{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T14:20:40Z","timestamp":1784816440192,"version":"3.55.0"},"reference-count":58,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T00:00:00Z","timestamp":1739404800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T00:00:00Z","timestamp":1739404800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Universidad Carlos III"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2025,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Design flows, code errors, or inadequate countermeasures may occur in software development. Some of them lead to vulnerabilities in the code, opening the door to attacks. Assorted techniques are developed to detect vulnerable code samples, making artificial intelligence techniques, such as Machine Learning (ML), a common practice. Nonetheless, the security of ML is a major concern. This includes the the case of ML-based detection whose training process is affected by data poisoning. More generally, vulnerability detection can be evaded unless poisoning attacks are properly handled. This paper tackles this problem. A novel vulnerability detection system based on ML-based image processing, using Convolutional Neural Network (CNN), is proposed. The system, hereinafter called IVul, is evaluated under the presence of backdoor attacks, a precise type of poisoning in which a pattern is introduced in the training data to alter the expected behavior of the learned models. IVul is evaluated with more than three thousand code samples associated with two representative programming languages (C# and PHP). IVul outperforms other comparable state-of-the-art vulnerability detectors in the literature, reaching\n                    <jats:inline-formula>\n                      <jats:alternatives>\n                        <jats:tex-math>$$82\\%$$<\/jats:tex-math>\n                        <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                          <mml:mrow>\n                            <mml:mn>82<\/mml:mn>\n                            <mml:mo>%<\/mml:mo>\n                          <\/mml:mrow>\n                        <\/mml:math>\n                      <\/jats:alternatives>\n                    <\/jats:inline-formula>\n                    to\n                    <jats:inline-formula>\n                      <jats:alternatives>\n                        <jats:tex-math>$$99\\%$$<\/jats:tex-math>\n                        <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                          <mml:mrow>\n                            <mml:mn>99<\/mml:mn>\n                            <mml:mo>%<\/mml:mo>\n                          <\/mml:mrow>\n                        <\/mml:math>\n                      <\/jats:alternatives>\n                    <\/jats:inline-formula>\n                    detection accuracy. Besides, results show that the type of attack may affect a particular language more than another, though, in general, PHP is more resilient to proposed attacks than C#.\n                  <\/jats:p>","DOI":"10.1007\/s10207-025-00989-2","type":"journal-article","created":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T07:45:09Z","timestamp":1739432709000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Software vulnerability detection under poisoning attacks using CNN-based image processing"],"prefix":"10.1007","volume":"24","author":[{"given":"Lorena","family":"Gonz\u00e1lez-Manzano","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joaquin","family":"Garcia-Alfaro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,2,13]]},"reference":[{"key":"989_CR1","volume-title":"Designing Security Architecture Solutions","author":"J Ramachandran","year":"2002","unstructured":"Ramachandran, J.: Designing Security Architecture Solutions. Wiley, Hoboken (2002)"},{"issue":"10","key":"989_CR2","doi-asserted-by":"crossref","first-page":"1825","DOI":"10.1109\/JPROC.2020.2993293","volume":"108","author":"G Lin","year":"2020","unstructured":"Lin, G., Wen, S., Han, Q.