{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T21:15:00Z","timestamp":1783372500175,"version":"3.54.6"},"reference-count":73,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2024,7,23]],"date-time":"2024-07-23T00:00:00Z","timestamp":1721692800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,7,23]],"date-time":"2024-07-23T00:00:00Z","timestamp":1721692800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100007512","name":"Universitat Rovira i Virgili","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100007512","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2024,10]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>As society\u2019s dependence on information and communication systems (ICTs) grows, so does the necessity of guaranteeing the proper functioning and use of such systems. In this context, it is critical to enhance the security and robustness of the DevSecOps pipeline through timely vulnerability detection. Usually, AI-based models enable desirable features such as automation, performance, and efficacy. However, the quality of such models highly depends on the datasets used during the training stage. The latter encompasses a series of challenges yet to be solved, such as access to extensive labelled datasets with specific properties, such as well-represented and balanced samples. This article explores the current state of practice of software vulnerability datasets and provides a classification of the main challenges and issues. After an extensive analysis, it describes a set of guidelines and desirable features that datasets should guarantee. The latter is applied to create a new dataset, which fulfils these properties, along with a descriptive comparison with the state of the art. Finally, a discussion on how to foster good practices among researchers and practitioners sets the ground for further research and continued improvement within this critical domain.<\/jats:p>","DOI":"10.1007\/s10207-024-00888-y","type":"journal-article","created":{"date-parts":[[2024,7,23]],"date-time":"2024-07-23T18:05:05Z","timestamp":1721757905000},"page":"3311-3327","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["A comprehensive analysis on software vulnerability detection datasets: trends, challenges, and road ahead"],"prefix":"10.1007","volume":"23","author":[{"given":"Yuejun","family":"Guo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Seifeddine","family":"Bettaieb","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fran","family":"Casino","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,7,23]]},"reference":[{"issue":"6","key":"888_CR1","doi-asserted-by":"publisher","first-page":"1333","DOI":"10.3390\/electronics12061333","volume":"12","author":"\u00d6 Aslan","year":"2023","unstructured":"Aslan, \u00d6., Aktu\u011f, S.S., Ozkan-Okay, M., Yilmaz, A.A., Akin, E.: A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions. Electronics 12(6), 1333 (2023). https:\/\/doi.org\/10.3390\/electronics12061333","journal-title":"Electronics"},{"key":"888_CR2","doi-asserted-by":"publisher","first-page":"25464","DOI":"10.1109\/ACCESS.2022.3154059","volume":"10","author":"F Casino","year":"2022","unstructured":"Casino, F., Dasaklis, T.K., Spathoulas, G.P., Anagnostopoulos, M., Ghosal, A., Borocz, I., Solanas, A., Conti, M., Patsakis, C.: Research trends, challenges, and emerging topics in digital forensics: A review of reviews. IEEE Access 10, 25464\u201325493 (2022)","journal-title":"IEEE Access"},{"key":"888_CR3","unstructured":"SecurityScorecard. CVE vulnerabilities by year. https:\/\/www.cvedetails.com\/browse-by-date.php . Accessed on January 30th, 2024 (2024)"},{"key":"888_CR4","doi-asserted-by":"publisher","unstructured":"Lee, M., Cho, S., Jang, C., Park, H., Choi, E.: In International Conference on Hybrid Information Technology, vol.