{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T04:04:33Z","timestamp":1782878673871,"version":"3.54.5"},"reference-count":62,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2021,3,29]],"date-time":"2021-03-29T00:00:00Z","timestamp":1616976000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,3,29]],"date-time":"2021-03-29T00:00:00Z","timestamp":1616976000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2021,5]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Detecting vulnerabilities in software is a constant race between development teams and potential attackers. While many static and dynamic approaches have focused on regularly analyzing the software in its entirety, a recent research direction has focused on the analysis of changes that are applied to the code. VCCFinder is a seminal approach in the literature that builds on machine learning to automatically detect whether an incoming commit will introduce some vulnerabilities. Given the influence of VCCFinder in the literature, we undertake an investigation into its performance as a state-of-the-art system. To that end, we propose to attempt a replication study on the VCCFinder supervised learning approach. The insights of our failure to replicate the results reported in the original publication informed the design of a new approach to identify vulnerability-contributing commits based on a semi-supervised learning technique with an alternate feature set. We provide all artefacts and a clear description of this approach as a <jats:bold>new reproducible baseline<\/jats:bold> for advancing research on machine learning-based identification of vulnerability-introducing commits.<\/jats:p>","DOI":"10.1007\/s10664-021-09944-w","type":"journal-article","created":{"date-parts":[[2021,3,29]],"date-time":"2021-03-29T19:02:40Z","timestamp":1617044560000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["Revisiting the VCCFinder approach for the identification of vulnerability-contributing commits"],"prefix":"10.1007","volume":"26","author":[{"given":"Timoth\u00e9","family":"Riom","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Arthur","family":"Sawadogo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kevin","family":"Allix","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tegawend\u00e9 F.","family":"Bissyand\u00e9","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Naouel","family":"Moha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jacques","family":"Klein","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,3,29]]},"reference":[{"key":"9944_CR1","doi-asserted-by":"publisher","unstructured":"Alohaly M, Takabi H (2017) When do changes induce software vulnerabilities?. In: 2017 IEEE 3rd International conference on collaboration and internet computing (CIC). pp 59\u201366. https:\/\/doi.org\/10.1109\/CIC.2017.00020","DOI":"10.1109\/CIC.2017.00020"},{"key":"9944_CR2","doi-asserted-by":"crossref","unstructured":"Arusoaie A, Ciob\u00e2ca S, Craciun V, Gavrilut D, Lucanu D (2017) A comparison of open-source static analysis tools for vulnerability detection in c\/c++ code. In: 2017 19th International symposium on symbolic and numeric algorithms for scientific computing (SYNASC), IEEE. pp 161\u2013168","DOI":"10.1109\/SYNASC.2017.00035"},{"key":"9944_CR3","doi-asserted-by":"publisher","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Le Traon Y, Octeau D, McDaniel P (2014) Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware tain analysis for android apps. In: Proceedings of the 35th ACM SIGPLAN Conference on programming language design and implementation, association for computing machinery, New York, NY, USA, PLDI \u201914, pp 259\u2013269. https:\/\/doi.org\/10.1145\/2594291.2594299","DOI":"10.1145\/2594291.2594299"},{"key":"9944_CR4","unstructured":"Association for