{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T23:27:13Z","timestamp":1782170833067,"version":"3.54.5"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2022,8,6]],"date-time":"2022-08-06T00:00:00Z","timestamp":1659744000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,8,6]],"date-time":"2022-08-06T00:00:00Z","timestamp":1659744000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100013249","name":"Institut des Sciences Math\u00e9matiques, Universit\u00e9 du Qu\u00e9bec \u00e0 Montr\u00e9al","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100013249","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2022,11]]},"DOI":"10.1007\/s10664-022-10168-9","type":"journal-article","created":{"date-parts":[[2022,8,6]],"date-time":"2022-08-06T07:14:24Z","timestamp":1659770064000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["SSPCatcher: Learning to catch security patches"],"prefix":"10.1007","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0592-788X","authenticated-orcid":false,"given":"Arthur D.","family":"Sawadogo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tegawend\u00e9 F.","family":"Bissyand\u00e9","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Naouel","family":"Moha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kevin","family":"Allix","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jacques","family":"Klein","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Li","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yves","family":"Le Traon","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,8,6]]},"reference":[{"key":"10168_CR1","doi-asserted-by":"crossref","unstructured":"Allix K, Bissyand\u00e9 T F, Klein J, Le Traon Y (2015) Are your training datasets yet relevant?. In: International Symposium on Engineering Secure Software and Systems. Springer, pp 51\u201367","DOI":"10.1007\/978-3-319-15618-7_5"},{"key":"10168_CR2","volume-title":"Software change impact analysis","author":"RS Arnold","year":"1996","unstructured":"Arnold R S (1996) Software change impact analysis. IEEE Computer Society Press, California"},{"key":"10168_CR3","unstructured":"Berr J (2017) \u201cwannacry\u201d ransomware attack losses could reach $4 billion. https:\/\/www.cbsnews.com\/news\/wannacry-ransomware-attacks-wannacry-virus-losses\/, Available: August 2018"},{"key":"10168_CR4","doi-asserted-by":"crossref","unstructured":"Bissyande T F, Thung F, Wang S, Lo D, Jiang L, Reveillere L (2013) Empirical evaluation of bug linking. In: Software Maintenance and Reengineering (CSMR), 2013 17th European Conference on. IEEE, pp 89\u201398","DOI":"10.1109\/CSMR.2013.19"},{"key":"10168_CR5","doi-asserted-by":"crossref","unstructured":"Blum A, Mitchell T (1998) Combining labeled and unlabeled data with co-training. In: Proceedings of the eleventh annual conference on Computational learning theory. ACM, pp 92\u2013100","DOI":"10.1145\/279943.279962"},{"key":"10168_CR6","doi-asserted-by":"crossref","unstructured":"Brooks T N (2017) Survey of automated vulnerability detection and exploit generation techniques in cyber reasoning systems. arXiv preprint arXiv:1702.06162","DOI":"10.1007\/978-3-030-01177-2_79"},{"key":"10168_CR7","unstructured":"Cadar C, Dunbar D, Engler D R, et al. (2008) Klee: Unassisted and automatic generation of high-coverage tests for complex systems programs.. In: OSDI, vol 8, pp 209\u2013224"},{"key":"10168_CR8","doi-asserted-by":"crossref","unstructured":"Cha S K, Avgerinos T, Rebert A, Brumley D (2012) Unleashing mayhem on binary code. In: Security and Privacy (SP), 2012 IEEE Symposium on. IEEE, pp 380\u2013394","DOI":"10.1109\/SP.2012.31"},{"issue":"5","key":"10168_CR9","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1109\/TSE.2008.24","volume":"34","author":"R-Y Chang","year":"2008","unstructured":"Chang R-Y, Podgurski A, Yang J (2008) Discovering neglected conditions in software by mining dependence graphs. IEEE Trans Softw Eng 34 (5):579\u2013596","journal-title":"IEEE Trans Softw Eng"},{"key":"10168_CR10","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1613\/jair.953","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla N V, Bowyer K W, Hall L O, Kegelmeyer W P (2002) Smote: synthetic minority over-sampling technique. Journal of artificial intelligence research 16:321\u2013357","journal-title":"Journal of artificial intelligence research"},{"key":"10168_CR11","doi-asserted-by":"crossref","unstructured":"Chowdhury I, Chan B, Zulkernine M (2008) Security metrics for source code structures. In: Proceedings of the fourth international workshop on Software engineering for secure systems. ACM, pp 57\u201364","DOI":"10.1145\/1370905.1370913"},{"key":"10168_CR12","doi-asserted-by":"crossref","unstructured":"Du X, Chen B, Li Y, Guo J, Zhou Y, Liu Y, Jiang Y (2019) Leopard: Identifying vulnerable code for vulnerability assessment through program metrics. 