\u00a02, pp. 505\u2013512. (2006) https:\/\/doi.org\/10.1109\/ICHIT.2006.253653","DOI":"10.1109\/ICHIT.2006.253653"},{"issue":"9","key":"888_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3556974","volume":"55","author":"J Senanayake","year":"2023","unstructured":"Senanayake, J., Kalutarage, H., Al-Kadri, M.O., Petrovski, A., Piras, L.: Android source code vulnerability detection: a systematic literature review. ACM Comput. Surv. 55(9), 1\u201337 (2023). https:\/\/doi.org\/10.1145\/3556974","journal-title":"ACM Comput. Surv."},{"key":"888_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111934","volume":"209","author":"T Sharma","year":"2024","unstructured":"Sharma, T., Kechagia, M., Georgiou, S., Tiwari, R., Vats, I., Moazen, H., Sarro, F.: A survey on machine learning techniques applied to source code. J. Syst. Softw. 209, 111934 (2024)","journal-title":"J. Syst. Softw."},{"key":"888_CR7","doi-asserted-by":"publisher","unstructured":"Croft, R., Newlands, D., Chen, Z., Babar, M.A.: In Proceedings of the 15th ACM \/ IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) (Association for Computing Machinery, New York, NY, USA, ), ESEM \u201921. (2021) https:\/\/doi.org\/10.1145\/3475716.3475781","DOI":"10.1145\/3475716.3475781"},{"key":"888_CR8","unstructured":"Zhou, Y., Liu, S., Siow, J., Du, X., Liu, Y.: in Proceedings of the 33rd International Conference on Neural Information Processing Systems (Curran Associates Inc., Red Hook, NY, USA, ), p. 10197\u201310207 (2019)"},{"key":"888_CR9","unstructured":"Lu, S., Guo, D., Ren, S., Huang, J., Svyatkovskiy, A., Blanco, A., Clement, C.B., Drain, D., Jiang, D., Tang, D., Li, G., Zhou, L., Shou, L., Zhou, L., Tufano, M., Gong, M., Zhou, M., Duan, N., Sundaresan, N., Deng, S.K., Fu, S., Liu, S.: CodeXGLUE: A machine learning benchmark dataset for code understanding and generation, CoRR arXiv:2102.04664 (2021)"},{"key":"888_CR10","volume":"68","author":"V Vouvoutsis","year":"2022","unstructured":"Vouvoutsis, V., Casino, F., Patsakis, C.: On the effectiveness of binary emulation in malware classification. J. Inf. Secur. Appl. 68, 103258 (2022)","journal-title":"J. Inf. Secur. Appl."},{"key":"888_CR11","unstructured":"Khare, A., Dutta, S., Li, Z., Solko-Breslin, A., Alur, R., Naik , M.: Understanding the effectiveness of large language models in detecting security vulnerabilities. https:\/\/arxiv.org\/pdf\/2311.16169.pdf (2023). Accessed on January 30th, (2024)"},{"key":"888_CR12","doi-asserted-by":"crossref","unstructured":"Fu, M., Tantithamthavorn, C., Nguyen, V., x\u00a0Le, V.: Chatgpt for vulnerability detection, classification, and repair: how far are we? https:\/\/arxiv.org\/pdf\/2310.09810.pdf (2023). Accessed on January 30th, 2024","DOI":"10.1109\/APSEC60848.2023.00085"},{"key":"888_CR13","doi-asserted-by":"publisher","unstructured":"Purba, M.D., Ghosh, A., Radford, B.J., Chu, B.: In IEEE 34th International Symposium on Software Reliability Engineering Workshops (ISSREW) IEEE Computer Society, Los Alamitos, CA, USA, (2023), pp. 112\u2013119. https:\/\/doi.org\/10.1109\/ISSREW60843.2023.00058","DOI":"10.1109\/ISSREW60843.2023.00058"},{"key":"888_CR14","unstructured":"Gao, Z., Wang, H., Zhou, Y., Zhu, W., Zhang, C.: How far have we gone in vulnerability detection using large language models. https:\/\/arxiv.org\/pdf\/2311.12420.pdf (2023)"},{"key":"888_CR15","unstructured":"Patsakis, C., Casino, F., Lykousas, N.: arXiv preprint arXiv:2404.19715 (2024)"},{"key":"888_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103009","volume":"179","author":"H Hanif","year":"2021","unstructured":"Hanif, H., Nasir, M.H.N.M., Ab Razak, M.F., Firdaus, A., Anuar, N.B.: The rise of software vulnerability: Taxonomy of software vulnerabilities detection and machine learning approaches. J. Netw. Comput. Appl. 179, 103009 (2021)","journal-title":"J. Netw. Comput. Appl."