Computer Machinery (2020) Artifact review and badging. https:\/\/www.acm.org\/publications\/policies\/artifact-review-badging-current, accessed November27, 2020"},{"key":"9944_CR5","unstructured":"Balcan M F, Blum A (2005) A pac-style model for learning from labeled and unlabeled data. In: International conference on computational learning theory, Springer. pp 111\u2013126"},{"issue":"19","key":"9944_CR6","doi-asserted-by":"publisher","first-page":"e5103","DOI":"10.1002\/cpe.5103","volume":"31","author":"X Ban","year":"2019","unstructured":"Ban X, Liu S, Chen C, Chua C (2019) A performance evaluation of deep-learnt features for software vulnerability detection. Concurr Comput Pract Exp 31(19):e5103. https:\/\/doi.org\/10.1002\/cpe.5103","journal-title":"Concurr Comput Pract Exp"},{"key":"9944_CR7","doi-asserted-by":"publisher","unstructured":"Blum A, Mitchell T (1998) Combining labeled and unlabeled data with co-training. In: Proceedings of the Eleventh annual conference on computational learning theory, association for computing machinery, New York, NY, USA, COLT\u2019 98, pp 92\u2013100. https:\/\/doi.org\/10.1145\/279943.279962","DOI":"10.1145\/279943.279962"},{"issue":"2","key":"9944_CR8","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1145\/2408776.2408795","volume":"56","author":"C Cadar","year":"2013","unstructured":"Cadar C, Sen K (2013) Symbolic execution for software testing: Three decades later. Commun ACM 56(2):82\u201390. https:\/\/doi.org\/10.1145\/2408776.2408795","journal-title":"Commun ACM"},{"key":"9944_CR9","unstructured":"Cadar C, Dunbar D, Engler D (2008) Klee: Unassisted and automatic generation of high-coverage tests for complex systems programs. In: Proceedings of the 8th USENIX Conference on operating systems design and implementation, USENIX Association, USA, OSDI\u201908, pp 209\u2013224"},{"issue":"1","key":"9944_CR10","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1016\/0167-8655(94)00074-D","volume":"16","author":"V Castelli","year":"1995","unstructured":"Castelli V, Cover T M (1995) On the exponential value of labeled samples. Pattern Recogn. Lett. 16(1):105\u2013111","journal-title":"Pattern Recogn. Lett."},{"issue":"5","key":"9944_CR11","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1109\/TSE.2008.24","volume":"34","author":"R Chang","year":"2008","unstructured":"Chang R, Podgurski A, Yang J (2008) Discovering neglected conditions in software by mining dependence graphs. IEEE Trans. Softw. Eng. 34 (5):579\u2013596. https:\/\/doi.org\/10.1109\/TSE.2008.24","journal-title":"IEEE Trans. Softw. Eng."},{"key":"9944_CR12","unstructured":"Cho C Y, Babiundefined D, Poosankam P, Chen K Z, Wu E X, Song D (2011) Mace: Model-inference-assisted concolic exploration for protocol and vulnerability discovery. In: Proceedings of the 20th USENIX Conference on security, USENIX Association, USA, SEC\u201911. pp 10"},{"key":"9944_CR13","first-page":"1871","volume":"9","author":"RE Fan","year":"2008","unstructured":"Fan R E, Chang K W, Hsieh C J, Wang X R, Lin C J (2008) Liblinear: A library for large linear classification. J Mach Learn Res 9:1871\u20131874","journal-title":"J Mach Learn Res"},{"key":"9944_CR14","doi-asserted-by":"publisher","unstructured":"Feng Q, Zhou R, Xu C, Cheng Y, Testa B, Yin H (2016) Scalable graph-based bug search for firmware images. In: Proceedings of the ACM SIGSAC Conference on computer and communications security, association for computing machinery, New York, NY, USA, CCS \u201916, pp 480\u2013491. https:\/\/doi.org\/10.1145\/2976749.2978370","DOI":"10.1145\/2976749.2978370"},{"issue":"4","key":"9944_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3092566","volume":"50","author":"SM Ghaffarian","year":"2017","unstructured":"Ghaffarian S M, Shahriari H R (2017) Software vulnerability analysis and discovery