{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T12:21:46Z","timestamp":1783513306536,"version":"3.55.0"},"reference-count":39,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T00:00:00Z","timestamp":1779667200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T00:00:00Z","timestamp":1779667200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Software Qual J"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1007\/s11219-026-09760-9","type":"journal-article","created":{"date-parts":[[2026,5,25]],"date-time":"2026-05-25T20:42:08Z","timestamp":1779741728000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["PPTSP: patch presence test via semantic normalization and key path extraction"],"prefix":"10.1007","volume":"34","author":[{"given":"Chengke","family":"Xu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Senlin","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xueming","family":"Duan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Limin","family":"Pan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,25]]},"reference":[{"key":"9760_CR27","unstructured":"2023 Overview - OpenAI API. https:\/\/platform.openai.com"},{"key":"9760_CR20","doi-asserted-by":"publisher","unstructured":"Altinay, A., Nash, J., Kroes, T., Rajasekaran, P., Zhou, D., Dabrowski, A., ... & Franz, M. (2020). BinRec: dynamic binary lifting and recompilation. In Proceedings of the Fifteenth European Conference on Computer Systems (Heraklion, Greece) (EuroSys \u201920). Association for Computing Machinery, New York, NY, USA. 36:16. https:\/\/doi.org\/10.1145\/3342195.3387550","DOI":"10.1145\/3342195.3387550"},{"key":"9760_CR37","doi-asserted-by":"publisher","first-page":"107786","DOI":"10.1016\/j.infsof.2025.107786","volume":"185","author":"G Bhandari","year":"2025","unstructured":"Bhandari, G., Gavric, N., & Shalaginov, A. (2025). Generating vulnerability security fixes with code language models. Information and Software Technology, 185, 107786.","journal-title":"Information and Software Technology"},{"key":"9760_CR5","doi-asserted-by":"crossref","unstructured":"Bourquin, M., King, A., & Robbins, E. (2013). BinSlayer: Accurate Comparison of Binary Executables. In Proceedings of the 2nd ACM SIGPLAN Program Protection and Reverse Engineering Workshop (PPREW\u201913) (Rome, Italy). ACM, New York, NY, USA. 4:10.","DOI":"10.1145\/2430553.2430557"},{"key":"9760_CR11","doi-asserted-by":"crossref","unstructured":"Chen, H. (2013). The influences of compiler optimization on binary files similarity detection. In 2013 the International Conference on Education Technology and Information System (ICETIS 2013). Atlantis Press, 971\u2013975.","DOI":"10.2991\/icetis-13.2013.221"},{"key":"9760_CR6","doi-asserted-by":"publisher","unstructured":"David, Y., & Yahav, E. (2014). Tracelet-Based Code Search in Executables. In Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation (Edinburgh, United Kingdom) (PLDI \u201914). Association for Computing Machinery, New York, NY, USA, 349\u2013360. https:\/\/doi.org\/10.1145\/2594291.2594343","DOI":"10.1145\/2594291.2594343"},{"key":"9760_CR36","doi-asserted-by":"publisher","first-page":"106771","DOI":"10.1016\/j.infsof.2021.106771","volume":"144","author":"N Dissanayake","year":"2022","unstructured":"Dissanayake, N., et al. (2022). Software security patch management-A systematic literature review of challenges, approaches, tools and practices. Information and Software Technology, 144, 106771.","journal-title":"Information and Software Technology"},{"key":"9760_CR25","doi-asserted-by":"crossref","unstructured":"Feng, Q. (2016). Scalable graph-based bug search for firmware images. Proceedings of the 2016 ACM SIGSAC conference on computer and communications security.","DOI":"10.1145\/2976749.2978370"},{"key":"9760_CR3","unstructured":"Gautam Altekar, I., & Bagrak, P. B. (2005). and Andrew Schultz. OPUS: Online Patches and Updates for Security. In Proceedings of the 14th Conference on USENIX Security Symposium - Volume 14 (Baltimore, MD) (SSYM\u201905). USENIX Association, USA, 19."