},{"key":"888_CR17","unstructured":"Guo, Y., et\u00a0al.: In European Symposium on Research in Computer Security Springer, (2024). To appear"},{"key":"888_CR18","doi-asserted-by":"publisher","unstructured":"Lin, G., Zhang, J., Luo, W., Pan, L., Xiang, Y.: In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security Association for Computing Machinery, New York, NY, USA, (2017), CCS \u201917, p. 2539\u20132541. https:\/\/doi.org\/10.1145\/3133956.3138840","DOI":"10.1145\/3133956.3138840"},{"issue":"05","key":"888_CR19","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1109\/MSEC.2022.3176058","volume":"20","author":"T Marjanov","year":"2022","unstructured":"Marjanov, T., Pashchenko, I., Massacci, F.: Machine learning for source code vulnerability detection: What works and what isn\u2019t there yet. IEEE Secur. Priv. 20(05), 60 (2022). https:\/\/doi.org\/10.1109\/MSEC.2022.3176058","journal-title":"IEEE Secur. Priv."},{"key":"888_CR20","unstructured":"AI community. Hugging face. https:\/\/huggingface.co\/ (2024). Accessed on January 30th, (2024)"},{"issue":"10","key":"888_CR21","doi-asserted-by":"publisher","first-page":"993","DOI":"10.1109\/TSE.2014.2340398","volume":"40","author":"R Scandariato","year":"2014","unstructured":"Scandariato, R., Walden, J., Hovsepyan, A., Joosen, W.: Predicting vulnerable software components via text mining. IEEE Trans. Softw. Eng. 40(10), 993 (2014). https:\/\/doi.org\/10.1109\/TSE.2014.2340398","journal-title":"IEEE Trans. Softw. Eng."},{"key":"888_CR22","doi-asserted-by":"crossref","unstructured":"Choi, M.J., Jeong, S., Oh, H., Choo, J.: In Proceedings of the 26th International Joint Conference on Artificial Intelligence AAAI Press, (2017), IJCAI\u201917, p. 1546\u20131553","DOI":"10.24963\/ijcai.2017\/214"},{"issue":"7","key":"888_CR23","doi-asserted-by":"publisher","first-page":"3289","DOI":"10.1109\/TII.2018.2821768","volume":"14","author":"G Lin","year":"2018","unstructured":"Lin, G., Zhang, J., Luo, W., Pan, L., Xiang, Y., De Vel, O., Montague, P.: Cross-project transfer representation learning for vulnerable function discovery. IEEE Trans. Ind. Inf. 14(7), 3289 (2018). https:\/\/doi.org\/10.1109\/TII.2018.2821768","journal-title":"IEEE Trans. Ind. Inf."},{"key":"888_CR24","doi-asserted-by":"publisher","unstructured":"Li, Z., Zou, D., Xu, S., Ou, X., Jin, H., Wang, S., Deng, Z., Zhong, Y.: In 25th Annual Network and Distributed System Security Symposium (NDSS) (The Internet Society, 2018). https:\/\/doi.org\/10.14722\/ndss.2018.23158. http:\/\/wp.internetsociety.org\/ndss\/wp-content\/uploads\/sites\/25\/2018\/02\/ndss2018_03A-2_Li_paper.pdf","DOI":"10.14722\/ndss.2018.23158"},{"key":"888_CR25","unstructured":"Le, T., Nguyen, T., Le, T., Phung, D., Montague, P., Vel, O.D., Qu, L.: In International Conference on Learning Representations (2019). https:\/\/openreview.net\/forum?id=ByloIiCqYQ"},{"key":"888_CR26","doi-asserted-by":"publisher","unstructured":"Zou, D., Wang, S., Xu, S., Li, Z., Jin, H.: IEEE Transactions on Dependable and Secure Computing PP, 1 (2019). https:\/\/doi.org\/10.1109\/TDSC.2019.2942930","DOI":"10.1109\/TDSC.2019.2942930"},{"key":"888_CR27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2930578","volume":"7","author":"Z Li","year":"2019","unstructured":"Li, Z., Zou, D., Tang, J., Zhang, Z., Sun, M., Jin, H.: Multi-Modal Medical Image Fusion WithAdaptive WeightedCombinationofNSSTBandsUsing Chaotic Grey Wolf Optimization. IEEE Access 7, 103184 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2930578","journal-title":"IEEE Access"},{"key":"888_CR28","doi-asserted-by":"publisher","unstructured":"Fan, J., Li, Y., Wang, S., Nguyen, T.N.: In Proceedings of the 17th International Conference on Mining Software Repositories Association for Computing Machinery, New York, NY, USA, (2020), MSR \u201920, p. 