-L., Zhang, J., Xiang, Y.: Software vulnerability detection using deep neural networks: a survey. Proc. IEEE 108(10), 1825\u20131848 (2020)","journal-title":"Proc. IEEE"},{"key":"989_CR3","doi-asserted-by":"crossref","DOI":"10.1016\/j.infsof.2023.107168","volume":"158","author":"Y Dong","year":"2023","unstructured":"Dong, Y., Tang, Y., Cheng, X., Yang, Y., Wang, S.: Sedsvd: statement-level software vulnerability detection based on relational graph convolutional network with subgraph embedding. Inf. Softw. Technol. 158, 107168 (2023)","journal-title":"Inf. Softw. Technol."},{"key":"989_CR4","doi-asserted-by":"crossref","first-page":"74562","DOI":"10.1109\/ACCESS.2020.2988557","volume":"8","author":"M Zagane","year":"2020","unstructured":"Zagane, M., Abdi, M.K., Alenezi, M.: Deep learning for software vulnerabilities detection using code metrics. IEEE Access 8, 74562\u201374570 (2020)","journal-title":"IEEE Access"},{"issue":"8","key":"989_CR5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3551636","volume":"55","author":"Z Tian","year":"2022","unstructured":"Tian, Z., Cui, L., Liang, J., Yu, S.: A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv. 55(8), 1\u201335 (2022)","journal-title":"ACM Comput. Surv."},{"issue":"10","key":"989_CR6","doi-asserted-by":"crossref","first-page":"2279","DOI":"10.1016\/S0031-3203(01)00178-9","volume":"35","author":"M Egmont-Petersen","year":"2002","unstructured":"Egmont-Petersen, M., de Ridder, D., Handels, H.: Image processing with neural networks-a review. Pattern Recogn. 35(10), 2279\u20132301 (2002)","journal-title":"Pattern Recogn."},{"key":"989_CR7","doi-asserted-by":"crossref","unstructured":"Albawi, S., Mohammed, T.A., Al-Zawi, S.: Understanding of a convolutional neural network. In: 2017 International Conference on Engineering and Technology (ICET). IEEE, pp. 1\u20136 (2017)","DOI":"10.1109\/ICEngTechnol.2017.8308186"},{"key":"989_CR8","unstructured":"Nwankpa, C., Ijomah, W., Gachagan, A., Marshall, S.: Activation functions: comparison of trends in practice and research for deep learning. arXiv preprint arXiv:1811.03378 (2018)"},{"issue":"02","key":"989_CR9","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1142\/S0218488598000094","volume":"6","author":"S Hochreiter","year":"1998","unstructured":"Hochreiter, S.: The vanishing gradient problem during learning recurrent neural nets and problem solutions. Internat. J. Uncertain. Fuzziness Knowl. Based Syst. 6(02), 107\u2013116 (1998)","journal-title":"Internat. J. Uncertain. Fuzziness Knowl. Based Syst."},{"key":"989_CR10","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1016\/j.future.2020.12.020","volume":"118","author":"S Marrone","year":"2021","unstructured":"Marrone, S., Papa, C., Sansone, C.: Effects of hidden layer sizing on CNN fine-tuning. Futur. Gener. Comput. Syst. 118, 48\u201355 (2021)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"989_CR11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.neunet.2015.07.007","volume":"71","author":"H Wu","year":"2015","unstructured":"Wu, H., Gu, X.: Towards dropout training for convolutional neural networks. Neural Netw. 71, 1\u201310 (2015)","journal-title":"Neural Netw."},{"key":"989_CR12","unstructured":"Tran, B., Li, J., Madry, A.: Spectral signatures in backdoor attacks. Adv. Neural Inf. Process. Syst. vol.