2019 IEEE\/ACM 41st International Conference on Software Engineering (ICSE), 60\u201371","DOI":"10.1109\/ICSE.2019.00024"},{"key":"10168_CR13","unstructured":"Godefroid P, Levin M Y, Molnar D A, et al. (2008) Automated whitebox fuzz testing.. In: NDSS, vol 8, pp 151\u2013166"},{"key":"10168_CR14","doi-asserted-by":"crossref","unstructured":"Hempstalk K, Frank E (2008) Discriminating against new classes: One-class versus multi-class classification. In: Australasian Joint Conference on Artificial Intelligence. Springer, pp 325\u2013336","DOI":"10.1007\/978-3-540-89378-3_32"},{"key":"10168_CR15","doi-asserted-by":"crossref","unstructured":"Hoang T, Lawall J, Oentaryo R J, Tian Y, Lo D (2018) Patchnet: A tool for deep patch classification. In: Tool Demonstrations of International Conference on Software Engineering","DOI":"10.1109\/ICSE-Companion.2019.00044"},{"issue":"3","key":"10168_CR16","doi-asserted-by":"publisher","first-page":"137","DOI":"10.4236\/jsea.2009.23020","volume":"2","author":"G Jay","year":"2009","unstructured":"Jay G, Hale J E, Smith R K, Hale D P, Kraft N A, Ward C (2009) Cyclomatic complexity and lines of code: Empirical evidence of a stable linear relationship. JSEA 2(3):137\u2013143","journal-title":"JSEA"},{"key":"10168_CR17","doi-asserted-by":"crossref","unstructured":"Ji T, Wu Y, Wang C, Zhang X, Wang Z (2018) The coming era of alphahacking?: A survey of automatic software vulnerability detection, exploitation and patching techniques. In: 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC). IEEE","DOI":"10.1109\/DSC.2018.00017"},{"key":"10168_CR18","doi-asserted-by":"crossref","unstructured":"Jimenez M, Le Traon Y, Papadakis M (2018) Enabling the continous analysis of security vulnerabilities with vuldata7. In: IEEE International Working Conference on Source Code Analysis and Manipulation","DOI":"10.1109\/SCAM.2018.00014"},{"key":"10168_CR19","unstructured":"Knight W (2017) The dark secret at the heart of ai. MIT Technology Review https:\/\/www.technologyreview.com\/s\/604087\/the-dark-secret-at-the-heart-of-ai\/"},{"key":"10168_CR20","doi-asserted-by":"crossref","unstructured":"Koyuncu A, Bissyand\u00e9 T F, Kim D, Klein J, Monperrus M, Le Traon Y (2017) Impact of tool support in patch construction. In: Proceedings of the 26th ACM SIGSOFT International Symposium on Software Testing and Analysis. ACM, pp 237\u2013248","DOI":"10.1145\/3092703.3092713"},{"issue":"1-2","key":"10168_CR21","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1023\/B:MACH.0000035472.73496.0c","volume":"57","author":"M-A Krogel","year":"2004","unstructured":"Krogel M-A, Scheffer T (2004) Multi-relational learning, text mining, and semi-supervised learning for functional genomics. Mach Learn 57(1-2):61\u201381","journal-title":"Mach Learn"},{"issue":"8","key":"10168_CR22","doi-asserted-by":"publisher","first-page":"613","DOI":"10.1002\/stvr.1475","volume":"23","author":"B Li","year":"2013","unstructured":"Li B, Sun X, Leung H, Zhang S (2013) A survey of code-based change impact analysis techniques. Softw Test Verification Reliab 23(8):613\u2013646","journal-title":"Softw Test Verification Reliab"},{"key":"10168_CR23","doi-asserted-by":"crossref","unstructured":"Li L, Bartel A, Bissyand\u00e9 T F, Klein J, Le Traon Y, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel P (2015) Iccta: Detecting inter-component privacy leaks in android apps. In: Proceedings of the 37th International Conference on Software Engineering-Volume 1. IEEE Press, pp 280\u2013291","DOI":"10.1109\/ICSE.2015.48"},{"key":"10168_CR24","unstructured":"Li X, Liu B (2003) Learning to classify text using positive and unlabeled data. In: IJCAI. ACM, pp 587\u2013 592"},{"key":"10168_CR25","doi-asserted-by":"crossref","unstructured":"Li Z, Zou D, Xu S, Ou X, Jin H, Wang S, Deng Z, Zhong Y (2018) Vuldeepecker: A deep learning-based system for vulnerability