using machine-learning and data-mining techniques: A survey. ACM Comput Surv (CSUR) 50(4):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"key":"9944_CR16","doi-asserted-by":"publisher","unstructured":"Goseva-Popstojanova K, Tyo J (2018) Identification of security related bug reports via text mining using supervised and unsupervised classification. In: 2018 IEEE International conference on software quality, reliability and security (QRS), pp 344\u2013355. https:\/\/doi.org\/10.1109\/QRS.2018.00047","DOI":"10.1109\/QRS.2018.00047"},{"key":"9944_CR17","unstructured":"Gro\u00df S (2018) Fuzzil: Coverage guided fuzzing for javascript engines. Master\u2019s thesis, Karlsruhe Institute of Technology"},{"key":"9944_CR18","doi-asserted-by":"crossref","unstructured":"Hogan K, Warford N, Morrison R, Miller D, Malone S, Purtilo J (2019) The challenges of labeling vulnerability-contributing commits. In: 2019 IEEE International symposium on software reliability engineering workshops (ISSREW). IEEE, pp 270\u2013275","DOI":"10.1109\/ISSREW.2019.00083"},{"key":"9944_CR19","unstructured":"Holzmann GJ (2002) Uno: Static source code checking for userdefined properties. In: 6th World conference on integrated design and process technology, IDPT \u201902"},{"key":"9944_CR20","unstructured":"Hsu CW, Chang CC, Lin CJ (2003) A practical guide to support vector classification. Tech. rep., Department of Computer Science, National Taiwan University. http:\/\/www.csie.ntu.edu.tw\/cjlin\/papers.html"},{"key":"9944_CR21","doi-asserted-by":"crossref","unstructured":"Kersten R, Luckow K S (2017) Poster: Afl-based fuzzing for java with kelinci. In: ACM Conference on computer and communications security","DOI":"10.1145\/3133956.3138820"},{"issue":"2","key":"9944_CR22","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1109\/TSE.2007.70773","volume":"34","author":"S Kim","year":"2008","unstructured":"Kim S, Whitehead EJ Jr, Zhang Y (2008) Classifying software changes: Clean or buggy? IEEE Trans. Softw. Eng. 34(2):181\u2013196. https:\/\/doi.org\/10.1109\/TSE.2007.70773","journal-title":"IEEE Trans. Softw. Eng."},{"key":"9944_CR23","doi-asserted-by":"crossref","unstructured":"Klees G, Ruef A, Cooper B, Wei S, Hicks M (2018) Evaluating fuzz testing. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp 2123\u20132138","DOI":"10.1145\/3243734.3243804"},{"key":"9944_CR24","unstructured":"Kononenko I (1995) On biases in estimating multi-valued attributes. In: Proceedings of the 14th International joint conference on artificial intelligence - Volume 2, Morgan Kaufmann Publishers Inc., San Francisco, CA, USA, IJCAI\u201995, pp 1034\u20131040"},{"key":"9944_CR25","unstructured":"Krsul I V (1998) Software vulnerability analysis. Purdue University West Lafayette, IN"},{"key":"9944_CR26","unstructured":"Larochelle D, Evans D (2001) Statically detecting likely buffer overflow vulnerabilities. In: Proceedings of the 10th Conference on USENIX security symposium - Volume 10, USENIX Association, USA, SSYM\u201901"},{"key":"9944_CR27","unstructured":"Levin A, Viola P, Freund Y (2003) Unsupervised improvement of visual detectors using co-training. In: IEEE, p 626"},{"key":"9944_CR28","doi-asserted-by":"crossref","unstructured":"Li H, Oh J, Oh H, Lee H (2016a) Automated source code instrumentation for verifying potential vulnerabilities. In: Hoepman JH, Katzenbeisser S (eds) ICT Systems security and privacy protection, Springer International Publishing, Cham. pp 211\u2013226","DOI":"10.1007\/978-3-319-33630-5_15"},{"key":"9944_CR29","doi-asserted-by":"publisher","unstructured":"Li Z, Zou D, Xu S, Jin H, Qi H, Hu J (2016b) Vulpecker: An automated vulnerability detection system based on code similarity analysis. In: Proceedings of the 32nd Annual conference on computer security applications, association for