\u00a031, (2018)"},{"key":"989_CR13","unstructured":"Chen, B., Carvalho, W., Baracaldo, N., Ludwig, H., Edwards, B., Lee, T., Molloy, I., Srivastava, B.: Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)"},{"key":"989_CR14","unstructured":"Severi, G., Meyer, J., Coull, S., Oprea, A.: $$\\{$$Explanation-Guided$$\\}$$ backdoor poisoning attacks against malware classifiers. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 1487\u20131504 (2021)"},{"key":"989_CR15","doi-asserted-by":"crossref","unstructured":"Taunk, K., De, S., Verma, S., Swetapadma, A.: A brief review of nearest neighbor algorithm for learning and classification. In: 2019 International Conference on Intelligent Computing and Control Systems (ICCS). IEEE, pp. 1255\u20131260 (2019)","DOI":"10.1109\/ICCS45141.2019.9065747"},{"key":"989_CR16","doi-asserted-by":"crossref","unstructured":"Talebi, H., Milanfar, P.: Learning to resize images for computer vision tasks. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 497\u2013506 (2021)","DOI":"10.1109\/ICCV48922.2021.00055"},{"key":"989_CR17","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107138","volume":"171","author":"D Vasan","year":"2020","unstructured":"Vasan, D., Alazab, M., Wassan, S., Naeem, H., Safaei, B., Zheng, Q.: Imcfn: image-based malware classification using fine-tuned convolutional neural network architecture. Comput. Netw. 171, 107138 (2020)","journal-title":"Comput. Netw."},{"key":"989_CR18","doi-asserted-by":"crossref","unstructured":"Aghakhani, H., Dai, W., Manoel, A., Fernandes, X., Kharkar, A., Kruegel, C., Vigna, G., Evans, D., Zorn, B., Sim, R.: Trojanpuzzle: covertly poisoning code-suggestion models. arXiv preprint arXiv:2301.02344 (2023)","DOI":"10.1109\/SP54263.2024.00140"},{"key":"989_CR19","doi-asserted-by":"crossref","unstructured":"Henkel, J., Ramakrishnan, G., Wang, Z., Albarghouthi, A., Jha, S., Reps, T.: Semantic robustness of models of source code. In: 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, pp. 526\u2013537 (2022)","DOI":"10.1109\/SANER53432.2022.00070"},{"key":"989_CR20","doi-asserted-by":"crossref","unstructured":"Li, Y., Liu, S., Chen, K., Xie, X., Zhang, T., Liu, Y.: Multi-target backdoor attacks for code pre-trained models. In: Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (2023)","DOI":"10.18653\/v1\/2023.acl-long.399"},{"key":"989_CR21","unstructured":"Black, P.E.: Sard: A software Assurance Reference Dataset (2017)"},{"key":"989_CR22","doi-asserted-by":"crossref","unstructured":"Wu, F., Wang, J., Liu, J., Wang, W.: Vulnerability detection with deep learning. In: 2017 3rd IEEE International Conference on Computer and Communications (ICCC). IEEE, pp. 1298\u20131302 (2017)","DOI":"10.1109\/CompComm.2017.8322752"},{"issue":"4","key":"989_CR23","doi-asserted-by":"crossref","first-page":"531","DOI":"10.1002\/sam.11583","volume":"15","author":"VR Joseph","year":"2022","unstructured":"Joseph, V.R.: Optimal ratio for data splitting. Stat. Anal. Data Min. ASA Data Sci. J. 15(4), 531\u2013538 (2022)","journal-title":"Stat. Anal. Data Min. ASA Data Sci. J."},{"issue":"1","key":"989_CR24","first-page":"1","volume":"1","author":"AA Mughal","year":"2018","unstructured":"Mughal, A.A.: The art of cybersecurity: defense in depth strategy for robust protection. Int. J. Intell. Autom. Comput. 1(1), 1\u201320 (2018)","journal-title":"Int. J. Intell. Autom. Comput."