detection. arXiv:1801.01681","DOI":"10.14722\/ndss.2018.23158"},{"key":"10168_CR26","doi-asserted-by":"crossref","unstructured":"Mann H B, Whitney D R (1947) On a test of whether one of two random variables is stochastically larger than the other. The annals of mathematical statistics, pp. 50\u201360","DOI":"10.1214\/aoms\/1177730491"},{"key":"10168_CR27","unstructured":"Newsome J, Song D X (2005) Dynamic taint analysis for automatic detection, analysis, and signaturegeneration of exploits on commodity software. In: NDSS, vol 5. Citeseer, pp 3\u20134"},{"key":"10168_CR28","doi-asserted-by":"crossref","unstructured":"Nguyen A T, Nguyen T T, Nguyen H A, Nguyen T N (2012) Multi-layered approach for recovering links between bug reports and fixes. In: Proceedings of the ACM SIGSOFT 20th International Symposium on the Foundations of Software Engineering. ACM, p 63","DOI":"10.1145\/2393596.2393671"},{"key":"10168_CR29","doi-asserted-by":"crossref","unstructured":"Nigam K, Ghani R (2000) Analyzing the effectiveness and applicability of co-training. In: Proceedings of the ninth international conference on Information and knowledge management. ACM, pp 86\u201393","DOI":"10.1145\/354756.354805"},{"key":"10168_CR30","unstructured":"NIST (2018) National vulnerability database. https:\/\/nvd.nist.gov"},{"key":"10168_CR31","doi-asserted-by":"crossref","unstructured":"Perl H, Dechand S, Smith M, Arp D, Yamaguchi F, Rieck K, Fahl S, Acar Y (2015) Vccfinder: Finding potential vulnerabilities in open-source projects to assist code audits. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. ACM, pp 426\u2013437","DOI":"10.1145\/2810103.2813604"},{"key":"10168_CR32","doi-asserted-by":"crossref","unstructured":"Ponta S E, Plate H, Sabetta A, Bezzi M, Dangremont C (2019) A manually-curated dataset of fixes to vulnerabilities of open-source software. arXiv preprint arXiv:1902.02595","DOI":"10.1109\/MSR.2019.00064"},{"key":"10168_CR33","unstructured":"Pontin J (2018) Greedy, brittle, opaque, and shallow: The downsides to deep learning. https:\/\/www.wired.com\/story\/greedy-brittle-opaque-and-shallow-the-downsides-to-deep-learning\/"},{"issue":"3","key":"10168_CR34","doi-asserted-by":"publisher","first-page":"130","DOI":"10.1108\/eb046814","volume":"14","author":"MF Porter","year":"1980","unstructured":"Porter M F (1980) An algorithm for suffix stripping. Program 14 (3):130\u2013137","journal-title":"Program"},{"key":"10168_CR35","unstructured":"Reis S, Abreu R (2017) SECBENCH: A database of real security vulnerabilities. In: Jaatun M G, Cruzes D S (eds) Proceedings of the International Workshop on Secure Software Engineering in DevOps and Agile Development co-located with the 22nd European Symposium on Research in Computer Security (ESORICS 2017), Oslo, Norway, September 14, 2017. CEUR Workshop Proceedings, vol 1977, CEUR-WS.org, pp 69\u201385"},{"key":"10168_CR36","doi-asserted-by":"crossref","unstructured":"Ribeiro M T, Singh S, Guestrin C (2016) Why should i trust you?: Explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining. ACM, pp 1135\u20131144","DOI":"10.1145\/2939672.2939778"},{"key":"10168_CR37","doi-asserted-by":"crossref","unstructured":"Sabetta A, Bezzi M (2018) A practical approach to the automatic classification of security-relevant commits. In: 34th IEEE International Conference on Software Maintenance and Evolution (ICSME)","DOI":"10.1109\/ICSME.2018.00058"},{"issue":"10","key":"10168_CR38","doi-asserted-by":"publisher","first-page":"993","DOI":"10.1109\/TSE.2014.2340398","volume":"40","author":"R Scandariato","year":"2014","unstructured":"Scandariato R, Walden J, Hovsepyan A, Joosen W (2014) Predicting vulnerable software components via text mining. IEEE Trans Softw Eng 40(10):993\u20131006","journal-title":"IEEE Trans Softw Eng"},{"key":"10168_CR39","unstructured":"Snyk.io (2017) The state of open-source security. https:\/\/snyk.io\/stateofossecurity\/pdf\/The%20State%20of%20Open%20Source.pdf, Available: August 2018"},{"key":"10168_CR40","volume-title":"Fuzzing: brute force vulnerability discovery","author":"M Sutton","year":"2007","unstructured":"Sutton M, Greene A, Amini P (2007) Fuzzing: brute force vulnerability discovery. Pearson Education, California"},{"key":"10168_CR41","doi-asserted-by":"crossref","unstructured":"Szekeres L, Payer M, Wei T, Song D (2013) Sok: Eternal war in memory. In: Security and Privacy (SP), 2013 