508\u2013512. https:\/\/doi.org\/10.1145\/3379597.3387501","DOI":"10.1145\/3379597.3387501"},{"key":"888_CR29","doi-asserted-by":"crossref","unstructured":"Lin, G., Xiao, W., Zhang, J.: Deep learning-based vulnerable function detection: A benchmark. Y. Xiang. In: Zhou, J., Luo, X., Shen, Q., Xu, Z. (eds.) Information and Communications Security, pp. 219\u2013232. Springer International Publishing, Cham (2020)","DOI":"10.1007\/978-3-030-41579-2_13"},{"key":"888_CR30","doi-asserted-by":"publisher","unstructured":"Liu, B., Meng, G., Zou, W., Gong, Q., Li, F., Lin, M., Sun, D., Huo, W., Zhang, C.: In Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering Association for Computing Machinery, New York, NY, USA, (2020), ICSE \u201920, p. 1547\u20131559. https:\/\/doi.org\/10.1145\/3377811.3380923","DOI":"10.1145\/3377811.3380923"},{"issue":"5","key":"888_CR31","doi-asserted-by":"publisher","first-page":"1692","DOI":"10.3390\/app10051692","volume":"10","author":"X Li","year":"2020","unstructured":"Li, X., Wang, L., Xin, Y., Yang, Y., Chen, Y.: Automated vulnerability detection in source code using minimum intermediate representation learning. Appl. Sci. 10(5), 1692 (2020)","journal-title":"Appl. Sci."},{"issue":"04","key":"888_CR32","doi-asserted-by":"publisher","first-page":"2244","DOI":"10.1109\/TDSC.2021.3051525","volume":"19","author":"Z Li","year":"2022","unstructured":"Li, Z., Zou, D., Xu, S., Jin, H., Zhu, Y., Chen, Z.: Can large language models better predict software vulnerability? IEEE Trans. Depend. Secure Comput. 19(04), 2244 (2022). https:\/\/doi.org\/10.1109\/TDSC.2021.3051525","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"888_CR33","doi-asserted-by":"publisher","unstructured":"Zheng, Y., Pujar, S., Lewis, B., Buratti, L., Epstein, E., Yang, B.,\u00a0Laredo, J., Morari, A., Su, Z.: In Proceedings of the 43rd International Conference on Software Engineering: Software Engineering in Practice IEEE Press, (2021), ICSE-SEIP \u201921, p. 111\u2013120. https:\/\/doi.org\/10.1109\/ICSE-SEIP52600.2021.00020","DOI":"10.1109\/ICSE-SEIP52600.2021.00020"},{"issue":"5","key":"888_CR34","doi-asserted-by":"publisher","first-page":"2469","DOI":"10.1109\/TDSC.2019.2954088","volume":"18","author":"G Lin","year":"2021","unstructured":"Lin, G., Zhang, J., Luo, W., Pan, L., De Vel, O., Montague, P., Xiang, Y.: Software vulnerability discovery via learning multi-domain knowledge bases. IEEE Trans. Depend. Secure Comput. 18(5), 2469 (2021). https:\/\/doi.org\/10.1109\/TDSC.2019.2954088","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"888_CR35","doi-asserted-by":"publisher","unstructured":"Ziems, N., Wu, S.: In IEEE INFOCOM WKSHPS: The Ninth International Workshop on Security and Privacy in Big Data (BigSecurity 2021) IEEE, (2021), pp. 1\u20136. https:\/\/doi.org\/10.1109\/INFOCOMWKSHPS51825.2021.9484500","DOI":"10.1109\/INFOCOMWKSHPS51825.2021.9484500"},{"issue":"09","key":"888_CR36","doi-asserted-by":"publisher","first-page":"3280","DOI":"10.1109\/TSE.2021.3087402","volume":"48","author":"S Chakraborty","year":"2022","unstructured":"Chakraborty, S., Krishna, R., Ding, Y., Ray, B.: Deep learning based vulnerability detection: Are we there yet? IEEE Trans. Softw. Eng. 48(09), 3280 (2022). https:\/\/doi.org\/10.1109\/TSE.2021.3087402","journal-title":"IEEE Trans. Softw. Eng."},{"issue":"1","key":"888_CR37","first-page":"5203217","volume":"2022","author":"X Yuan","year":"2022","unstructured":"Yuan, X., Lin, G., Tai, Y., Zhang, J.: Deep neural embedding for software vulnerability discovery: Comparison and optimization. Secur. Commun. Netw. 2022(1), 5203217 (2022)","journal-title":"Secur. Commun. Netw."