},{"issue":"12","key":"989_CR25","doi-asserted-by":"crossref","first-page":"1284","DOI":"10.1109\/32.106988","volume":"17","author":"GK Gill","year":"1991","unstructured":"Gill, G.K., Kemerer, C.F.: Cyclomatic complexity density and software maintenance productivity. IEEE Trans. Softw. Eng. 17(12), 1284\u20131288 (1991)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"989_CR26","doi-asserted-by":"crossref","unstructured":"Chen, Y., Ding, Z., Alowain, L., Chen, X., Wagner, D.: Diversevul: a new vulnerable source code dataset for deep learning based vulnerability detection (2023)","DOI":"10.1145\/3607199.3607242"},{"key":"989_CR27","doi-asserted-by":"crossref","unstructured":"Bhandari, G., Naseer, A., Moonen, L.: Cvefixes: automated collection of vulnerabilities and their fixes from open-source software. In: Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering, pp. 30\u201339 (2021)","DOI":"10.1145\/3475960.3475985"},{"key":"989_CR28","unstructured":"Yin, T.: Lizard: an extensible cyclomatic complexity analyzer. Astrophysics Source Code Library, pp. ascl\u20131906, (2019)"},{"key":"989_CR29","doi-asserted-by":"crossref","unstructured":"Chernis, B., Verma, R.: Machine learning methods for software vulnerability detection. In: Proceedings of the Fourth ACM International Workshop on Security and Privacy Analytics, pp. 31\u201339 (2018)","DOI":"10.1145\/3180445.3180453"},{"key":"989_CR30","doi-asserted-by":"crossref","DOI":"10.1016\/j.jss.2022.111283","volume":"188","author":"F Lomio","year":"2022","unstructured":"Lomio, F., Iannone, E., De Lucia, A., Palomba, F., Lenarduzzi, V.: Just-in-time software vulnerability detection: Are we there yet? J. Syst. Softw. 188, 111283 (2022)","journal-title":"J. Syst. Softw."},{"issue":"Suppl 1","key":"989_CR31","first-page":"23","volume":"14","author":"EC Alexopoulos","year":"2010","unstructured":"Alexopoulos, E.C.: Introduction to multivariate regression analysis. Hippokratia 14(Suppl 1), 23 (2010)","journal-title":"Hippokratia"},{"key":"989_CR32","volume-title":"Optimal Sports Math, Statistics, and Fantasy. Chapter 2 - Regression Models","author":"R Kissell","year":"2017","unstructured":"Kissell, R., Poserina, J.: Optimal Sports Math, Statistics, and Fantasy. Chapter 2 - Regression Models. Academic Press, Cambridge (2017)"},{"key":"989_CR33","doi-asserted-by":"crossref","unstructured":"Hanif, H., Maffeis, S.: Vulberta: simplified source code pre-training for vulnerability detection. In: 2022 International Joint Conference on Neural Networks (IJCNN). IEEE, pp. 1\u20138 (2022)","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"key":"989_CR34","doi-asserted-by":"crossref","unstructured":"Shapira, T., Shavitt, Y.: Flowpic: encrypted internet traffic classification is as easy as image recognition. In: IEEE INFOCOM 2019-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS). IEEE, pp. 680\u2013687 (2019)","DOI":"10.1109\/INFCOMW.2019.8845315"},{"key":"989_CR35","doi-asserted-by":"crossref","unstructured":"Salman,O., Elhajj, I.H., Chehab, A., Kayssi, A.: A multi-level internet traffic classifier using deep learning. In: 2018 9th International Conference on the Network of the Future (NOF). IEEE, pp. 68\u201375 (2018)","DOI":"10.1109\/NOF.2018.8598055"},{"key":"989_CR36","doi-asserted-by":"crossref","unstructured":"Bendiab, G., Shiaeles, S., Alruban, A., Kolokotronis, N.: IoT malware network traffic classification using visual representation and deep learning. In: 2020 6th IEEE Conference on Network Softwarization (NetSoft). IEEE, pp. 444\u2013449 (2020)","DOI":"10.1109\/NetSoft48620.2020.9165381"},{"key":"989_CR37","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., Manjunath, B. S.: Malware images: visualization and automatic classification. In: Proceedings of the 8th International Symposium on Visualization for Cyber Security, pp. 1\u20137 (2011)","DOI":"10.1145\/2016904.2016908"},{"key":"989_CR38","doi-asserted-by":"crossref","unstructured":"Wu, Y, Zou, D, Dou, S, Yang, W, Xu, D, Jin, H.: Vulcnn: an image-inspired scalable vulnerability detection system. In: Proceedings of the 44th International Conference on Software Engineering, pp. 2365\u20132376 (2022)","DOI":"10.1145\/3510003.3510229"},{"key":"989_CR39","doi-asserted-by":"crossref","unstructured":"Fu, M., Tantithamthavorn, C.: Linevul: a transformer-based line-level vulnerability prediction. In: Proceedings of the 19th International Conference on Mining Software Repositories, pp. 608\u2013620 (2022)","DOI":"10.1145\/3524842.3528452"},{"issue":"1","key":"989_CR40","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1007\/s10664-023-10346-3","volume":"29","author":"M Fu","year":"2024","unstructured":"Fu, M., Tantithamthavorn, C., Le, T., Kume, Y., Nguyen, V., Phung, D., Grundy, J.: Aibughunter: a practical tool for predicting, classifying and repairing software vulnerabilities. Empir. Softw. Eng. 29(1), 4 (2024)","journal-title":"Empir. Softw. Eng."},{"key":"989_CR41","doi-asserted-by":"crossref","unstructured":"Fu, M., Tantithamthavorn, C., Nguyen, V., Le, T.: Chatgpt for vulnerability detection, classification, and repair: How far are we?\u201d arXiv preprint arXiv:2310.09810 (2023)","DOI":"10.1109\/APSEC60848.2023.00085"},{"issue":"4","key":"989_CR42","doi-asserted-by":"crossref","first-page":"2244","DOI":"10.1109\/TDSC.2021.3051525","volume":"19","author":"Z Li","year":"2021","unstructured":"Li, Z., Zou, D., Xu, S., Jin, H., Zhu, Y., Chen, Z.: Sysevr: a framework for using deep learning to detect software vulnerabilities. IEEE Trans. Depend. Secure Comput. 19(4), 2244\u20132258 (2021)","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"989_CR43","unstructured":"Yang, Z., Xu, B., Zhang, J.M., Kang, H., Shi, J., He, J., Lo, D.: Stealthy backdoor attack for code models. IEEE Trans. Softw. Eng., no.\u00a001, pp. 1\u201321, 5555"},{"key":"989_CR44","doi-asserted-by":"crossref","unstructured":"Li, Z., Zou, D., Xu, S., Ou, X., Jin, H., Wang, S., Deng, Z., Zhong, Y.: Vuldeepecker: a deep learning-based system for vulnerability detection. In: Network and Distributed System Security (NDSS) Symposium, (2018)","DOI":"10.14722\/ndss.2018.23158"},{"key":"989_CR45","unstructured":"Schuster, R., Song, C., Tromer, E., Shmatikov, V.: You autocomplete me: poisoning vulnerabilities in neural code completion. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 1559\u20131575 (2021)"},{"key":"989_CR46","doi-asserted-by":"crossref","DOI":"10.1016\/j.infsof.2021.106809","volume":"144","author":"L Wartschinski","year":"2022","unstructured":"Wartschinski, L., Noller, Y., Vogel, T., Kehrer, T., Grunske, L.: Vudenc: vulnerability detection with deep learning on a natural codebase for python. Inf. Softw. Technol. 144, 106809 (2022)","journal-title":"Inf. Softw. Technol."},{"key":"989_CR47","doi-asserted-by":"crossref","unstructured":"Li, J., Li, Z., Zhang, H., Li, G., Jin, Z., Hu, X., Xia, X.: Poison attack and poison detection on deep source code processing models. ACM Trans. Softw. Eng. Methodol. (2023)","DOI":"10.1145\/3630008"},{"key":"989_CR48","doi-asserted-by":"crossref","unstructured":"Wan, Y., Zhang, S., Zhang, H., Sui, Y., Xu, G., Yao, D., Jin, H., Sun, L.: You see what i want you to see: poisoning vulnerabilities in neural code search. In: Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 1233\u20131245 (2022)","DOI":"10.1145\/3540250.3549153"},{"key":"989_CR49","doi-asserted-by":"crossref","DOI":"10.1016\/j.jss.2023.111623","volume":"199","author":"W Tang","year":"2023","unstructured":"Tang, W., Tang, M., Ban, M., Zhao, Z., Feng, M.: Csgvd: a deep learning approach combining sequence and graph embedding for source code vulnerability detection. J. Syst. Softw. 