IEEE Symposium on. IEEE, pp 48\u201362","DOI":"10.1109\/SP.2013.13"},{"key":"10168_CR42","doi-asserted-by":"crossref","unstructured":"Tian Y, Lawall J, Lo D (2012) Identifying linux bug fixing patches. In: Proceedings of the 34th International Conference on Software Engineering. IEEE Press, pp 386\u2013396","DOI":"10.1109\/ICSE.2012.6227176"},{"key":"10168_CR43","unstructured":"Trend Micro (2017) Patching problems and how to solve them. https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/vulnerabilities-and-exploits\/patching-problems-and-how-to-solve-them, Available: August 2018"},{"key":"10168_CR44","unstructured":"van Rossum G (2008) Origin of bdfl. All Things Pythonic Weblogs. http:\/\/www.artima.com\/weblogs\/viewpost.jsp"},{"key":"10168_CR45","volume-title":"The nature of statistical learning theory","author":"V Vapnik","year":"2013","unstructured":"Vapnik V (2013) The nature of statistical learning theory. Springer, New York"},{"key":"10168_CR46","doi-asserted-by":"crossref","unstructured":"Wu R, Zhang H, Kim S, Cheung S-C (2011) Relink: recovering links between bugs and changes. In: Proceedings of the 19th ACM SIGSOFT symposium and the 13th European conference on Foundations of software engineering. ACM, pp 15\u201325","DOI":"10.1145\/2025113.2025120"},{"key":"10168_CR47","unstructured":"Xiao Y, Chen B, Yu C, Xu Z, Yuan Z, Li F, Liu B, Liu Y, Huo W, Zou W, Shi W (2020) Mvp: Detecting vulnerabilities using patch-enhanced vulnerability signatures. In: USENIX Security Symposium"},{"key":"10168_CR48","doi-asserted-by":"crossref","unstructured":"Yamaguchi F, Golde N, Arp D, Rieck K (2014) Modeling and discovering vulnerabilities with code property graphs. In: 2014 IEEE Symposium on Security and Privacy, pp 590\u2013604","DOI":"10.1109\/SP.2014.44"},{"key":"10168_CR49","doi-asserted-by":"crossref","unstructured":"Yamaguchi F, Golde N, Arp D, Rieck K (2014) Modeling and discovering vulnerabilities with code property graphs. In: Security and Privacy (SP), 2014 IEEE Symposium on. IEEE, pp 590\u2013604","DOI":"10.1109\/SP.2014.44"},{"key":"10168_CR50","doi-asserted-by":"crossref","unstructured":"Yamaguchi F, Wressnegger C, Gascon H, Rieck K (2013) Chucky: Exposing missing checks in source code for vulnerability discovery. In: Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security. ACM, pp 499\u2013510","DOI":"10.1145\/2508859.2516665"},{"issue":"9","key":"10168_CR51","doi-asserted-by":"publisher","first-page":"574","DOI":"10.1109\/TSE.2004.52","volume":"30","author":"AnnieTT Ying","year":"2004","unstructured":"Ying Annie TT, Murphy G C, Ng R, Chu-Carroll M C (2004) Predicting source code changes by mining change history. IEEE Trans Softw Eng 30 (9):574\u2013586","journal-title":"IEEE Trans Softw Eng"},{"key":"10168_CR52","unstructured":"Zhou Y, Liu S, Siow J, Du X, Liu Y (2019) Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In: NeurIPS"},{"key":"10168_CR53","doi-asserted-by":"crossref","unstructured":"Zhou Y, Sharma A (2017) Automated identification of security issues from commit messages and bug reports. In: Proceedings of the 2017 11th Joint Meeting on Foundations of Software Engineering. ACM, pp 914\u2013919","DOI":"10.1145\/3106237.3117771"},{"key":"10168_CR54","doi-asserted-by":"crossref","unstructured":"Zimmermann T, Nagappan N, Williams L (2010) Searching for a needle in a haystack: Predicting security vulnerabilities for windows vista. In: Software Testing, Verification and Validation (ICST), 2010 Third International Conference on. IEEE, pp 421\u2013428","DOI":"10.1109\/ICST.2010.32"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10168-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-022-10168-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-022-10168-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,14]],"date-time":"2022-10-14T12:12:06Z","timestamp":1665749526000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-022-10168-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,8,6]]},"references-count":54,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2022,11]]}},"alternative-id":["10168"],"URL":"https:\/\/doi.org\/10.1007\/s10664-022-10168-9","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,8,6]]},"assertion":[{"value":"17 March 2022","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 August 2022","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"151"}}