{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T12:47:04Z","timestamp":1770814024434,"version":"3.50.1"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T00:00:00Z","timestamp":1767830400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T00:00:00Z","timestamp":1767830400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimedia Systems"],"published-print":{"date-parts":[[2026,2]]},"DOI":"10.1007\/s00530-025-02106-8","type":"journal-article","created":{"date-parts":[[2026,1,8]],"date-time":"2026-01-08T11:53:14Z","timestamp":1767873194000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Vulnerability Positioner (VulP): enhancing code vulnerability localization with CodeBERT"],"prefix":"10.1007","volume":"32","author":[{"given":"Xuejun","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhuo","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fenghe","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuqin","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaohong","family":"Jia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,1,8]]},"reference":[{"key":"2106_CR1","doi-asserted-by":"crossref","unstructured":"Li, Z., Zou, D.Q., Xu, S.H., Jin, H., Wang, S.J., Deng, Z.J., Zhong, Y.Y.: VulDeePecker: A deep learning-based system for vulnerability detection. In: Proceeding of the 25th Annual Network and Distributed System Security Symposium (NDSS) (2018)","DOI":"10.14722\/ndss.2018.23158"},{"issue":"4","key":"2106_CR2","doi-asserted-by":"publisher","first-page":"2244","DOI":"10.1109\/TDSC.2021.3051525","volume":"19","author":"Z Li","year":"2022","unstructured":"Li, Z., Zou, D.Q., Xu, S.H., Jin, H., Zhu, Y.W., Chen, Z.X.: SySeVR: A framework for using deep learning to detect software vulnerabilities. IEEE Trans. Dependable Secure Comput. 19(4), 2244\u20132258 (2022)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"5","key":"2106_CR3","first-page":"2224","volume":"18","author":"DQ Zou","year":"2019","unstructured":"Zou, D.Q., Wang, S.J., Xu, S.H., Li, Z., Jin, H.: \u00b5 VulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability Detection. IEEE Trans. Dependable Secure Comput. 18(5), 2224\u20132236 (2019)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"2106_CR4","doi-asserted-by":"crossref","unstructured":"Li, Y., Wang, S., Nguyen, T.N.: Vulnerability detection with fine-grained interpretations. In: Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 292-303. (2021)","DOI":"10.1145\/3468264.3468597"},{"key":"2106_CR5","doi-asserted-by":"crossref","unstructured":"Ding, Y., Suneja, S., Zheng, Y.H., Laredo, J., Morari, A., Kaiser, G.: VELVET: a noVel Ensemble Learning approach to automatically locate VulnErable sTatements. In: 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). 959\u2013970 (2022)","DOI":"10.1109\/SANER53432.2022.00114"},{"key":"2106_CR6","doi-asserted-by":"crossref","unstructured":"Fu, M., Tantithamthavorn, C.: Linevul: A transformer-based line-level vulnerability prediction. In: Proceedings of the 19th International Conference on Mining Software Repositories. 608\u2013620 (2022)","DOI":"10.1145\/3524842.3528452"},{"key":"2106_CR7","doi-asserted-by":"crossref","unstructured":"Hin, D., Kan, A., Chen, H.M., Babar, M.A.: LineVD: Statement-level vulnerability detection using graph neural networks. In: Proceedings of the 19th international conference on mining software repositories. 596\u2013607 (2022)","DOI":"10.1145\/3524842.3527949"},{"key":"2106_CR8","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2024.107458","volume":"171","author":"CY Liu","year":"2024","unstructured":"Liu, C.Y., Chen, X., Li, X.W., Xue, Y.X.: Making vulnerability prediction more practical: Prediction, categorization, and localization. Inf. Softw. Technol. 171, 107458 (2024)","journal-title":"Inf. Softw. Technol."