199, 111623 (2023)","journal-title":"J. Syst. Softw."},{"key":"989_CR50","doi-asserted-by":"crossref","unstructured":"Sun, W., Chen, Y., Tao, G., Fang, C., Zhang, X., Zhang, Q., Luo, B.: Backdooring neural code search. arXiv preprint arXiv:2305.17506 (2023)","DOI":"10.18653\/v1\/2023.acl-long.540"},{"key":"989_CR51","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11227-023-05282-4","volume":"79","author":"C Do Xuan","year":"2023","unstructured":"Do Xuan, C., Mai, D.H., Thanh, M.C., Van Cong, B.: A novel approach for software vulnerability detection based on intelligent cognitive computing. J. Supercomput. 79, 1\u201337 (2023)","journal-title":"J. Supercomput."},{"key":"989_CR52","unstructured":"Qi, S., Yang, Y., Gao, S., Gao, C., Xu, Z.: Badcs: a backdoor attack framework for code search. arXiv preprint arXiv:2305.05503 (2023)"},{"key":"989_CR53","doi-asserted-by":"crossref","unstructured":"Fidalgo, A., Medeiros, I., Antunes, P., Neves, N.: Towards a deep learning model for vulnerability detection on web application variants. In: 2020 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW). IEEE, pp. 465\u2013476 (2020)","DOI":"10.1109\/ICSTW50294.2020.00083"},{"key":"989_CR54","doi-asserted-by":"crossref","unstructured":"Ramakrishnan, G., Albarghouthi, A.: Backdoors in neural models of source code. In: 2022 26th International Conference on Pattern Recognition (ICPR). IEEE, pp. 2892\u20132899 (2022)","DOI":"10.1109\/ICPR56361.2022.9956690"},{"key":"989_CR55","first-page":"652","volume":"2022","author":"Z Sun","year":"2022","unstructured":"Sun, Z., Du, X., Song, F., Ni, M., Li, L.: Coprotector: protect open-source code against unauthorized training usage with data poisoning. Proc. ACM Web Conf. 2022, 652\u2013660 (2022)","journal-title":"Proc. ACM Web Conf."},{"key":"989_CR56","doi-asserted-by":"crossref","unstructured":"Hin, D., Kan, A., Chen, H., Babar, M.A.: Linevd: Statement-level vulnerability detection using graph neural networks. In: Proceedings of the 19th International Conference on Mining Software Repositories, pp. 596\u2013607 (2022)","DOI":"10.1145\/3524842.3527949"},{"key":"989_CR57","unstructured":"Mirsky, Y., Macon, G., Brown, M., Yagemann, C., Pruett, M., Downing, E., Mertoguno, S., Lee, W.: Vulchecker: graph-based vulnerability localization in source code. In: 31st USENIX Security Symposium, Security 2022, (2023)"},{"key":"989_CR58","doi-asserted-by":"crossref","unstructured":"Li, Y., Wang, S., Nguyen, T.N.: Vulnerability detection with fine-grained interpretations. In: Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 292\u2013303 (2021)","DOI":"10.1145\/3468264.3468597"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-00989-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-025-00989-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-00989-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,30]],"date-time":"2025-03-30T04:03:54Z","timestamp":1743307434000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-025-00989-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,13]]},"references-count":58,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["989"],"URL":"https:\/\/doi.org\/10.1007\/s10207-025-00989-2","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-4142473\/v1","asserted-by":"object"}]},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,13]]},"assertion":[{"value":"13 February 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Authors declare they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interest"}}],"article-number":"75"}}