computing machinery, New York, NY, USA, ACSAC \u201916, pp 201\u2013213. https:\/\/doi.org\/10.1145\/2991079.2991102","DOI":"10.1145\/2991079.2991102"},{"issue":"7","key":"9944_CR30","doi-asserted-by":"publisher","first-page":"3289","DOI":"10.1109\/TII.2018.2821768","volume":"14","author":"G Lin","year":"2018","unstructured":"Lin G, Zhang J, Luo W, Pan L, Xiang Y, De Vel O, Montague P (2018) Cross-project transfer representation learning for vulnerable function discovery. IEEE Trans Industr Inform 14(7):3289\u20133297. https:\/\/doi.org\/10.1109\/TII.2018.2821768","journal-title":"IEEE Trans Industr Inform"},{"key":"9944_CR31","unstructured":"Livshits V B, Lam M S (2005) Finding security vulnerabilities in java applications with static analysis. In: Proceedings of the 14th Conference on USENIX security symposium - Volume 14, USENIX Association, USA, SSYM\u201905, p 18"},{"key":"9944_CR32","doi-asserted-by":"publisher","unstructured":"\u015aliwerski J, Zimmermann T, Zeller A (2005) When do changes induce fixes?. In: Proceedings of the 2005 International workshop on mining software repositories, association for computing machinery, New York, NY, USA, MSR \u201905. p 1\u20135. https:\/\/doi.org\/10.1145\/1083142.1083147","DOI":"10.1145\/1083142.1083147"},{"key":"9944_CR33","doi-asserted-by":"publisher","unstructured":"Martin M, Livshits B, Lam M S (2005) Finding application errors and security flaws using pql: A program query language. In: Proceedings of the 20th Annual ACM SIGPLAN conference on object-oriented programming, systems, languages, and applications, association for computing machinery, New York, NY, USA, OOPSLA \u201905, pp 365\u2013383. https:\/\/doi.org\/10.1145\/1094811.1094840","DOI":"10.1145\/1094811.1094840"},{"issue":"4","key":"9944_CR34","doi-asserted-by":"publisher","first-page":"308","DOI":"10.1109\/TSE.1976.233837","volume":"SE-2","author":"TJ McCabe","year":"1976","unstructured":"McCabe TJ (1976) A complexity measure. IEEE Trans Softw Eng SE-2(4):308\u2013320. https:\/\/doi.org\/10.1109\/TSE.1976.233837","journal-title":"IEEE Trans Softw Eng"},{"key":"9944_CR35","doi-asserted-by":"publisher","unstructured":"Medeiros I, Neves N, Correia M (2016) Dekant: A static analysis tool that learns to detect web application vulnerabilities. In: Proceedings of the 25th International symposium on software testing and analysis, association for computing machinery, New York, NY, USA, ISSTA. https:\/\/doi.org\/10.1145\/2931037.2931041, vol 2016, pp 1\u201311","DOI":"10.1145\/2931037.2931041"},{"key":"9944_CR36","doi-asserted-by":"publisher","unstructured":"Meneely A, Srinivasan H, Musa A, Tejeda AR, Mokary M, Spates B (2013) When a patch goes bad: Exploring the properties of vulnerability-contributing commits. In: 2013 ACM \/ IEEE International symposium on empirical software engineering and measurement. pp 65\u201374. https:\/\/doi.org\/10.1109\/ESEM.2013.19","DOI":"10.1109\/ESEM.2013.19"},{"issue":"5","key":"9944_CR37","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1016\/S1361-3723(13)70045-9","volume":"2013","author":"S Moshtari","year":"2013","unstructured":"Moshtari S, Sami A, Azimi M (2013) Using complexity metrics to improve software security. Comput Fraud Secur 2013(5):8\u201317","journal-title":"Comput Fraud Secur"},{"key":"9944_CR38","doi-asserted-by":"publisher","unstructured":"Neuhaus S, Zimmermann T, Holler C, Zeller A (2007) Predicting vulnerable software components. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, Association for Computing Machinery, New York, NY, USA, CCS \u201907, pp 529\u2013540. https:\/\/doi.org\/10.1145\/1315245.1315311","DOI":"10.1145\/1315245.1315311"},{"key":"9944_CR39","doi-asserted-by":"publisher","unstructured":"Padhye R, Lemieux C, Sen K (2019) Jqf: coverage-guided property-based testing in java. pp 398\u2013401. https:\/\/doi.org\/10.1145\/3293882.3339002","DOI":"10.1145\/3293882.3339002"},{"key":"9944_CR40","doi-asserted-by":"publisher","unstructured":"Perl H, Dechand S, Smith M, Arp D, Yamaguchi F, Rieck K, Fahl S, Acar Y (2015) Vccfinder: Finding potential vulnerabilities in open-source projects to assist code audits. In: Proceedings of the 22nd ACM SIGSAC Conference on computer and communications security, association for computing machinery, New York, NY, USA, CCS \u201915, pp 426\u2013437. https:\/\/doi.org\/10.1145\/2810103.2813604","DOI":"10.1145\/2810103.2813604"},{"issue":"1","key":"9944_CR41","first-page":"3247","volume":"13","author":"K Rieck","year":"2012","unstructured":"Rieck K, Wressnegger C, Bikadorov A (2012) Sally: A tool for embedding strings in vector spaces. J Mach Learn Res 13(1):3247\u20133251","journal-title":"J Mach Learn Res"},{"key":"9944_CR42","doi-asserted-by":"publisher","unstructured":"Sabetta A, Bezzi M (2018) A practical approach to the automatic classification of security-relevant commits. In: 2018 IEEE International conference on software maintenance and evolution (ICSME). pp 579\u2013582,. https:\/\/doi.org\/10.1109\/ICSME.2018.00058","DOI":"10.1109\/ICSME.2018.00058"},{"key":"9944_CR43","unstructured":"Sawadogo AD, Bissyand\u00e9 TF, Moha N, Allix K, Klein J, Li L, Le Traon Y (2020) Learning to catch security patches. arXiv:2001.09148"},{"issue":"10","key":"9944_CR44","doi-asserted-by":"publisher","first-page":"993","DOI":"10.1109\/TSE.2014.2340398","volume":"40","author":"R Scandariato","year":"2014","unstructured":"Scandariato R, Walden J, Hovsepyan A, Joosen W (2014) Predicting vulnerable software components via text mining. IEEE Trans. Softw. Eng. 40(10):993\u20131006. https:\/\/doi.org\/10.1109\/TSE.2014.2340398","journal-title":"IEEE Trans. Softw. Eng."},{"key":"9944_CR45","doi-asserted-by":"crossref","unstructured":"Shin Y, Williams L (2011) An initial study on the use of execution complexity metrics as indicators of software vulnerabilities. In: Proceedings of the 7th International workshop on software engineering for secure systems, pp 1\u20137","DOI":"10.1145\/1988630.1988632"},{"key":"9944_CR46","doi-asserted-by":"publisher","unstructured":"Signoles J, Cuoq P, Kirchner F, Kosmatov N, Prevosto V, Yakobowski B (2012) Frama-c: a software analysis perspective, vol 27. https:\/\/doi.org\/10.1007\/s00165-014-0326-7","DOI":"10.1007\/s00165-014-0326-7"},{"key":"9944_CR47","unstructured":"Torvalds L, Triplett J, Li C, Oostenryck LV (2003) Sparse - a semantic parser for c. https:\/\/sparse.wiki.kernel.org\/index.php\/Main_Page accessed january 2020"},{"key":"9944_CR48","volume-title":"The nature of statistical learning theory","author":"V Vapnik","year":"2013","unstructured":"Vapnik V (2013) The nature of statistical learning theory. Springer science & business media, New York"},{"key":"9944_CR49","unstructured":"Wan L (2019) Automated vulnerability detection system based on commit messages. PhD thesis"},{"key":"9944_CR50","doi-asserted-by":"publisher","unstructured":"Wang S, Chollak D, Movshovitz-Attias D, Tan L (2016) Bugram: Bug detection with n-gram language models. In: Proceedings of the 31st IEEE\/ACM International conference on automated software engineering, association for computing machinery, New York, NY, USA, ASE 2016, pp 708\u2013719. https:\/\/doi.org\/10.1145\/2970276.2970341","DOI":"10.1145\/2970276.2970341"},{"key":"9944_CR51","unstructured":"Wheeler DA (2001) Flawfinder. https:\/\/dwheeler.com\/flawfinder\/, accessed April 2020"},{"key":"9944_CR52","doi-asserted-by":"publisher","unstructured":"Wijayasekara D, Manic M, Wright JL, McQueen M (2012) Mining bug databases for unidentified software vulnerabilities. In: 2012 5th International conference on human system interactions. pp 