},{"key":"2106_CR9","doi-asserted-by":"crossref","unstructured":"Feng, Z.Y., Guo, D.Y., Tang, D.Y., Duan, N., Feng, X.C., Gong, M., Shou, L.J., Qin, B., Liu, T., Jiang, D.X., Zhou, M.: CodeBERT: A Pre-Trained Model for Programming and Natural Languages. In: Findings of the Association for Computational Linguistics: EMNLP. 1536\u20131547 (2020)","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"2106_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104098","volume":"148","author":"C Liang","year":"2024","unstructured":"Liang, C., Wei, Q., Du, J., Wang, Y., Jiang, Z.: Survey of source code vulnerability analysis based on deep learning. Comput. Security. 148, 104098 (2024)","journal-title":"Comput. Security."},{"key":"2106_CR11","unstructured":"Flawfinder. (Accessed on 3 December 2025) https:\/\/dwheeler.com\/flawfinder\/."},{"key":"2106_CR12","unstructured":"Clang static analyzer. (Accessed on 3 December 2025) https:\/\/clang-analyzer.llvm.org\/scan-build.html."},{"key":"2106_CR13","unstructured":"RATS. (Accessed on 3 December 2025 ) https:\/\/code.google.com\/archive\/p\/rough-auditing-tool-for-security\/"},{"key":"2106_CR14","unstructured":"Checkmarx. (Accessed on 3 December 2025) https:\/\/www.checkmarx.com\/."},{"key":"2106_CR15","unstructured":"Oualid, Z., Hanan, EI.B.: Dynamic vulnerability detection approaches and tools: State of the Art. In: 2020 Fourth International Conference On Intelligent Computing in Data Sciences (ICDS), 1\u20136 (2020)"},{"issue":"3","key":"2106_CR16","doi-asserted-by":"publisher","first-page":"777","DOI":"10.1007\/s11277-015-3152-1","volume":"89","author":"S Kim","year":"2016","unstructured":"Kim, S., Kim, R., Park, Y.B.: Software Vulnerability Detection Methodology Combined with Static and Dynamic Analysis. Wireless Pers. Commun. 89(3), 777\u2013793 (2016)","journal-title":"Wireless Pers. Commun."},{"key":"2106_CR17","doi-asserted-by":"crossref","unstructured":"Zhang, J., Liu, S.Q., Wang, X., Li, T.L., Liu, Y.: Learning to locate and describe vulnerabilities. In: Proceedings of the 38th IEEE\/ACM International Conference on Automated Software Engineering, 332\u2013344 (2023)","DOI":"10.1109\/ASE56229.2023.00045"},{"key":"2106_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103469","volume":"134","author":"B Wu","year":"2023","unstructured":"Wu, B., Zou, F.T., Yi, P., Wu, Y., Zhang, L.: SlicedLocator: Code Vulnerability Locator Based on Sliced Dependence Graph. Comput. Security. 134, 103469 (2023)","journal-title":"Comput. Security."},{"key":"2106_CR19","doi-asserted-by":"publisher","first-page":"2821","DOI":"10.1109\/TDSC.2021.3076142","volume":"19","author":"Z Li","year":"2022","unstructured":"Li, Z., Zou, D.Q., Xu, S.H., Chen, Z.X., Zhu, Y.W., Jin, H.: VulDeeLocator: a deep learning-based fine-grained vulnerability detector. IEEE Transactions on Dependable and Secure Computing 19, 2821\u20132837 (2022)","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"2106_CR20","doi-asserted-by":"crossref","unstructured":"Cheng, X., Zhang, G., Wang, H.: Path-sensitive code embedding via contrastive learning for software vulnerability detection. In: Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, 519\u2013531 (2022)","DOI":"10.1145\/3533767.3534371"},{"key":"2106_CR21","doi-asserted-by":"crossref","unstructured":"Nguyen, V.A., Nguyen, D.Q., Nguyen, V., Le, T., Tran, Q.H., Phung, D.: ReGVD: Revisiting graph neural networks for vulnerability detection. In: Proceedings of the ACM\/IEEE 44th International Conference on Software Engineering: Companion Proceedings. 178-182 (2022)","DOI":"10.1145\/3510454.3516865"},{"key":"2106_CR22","doi-asserted-by":"crossref","unstructured":"Wang, W., Nguyen, T.N., Wang, S., Li, Y., Zhang, J., Yadavally, A.: DeepVD: Toward class-separation features for neural network vulnerability detection. In: 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 2249-2261 (2023)","DOI":"10.1109\/ICSE48619.2023.00189"},{"issue":"12","key":"2106_CR23","doi-asserted-by":"publisher","first-page":"3454","DOI":"10.1109\/TSE.2024.3493245","volume":"50","author":"Y Jiang","year":"2024","unstructured":"Jiang, Y., Zhang, Y.J., Su, X.H., Treude, C., Wang, T.T.: StagedVulBERT: Multigranular Vulnerability Detection With a Novel Pretrained Code Model. IEEE Trans. Software Eng. 50(12), 3454\u20133471 (2024)","journal-title":"IEEE Trans. Software Eng."