, B., Rahman, M.M., Jiles, R., Le, W.: An empirical study of deep learning models for vulnerability detection. In: 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE), pp. 2237\u20132248. IEEE (2023)","DOI":"10.1109\/ICSE48619.2023.00188"},{"key":"8_CR31","unstructured":"Sun, Y., et al.: LLM4Vuln: a unified evaluation framework for decoupling and enhancing LLMs\u2019 vulnerability reasoning. arXiv preprint arXiv:2401.16185 (2024)"},{"key":"8_CR32","unstructured":"Ullah, S., Han, M., Pujar, S., Pearce, H., Coskun, A., Stringhini, G.: Can large language models identify and reason about security vulnerabilities? Not yet. arXiv preprint arXiv:2312.12575 (2023)"},{"key":"8_CR33","unstructured":"Wheeler, D.A.: Flawfinder. DWheeler (2009). https:\/\/www.dwheeler.com\/flawfinder\/. Accessed 22 April 2025"},{"key":"8_CR34","unstructured":"Woo, S., Kim, S., Lee, H., Oh, H.: VUDDY: a scalable approach for vulnerable code clone discovery. In: IEEE Symposium on Security and Privacy (SP), pp. 595\u2013614. IEEE, San Jose, CA, USA (2017)"},{"key":"8_CR35","doi-asserted-by":"crossref","unstructured":"Yin, X., Ni, C., Wang, S.: Multitask-based evaluation of open-source LLM on software vulnerability. IEEE Trans. Softw. Eng. 50 (2024)","DOI":"10.1109\/TSE.2024.3470333"},{"key":"8_CR36","doi-asserted-by":"publisher","first-page":"560","DOI":"10.1007\/978-981-99-9331-4_37","volume-title":"Frontiers in Cyber Security","author":"C Zeng","year":"2024","unstructured":"Zeng, C., Zhou, B., Dong, H., Wu, H., Xie, P., Guan, Z.: A general source code vulnerability detection method via ensemble of graph neural networks. In: Yang, H., Lu, R. (eds.) Frontiers in Cyber Security, pp. 560\u2013574. Springer Nature Singapore, Singapore (2024)"},{"key":"8_CR37","unstructured":"Zhang, Z., et al.: Unifying the perspectives of NLP and software engineering: a survey on language models for code. Trans. Mach. Learn. Res. (2024). https:\/\/openreview.net\/forum?id=hkNnGqZnpa"},{"key":"8_CR38","doi-asserted-by":"crossref","unstructured":"Zhou, X., Cao, S., Sun, X., Lo, D.: Large language model for vulnerability detection and repair: literature review and the road ahead. ACM Trans. Softw. Eng. Methodol. (2024)","DOI":"10.1145\/3708522"},{"key":"8_CR39","unstructured":"Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y.: Devign: effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In: Advances in Neural Information Processing Systems, pp. 10197\u201310207 (2019)"},{"issue":"5","key":"8_CR40","first-page":"2224","volume":"18","author":"D Zou","year":"2021","unstructured":"Zou, D., Wang, S., Xu, S., Li, Z., Jin, H.: VulDeePecker: a deep learning-based system for multiclass vulnerability detection. IEEE Trans. Dependable Secure Comput. 18(5), 2224\u20132236 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."}],"container-title":["Lecture Notes in Computer Science","Availability, Reliability and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00644-8_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T18:17:57Z","timestamp":1757355477000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00644-8_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032006462","9783032006448"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00644-8_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"9 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ARES","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Availability, Reliability and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ghent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ares-12025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.ares-conference.eu","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}