},{"key":"888_CR38","doi-asserted-by":"publisher","unstructured":"Zhou, X., Verma, R.M.: In Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security Association for Computing Machinery, New York, NY, USA, (2022), ASIA CCS \u201922, p. 1225\u20131227. https:\/\/doi.org\/10.1145\/3488932.3527288","DOI":"10.1145\/3488932.3527288"},{"key":"888_CR39","doi-asserted-by":"publisher","unstructured":"Cao, S., Sun, X., Bo, L., Wu, R., Li, B., Tao, C.: In Proceedings of the 44th International Conference on Software Engineering Association for Computing Machinery, New York, NY, USA, (2022), ICSE \u201922, p. 1456\u20131468. https:\/\/doi.org\/10.1145\/3510003.3510219","DOI":"10.1145\/3510003.3510219"},{"key":"888_CR40","doi-asserted-by":"publisher","unstructured":"Chen, Y., Ding, Z., Alowain, L., Chen, X., Wagner, D.: In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses Association for Computing Machinery, New York, NY, USA, (2023), RAID \u201923, p. 654\u2013668. https:\/\/doi.org\/10.1145\/3607199.3607242","DOI":"10.1145\/3607199.3607242"},{"key":"888_CR41","doi-asserted-by":"publisher","unstructured":"Sun, S., Wang, S., Wang, X., Xing, Y., Zhang, E., Sun, K.: In 2023 IEEE International Conference on Software Maintenance and Evolution (ICSME) IEEE Computer Society, Los Alamitos, CA, USA, (2023), pp. 171\u2013181. https:\/\/doi.org\/10.1109\/ICSME58846.2023.00027","DOI":"10.1109\/ICSME58846.2023.00027"},{"issue":"8","key":"888_CR42","doi-asserted-by":"publisher","first-page":"4196","DOI":"10.1109\/TSE.2023.3286586","volume":"49","author":"J Zhang","year":"2023","unstructured":"Zhang, J., Liu, Z., Hu, X., Xia, X., Li, S.: Vulnerability detection by learning from syntax-based execution paths of code. IEEE Trans. Softw. Eng. 49(8), 4196 (2023). https:\/\/doi.org\/10.1109\/TSE.2023.3286586","journal-title":"IEEE Trans. Softw. Eng."},{"key":"888_CR43","unstructured":"Ding, Y., Fu, Y.,\u00a0Ibrahim, O., Sitawarin, C., Chen, X., Alomair, B., Wagner, D., Ray, B., Chen, Y.: Vulnerability detection with code language models: how far are we? https:\/\/arxiv.org\/pdf\/2311.16169.pdf (2024). Accessed on June 11th, (2024)"},{"key":"888_CR44","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2024.112014","volume":"214","author":"S Nguyen","year":"2024","unstructured":"Nguyen, S., Nguyen, T.T., Vu, T.T., Do, T.D., Ngo, K.T., Vo, H.D.: Code-centric learning-based just-in-time vulnerability detection. J. Syst. Softw. 214, 112014 (2024). https:\/\/doi.org\/10.1016\/j.jss.2024.112014","journal-title":"J. Syst. Softw."},{"key":"888_CR45","unstructured":"Guo, Y., Hu, Q., Tang, Q., Traon, Y.L.: In 28th European Symposium on Research in Computer Security (ESORICS) IEEE, (2023)"},{"key":"888_CR46","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2019.06.008","volume":"48","author":"RO Andrade","year":"2019","unstructured":"Andrade, R.O., Yoo, S.G.: Cognitive security: A comprehensive study of cognitive science in cybersecurity. J. Inf. Secur. Appl. 48, 102352 (2019). https:\/\/doi.org\/10.1016\/j.jisa.2019.06.008","journal-title":"J. Inf. Secur. Appl."},{"key":"888_CR47","doi-asserted-by":"publisher","unstructured":"Jimenez, M., Rwemalika, R., Papadakis, M., Sarro, F., Le\u00a0Traon, Y., Harman, M.: In ESEC\/FSE ACM, New York, USA, (2019), p. 695\u2013705. https:\/\/doi.org\/10.1145\/3338906.3338941","DOI":"10.1145\/3338906.3338941"},{"issue":"7","key":"888_CR48","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1007\/s10664-022-10197-4","volume":"27","author":"A Garg","year":"2022","unstructured":"Garg, A., Degiovanni, R., Jimenez, M., Cordy, M., Papadakis, M., Le Traon, Y.: Learning from what we know: How to perform vulnerability prediction using noisy historical data. Empirical Softw. Eng. 27(7), 169 (2022). https:\/\/doi.org\/10.1007\/s10664-022-10197-4","journal-title":"Empirical Softw. Eng."