},{"key":"2106_CR24","doi-asserted-by":"crossref","unstructured":"Hazim, H., Sergio, M.: VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection. In: 2022 International Joint Conference on Neural Networks (IJCNN), 1\u20138 (2022)","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"issue":"2","key":"2106_CR25","doi-asserted-by":"publisher","DOI":"10.1007\/s10515-024-00440-1","volume":"31","author":"CX Do","year":"2024","unstructured":"Do, C.X., Luu, N.T., Nguyen, P.T.L.: Optimizing software vulnerability detection using RoBERTa and machine learning. Automated Software Engineering 31(2), 40 (2024)","journal-title":"Automated Software Engineering"},{"key":"2106_CR26","doi-asserted-by":"crossref","unstructured":"Wang, Y., Wang, W., Joty, S., Hoi, S.C.: CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and Generation. In: Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, 8696\u20138708 (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.685"},{"key":"2106_CR27","first-page":"149","volume":"9","author":"XJ Zhang","year":"2023","unstructured":"Zhang, X.J., Zhang, F.H., Gai, J.Y., Du, X.G., Zhou, W.J., Cai, T.L., Zhao, B.: mVulSniffer: a multi-type source code vulnerability sniffer method. J. Commun. 9, 149\u2013160 (2023)","journal-title":"J. Commun."},{"key":"2106_CR28","unstructured":"Guo, D.Y., Ren, S., Lu, S., Feng, Z., Tang, D., Duan, N., Yin, J., Svyatkovskiy, A., Zhou, M.: GraphCodeBERT: Pre-training Code Representations with Data Flow. In: International Conference on Learning Representations (ICLR) (2021)"},{"key":"2106_CR29","doi-asserted-by":"crossref","unstructured":"Wang, Y., Le, H., Gotmare, A.D., Bui, N.D.Q., Li, J., Hoi, S.C.H.: CodeT5+: Open Code Large Language Models for Code Understanding and Generation. In: Proceedings Conference on Empirical Methods in Natural Language Processing (EMNLP), 1069-1088 (2023)","DOI":"10.18653\/v1\/2023.emnlp-main.68"},{"key":"2106_CR30","doi-asserted-by":"crossref","unstructured":"Zhang, X.J., Zhang, F.H., Zhao, B., Zhou, B., Xiao, B.Y.: VulD-Transformer: Source Code Vulnerability Detection via Transformer. In: Proceedings of the 14th Asia-Pacific Symposium on Internetware, 185\u2013193 (2023)","DOI":"10.1145\/3609437.3609451"},{"key":"2106_CR31","doi-asserted-by":"crossref","unstructured":"Chen, Y.Z., Ding, Z.J., Alowain, L., Chen, X.Y., Wagner, D.: Diversevul: A new vulnerable source code dataset for deep learning based vulnerability detection. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses. 654-668 (2023)","DOI":"10.1145\/3607199.3607242"}],"container-title":["Multimedia Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00530-025-02106-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00530-025-02106-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00530-025-02106-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T04:20:49Z","timestamp":1770783649000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00530-025-02106-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1,8]]},"references-count":31,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,2]]}},"alternative-id":["2106"],"URL":"https:\/\/doi.org\/10.1007\/s00530-025-02106-8","relation":{},"ISSN":["0942-4962","1432-1882"],"issn-type":[{"value":"0942-4962","type":"print"},{"value":"1432-1882","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1,8]]},"assertion":[{"value":"19 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 November 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 January 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"67"}}