89\u201396. https:\/\/doi.org\/10.1109\/HSI.2012.22","DOI":"10.1109\/HSI.2012.22"},{"key":"9944_CR53","doi-asserted-by":"publisher","unstructured":"Wijayasekara D, Manic M, McQueen M (2014) Vulnerability identification and classification via text mining bug databases. In: IECON 2014 - 40th Annual Conference of the IEEE Industrial Electronics Society, pp 3612\u20133618. https:\/\/doi.org\/10.1109\/IECON.2014.7049035","DOI":"10.1109\/IECON.2014.7049035"},{"key":"9944_CR54","doi-asserted-by":"publisher","unstructured":"Yamaguchi F, Wressnegger C, Gascon H, Rieck K (2013) Chucky: Exposing missing checks in source code for vulnerability discovery. In: Proceedings of the 2013 ACM SIGSAC Conference on computer & communications security, association for computing machinery, New York, NY, USA, CCS \u201913, pp 499\u2013510. https:\/\/doi.org\/10.1145\/2508859.2516665","DOI":"10.1145\/2508859.2516665"},{"key":"9944_CR55","doi-asserted-by":"publisher","unstructured":"Yamaguchi F, Golde N, Arp D, Rieck K (2014) Modeling and discovering vulnerabilities with code property graphs. https:\/\/doi.org\/10.1109\/SP.2014.44","DOI":"10.1109\/SP.2014.44"},{"key":"9944_CR56","doi-asserted-by":"publisher","unstructured":"Yamamoto K (2018) Vulnerability detection in source code based on git history. https:\/\/doi.org\/10.13140\/RG.2.2.28338.09922. (Unpublished)","DOI":"10.13140\/RG.2.2.28338.09922"},{"key":"9944_CR57","doi-asserted-by":"publisher","unstructured":"Yang L, Li X, Yu Y (2017) Vuldigger: A just-in-time and cost-aware tool for digging vulnerability-contributing changes. In: GLOBECOM 2017 - 2017 IEEE Global communications conference, pp 1\u20137. https:\/\/doi.org\/10.1109\/GLOCOM.2017.8254428","DOI":"10.1109\/GLOCOM.2017.8254428"},{"key":"9944_CR58","unstructured":"Zalewski M (2017) American fuzzy lop. http:\/\/lcamtuf.coredump.cx\/afl\/"},{"key":"9944_CR59","unstructured":"Zhang T, Oles F (2000) The value of unlabeled data for classification problems"},{"key":"9944_CR60","doi-asserted-by":"publisher","unstructured":"Zhou Y, Sharma A (2017) Automated identification of security issues from commit messages and bug reports. In: Proceedings of the 2017 11th Joint meeting on foundations of software engineering, association for computing machinery, New York, NY, USA ESEC\/FSE 2017, pp 914\u2013919. https:\/\/doi.org\/10.1145\/3106237.3117771","DOI":"10.1145\/3106237.3117771"},{"key":"9944_CR61","doi-asserted-by":"crossref","unstructured":"Zhu X, Feng X, Jiao T, Wen S, Xiang Y, Camtepe S, Xue J (2019) A feature-oriented corpus for understanding, evaluating and improving fuzz testing, pp 658\u2013663","DOI":"10.1145\/3321705.3329845"},{"key":"9944_CR62","doi-asserted-by":"publisher","unstructured":"Zimmermann T, Nagappan N, Williams L (2010) Searching for a needle in a haystack: Predicting security vulnerabilities for windows vista. In: 2010 Third international conference on software testing, verification and validation, pp 421\u2013428. https:\/\/doi.org\/10.1109\/ICST.2010.32","DOI":"10.1109\/ICST.2010.32"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-021-09944-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-021-09944-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-021-09944-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,25]],"date-time":"2021-04-25T07:51:57Z","timestamp":1619337117000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-021-09944-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3,29]]},"references-count":62,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2021,5]]}},"alternative-id":["9944"],"URL":"https:\/\/doi.org\/10.1007\/s10664-021-09944-w","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,3,29]]},"assertion":[{"value":"22 January 2021","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 March 2021","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"46"}}