},{"key":"888_CR49","unstructured":"Denyer, D., Tranfield, D.: The Sage handbook of organizational research methods pp. 671\u2013689 (2009)"},{"issue":"1","key":"888_CR50","first-page":"9","volume":"37","author":"J Vom Brocke","year":"2015","unstructured":"Vom Brocke, J., Simons, A., Riemer, K., Niehaves, B., Plattfaut, R., Cleven, A.: Standing on the shoulders of giants: Challenges and recommendations of literature search in information systems research. Commun. Assoc. Inf. Syst. 37(1), 9 (2015)","journal-title":"Commun. Assoc. Inf. Syst."},{"key":"888_CR51","unstructured":"F-Droid Contributors. F-droid: free and open source android app repository. https:\/\/f-droid.org\/ (2024). Accessed on January 30th, (2024)"},{"key":"888_CR52","doi-asserted-by":"crossref","unstructured":"Frederick, P.E.B., Boland\u00a0Jr. E.: Computer (IEEE Computer) 45(10) (2012). https:\/\/www.nist.gov\/publications\/juliet-11-cc-and-java-test-suite","DOI":"10.1109\/MC.2012.345"},{"key":"888_CR53","unstructured":"Wang, S., Liu, W., Wu, J., Cao, L., Meng, Q., Kennedy, P.J.: In 2016 international joint conference on neural networks (IJCNN) IEEE, (2016), pp. 4368\u20134374"},{"key":"888_CR54","doi-asserted-by":"publisher","unstructured":"Cui, Y., Jia, M., Lin, T.Y., Song, Y., Belongie, S.: In IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2019), pp. 9260\u20139269. https:\/\/doi.org\/10.1109\/CVPR.2019.00949","DOI":"10.1109\/CVPR.2019.00949"},{"issue":"2","key":"888_CR55","doi-asserted-by":"publisher","first-page":"318","DOI":"10.1109\/TPAMI.2018.2858826","volume":"42","author":"TY Lin","year":"2020","unstructured":"Lin, T.Y., Goyal, P., Girshick, R., He, K., Doll\u00e1r, P.: A detection method for pavement cracks combining object detection and attention mechanism. IEEE Trans. Pattern Anal. Mach. Intell. 42(2), 318 (2020). https:\/\/doi.org\/10.1109\/TPAMI.2018.2858826","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"888_CR56","unstructured":"Guo, Y.: Additonal materials. https:\/\/doi.org\/10.6084\/m9.figshare.25061420 (2024). Accessed on January 30th, (2024)"},{"key":"888_CR57","unstructured":"Alexopoulos, N., Brack, M., Wagner, J.P., Grube, T., M\u00fchlh\u00e4user, M.: In USENIX Security USENIX Association, Boston, MA, (2022), pp. 359\u2013376. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/alexopoulos"},{"key":"888_CR58","unstructured":"Kupsch, J.A., Miller, B.P.: In First International Workshop on Managing Insider Security Threats (MIST) (2009), pp. 83\u201397"},{"key":"888_CR59","unstructured":"Guo, Y.: Software vulnerability detection datasets - function\/methond level (2023)"},{"key":"888_CR60","unstructured":"National Institute of Standards and Technology. U.S. Department of Commerce. Nvd data feeds. https:\/\/nvd.nist.gov\/vuln\/data-feeds (2024). Accessed on January 30th, 2024"},{"key":"888_CR61","unstructured":"The MITRE Corporation. 2023 cwe top 25 most dangerous software weaknesses. https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html (2024). Accessed on January 30th, 2024"},{"key":"888_CR62","doi-asserted-by":"publisher","unstructured":"Dong, Z., Hu, Q., Guo, Y., Cordy, M., Papadakis, M., Zhang, Z., Traon, Y.L., Zhao, J.: In IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) IEEE Computer Society, Los Alamitos, CA, USA, (2023), pp. 379\u2013390. https:\/\/doi.org\/10.1109\/SANER56733.2023.00043","DOI":"10.1109\/SANER56733.2023.00043"},{"key":"888_CR63","doi-asserted-by":"publisher","unstructured":"Yang, Z., Shi, J., He, J., Lo, D.: In ICSE ACM, New York, USA, (2022), p. 1482\u20131493. https:\/\/doi.org\/10.1145\/3510003.3510146","DOI":"10.1145\/3510003.3510146"},{"key":"888_CR64","doi-asserted-by":"publisher","first-page":"32150","DOI":"10.1109\/ACCESS.2020.2973219","volume":"8","author":"G Karatas","year":"2020","unstructured":"Karatas, G., Demir, O., Sahingoz, O.K.: Increasing the performance of machine learning-based IDSs on an imbalanced and up-to-date dataset. IEEE Access 8, 32150 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.2973219","journal-title":"IEEE Access"},{"issue":"1","key":"888_CR65","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1145\/1007730.1007735","volume":"6","author":"GE Batista","year":"2004","unstructured":"Batista, G.E., Prati, R.C., Monard, M.C.: A study of the behavior of several methods for balancing machine learning training data. ACM SIGKDD Explor. Newslett. 6(1), 20 (2004)","journal-title":"ACM SIGKDD Explor. Newslett."},{"key":"888_CR66","doi-asserted-by":"publisher","unstructured":"Nguyen, N., Nadi, S.: In Proceedings of the 19th International Conference on Mining Software Repositories Association for Computing Machinery, New York, NY, USA, (2022), MSR \u201922, pp. 1\u20135. https:\/\/doi.org\/10.1145\/3524842.3528470","DOI":"10.1145\/3524842.3528470"},{"key":"888_CR67","unstructured":"Bommasani, R., Klyman, K., Longpre, S., Kapoor, S., Maslej, N., Xiong, B., Zhang, D., Liang, P.: The foundation model transparency index. https:\/\/arxiv.org\/pdf\/2310.12941.pdf (2023). Accessed on January 30th, (2024)"},{"key":"888_CR68","unstructured":"European Parliament. Artificial intelligence act. https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-9-2023-0236_EN.html (2023). Accessed on January 30th, 2024"},{"key":"888_CR69","doi-asserted-by":"publisher","unstructured":"Guo, Y., Bettaieb, S.: In 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS &PW) IEEE Computer Society, Los Alamitos, CA, USA, (2023), pp. 29\u201333. https:\/\/doi.org\/10.1109\/EuroSPW59978.2023.00008","DOI":"10.1109\/EuroSPW59978.2023.00008"},{"issue":"4","key":"888_CR70","doi-asserted-by":"publisher","first-page":"1","DOI":"10.5815\/ijem.2022.04.01","volume":"12","author":"H Kek\u00fcl","year":"2022","unstructured":"Kek\u00fcl, H., Ergen, B., Arslan, H.: Comparison and analysis of software vulnerability databases. Int. J. Eng. Manuf. 12(4), 1 (2022). https:\/\/doi.org\/10.5815\/ijem.2022.04.01","journal-title":"Int. J. Eng. Manuf."},{"key":"888_CR71","doi-asserted-by":"publisher","unstructured":"Croft, R., Babar, M.A., Kholoosi, M.: In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE) IEEE Computer Society, Los Alamitos, CA, USA, (2023), pp. 121\u2013133. https:\/\/doi.org\/10.1109\/ICSE48619.2023.00022","DOI":"10.1109\/ICSE48619.2023.00022"},{"key":"888_CR72","doi-asserted-by":"publisher","unstructured":"Hanif, H., Md Nasir, M.H.N., Ab Razak, M.F., Firdaus, A., Anuar, N.B.: Journal of Network and Computer Applications 179, 103009 (2021). https:\/\/doi.org\/10.1016\/j.jnca.2021.103009","DOI":"10.1016\/j.jnca.2021.103009"},{"key":"888_CR73","doi-asserted-by":"publisher","unstructured":"Nie, X., Li, N., Wang, K., Wang, S., Luo, X., Wang, H.: In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis Association for Computing Machinery, New York, NY, USA, 2023, ISSTA (2023), p. 52\u201363. https:\/\/doi.org\/10.1145\/3597926.3598037","DOI":"10.1145\/3597926.3598037"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-024-00888-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-024-00888-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-024-00888-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,14]],"date-time":"2024-09-14T01:06:45Z","timestamp":1726276005000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-024-00888-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7,23]]},"references-count":73,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2024,10]]}},"alternative-id":["888"],"URL":"https:\/\/doi.org\/10.1007\/s10207-024-00888-y","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7,23]]},"assertion":[{"value":"23 July 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could appear to influence the work described in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"The authors declare full compliance with ethical standards. This article does not contain any studies involving humans or animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}}]}}