},{"issue":"3","key":"9760_CR14","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3446371","volume":"54","author":"IU Haq","year":"2021","unstructured":"Haq, I. U., & Caballero, J. (2021). A survey of binary code similarity. ACM Computing Surveys (CSUR), 54(3), 1\u201338.","journal-title":"ACM Computing surveys (CSUR)"},{"key":"9760_CR9","doi-asserted-by":"crossref","unstructured":"Jiang, Z., Zhang, Y., Xu, J., Wen, Q., Wang, Z., Zhang, X., Xing, X., & Yang, M., Yang, Z. (2020). Pdiff: Semantic-based patch presence detection for downstream kernels. In Proceedings of the 2020 ACMSIGSAC Conference on Computer and Communications Security. 1149\u20131163.","DOI":"10.1145\/3372297.3417240"},{"key":"9760_CR28","doi-asserted-by":"publisher","first-page":"22199","DOI":"10.52202\/068431-1613","volume":"35","author":"T Kojima","year":"2022","unstructured":"Kojima, T., et al. (2022). Large language models are zero-shot reasoners. Advances in Neural Information Processing Systems, 35, 22199\u201322213.","journal-title":"Advances in neural information processing systems"},{"key":"9760_CR7","doi-asserted-by":"publisher","unstructured":"Li, F., & Paxson, V. (2017). A large-seale empirical study of security patches. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (Dallas, Texas, USA) (CCS \u201817). Association for Computing Machinery, New York, NY,USA,2201\u20132215. https:\/\/doi.org\/10.1145\/3133956.3134072","DOI":"10.1145\/3133956.3134072"},{"issue":"2","key":"9760_CR1","doi-asserted-by":"publisher","first-page":"1397","DOI":"10.1109\/COMST.2018","volume":"20","author":"L De Liu","year":"2018","unstructured":"Liu, L., De Vel, O., Han, Q. L., Zhang, J., & Xiang, Y. (2018). Detecting and preventing cyber insider threats: A survey. IEEE Communications Surveys & Tutorials, 20(2), 1397\u20131417. https:\/\/doi.org\/10.1109\/COMST.2018","journal-title":"IEEE Communications Surveys &amp; Tutorials"},{"key":"9760_CR32","doi-asserted-by":"crossref","unstructured":"Li, Z., Zou, D., Xu, S., Jin, H., Qi, H., & Hu, J. (2016). VulPecker: An automated vulnerability detection system based on code similarity analysis, in Proc. 32nd Annu. Conf. Comput. Secur. Appl., pp. 201\u2013213.","DOI":"10.1145\/2991079.2991102"},{"key":"9760_CR38","unstructured":"National Vulnerability Database (2018). CVE-2018-0735. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-0735"},{"key":"9760_CR40","unstructured":"National Vulnerability Database (2021). CVE-2021-3537. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-3537"},{"key":"9760_CR39","unstructured":"National Vulnerability Database (2021). CVE-2021-38171. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-38171"},{"key":"9760_CR24","unstructured":"National Vulnerability Database (2022). CVE-2022-3786. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-3786"},{"key":"9760_CR23","unstructured":"National Vulnerability Database (2023). CVE-2023-0465. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-0465"},{"key":"9760_CR2","unstructured":"National Vulnerability Database (2025). CVE: Vulnerabilities By Year. Retrieved May 15, 2025 from https:\/\/www.cvedetails.com\/browse-by-date.php"},{"issue":"6","key":"9760_CR21","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1145\/1273442.1250746","volume":"42","author":"N Nethercote","year":"2007","unstructured":"Nethercote, N., & Seward, J. (2007). Valgrind: a framework for heavyweight dynamic binary instrumentation. ACM Sigplan Notices, 42(6), 89\u2013100.","journal-title":"ACM Sigplan notices"},{"key":"9760_CR29","doi-asserted-by":"publisher","first-page":"27730","DOI":"10.52202\/068431-2011","volume":"35","author":"L Ouyang","year":"2022","unstructured":"Ouyang, L., et al. (2022). Training language models to follow instructions with human feedback. Advances in Neural Information Processing Systems, 35, 27730\u201327744.","journal-title":"Advances in neural information processing systems"},{"key":"9760_CR30","doi-asserted-by":"publisher","unstructured":"Pan, Z. (2024). Ppt4j: Patch presence test for java binaries. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE \u201924). Association for Computing Machinery, New York, NY, USA. 225:12. https:\/\/doi.org\/10.1145\/3597503.3639231","DOI":"10.1145\/3597503.3639231"},{"key":"9760_CR33","doi-asserted-by":"crossref","unstructured":"Peng, J. (2019). 1dVul: Discovering 1-day vulnerabilities through binary patches, in Proc. 49th Annu. IEEE\/IFIP Int. Conf. Dependable Syst. Netw. (DSN), Piscataway, NJ, USA: IEEE Press, pp. 605\u2013616.","DOI":"10.1109\/DSN.2019.00066"},{"key":"9760_CR17","doi-asserted-by":"crossref","unstructured":"Pewny, J. (2014). Leveraging semantic signatures for bug search in binary programs. Proceedings of the 30th Annual Computer Security Applications Conference.","DOI":"10.1145\/2664243.2664269"},{"key":"9760_CR4","doi-asserted-by":"publisher","unstructured":"Qi, Z., Hu, X., Li, Z., Xia, X., Lo, D., Li, S. (2024). PS3: Precise Patch presence test based on Semantic Symbolic Signature. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering (ICSE \u201924). Association for Computing Machinery, New York, NY, USA. 167:12. https:\/\/doi.org\/10.1145\/3597503.3639134","DOI":"10.1145\/3597503.3639134"},{"key":"9760_CR19","unstructured":"Rays, H. (2025). IDA Pro. https:\/\/www.hex-rays.com\/products\/ida\/"},{"key":"9760_CR13","doi-asserted-by":"publisher","first-page":"95","DOI":"10.1016\/j.comcom.2021.03.011","volume":"173","author":"P Sun","year":"2021","unstructured":"Sun, P., et al. (2021). Osprey: A fast and accurate patch presence test framework for binaries. Computer Communications, 173, 95\u2013106.","journal-title":"Computer Communications"},{"key":"9760_CR26","doi-asserted-by":"crossref","unstructured":"Tian, Y., Lawall, J., & Lo, D. (2012). Identifying linux bug fixing patches. 2012 34th international conference on software engineering (ICSE). IEEE.","DOI":"10.1109\/ICSE.2012.6227176"},{"key":"9760_CR16","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1016\/j.jpdc.2016.10.012","volume":"103","author":"F Tong","year":"2017","unstructured":"Tong, F., & Yan, Z. (2017). A hybrid approach of mobile malware detection in Android. Journal of Parallel and Distributed computing, 103, 22\u201331.","journal-title":"Journal of Parallel and Distributed computing"},{"key":"9760_CR15","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1016\/j.inffus.2021.12.006","volume":"82","author":"W Wei","year":"2022","unstructured":"Wei, W., et al. (2022). EPMDroid: Efficient and privacy-preserving malware detection based on SGX through data fusion. Information Fusion, 82, 43\u201357.","journal-title":"Information Fusion"},{"key":"9760_CR22","unstructured":"Wikiversity (2020). Backus-Naur form. https:\/\/en.wikipedia.org\/wiki\/BackusNaur_form"},{"key":"9760_CR35","doi-asserted-by":"publisher","first-page":"104181","DOI":"10.1016\/j.cose.2024.104181","volume":"148","author":"S Woo","year":"2025","unstructured":"Woo, S., Choi, E., & Lee, H. (2025). A large-scale analysis of the effectiveness of publicly reported security patches. Computers & Security, 148, 104181.","journal-title":"Computers & Security"},{"key":"9760_CR18","doi-asserted-by":"crossref","unstructured":"Xie, Z., Wen, M., Jia, H., Guo, X., Huang, X., Zou, D., & Jin, H. (2023). Precise and Efficient Patch presence test for Android Applications against Code Obfuscation. In Proceedings of the 32nd ACMSIGSOFT International Symposium on Software Testing and Analysis. 347\u2013359.","DOI":"10.1145\/3597926.3598061"},{"key":"9760_CR12","doi-asserted-by":"crossref","unstructured":"Xu, Y., Xu, Z., Chen, B., Song, F., Liu, Y., & Liu, T. (2020). Patch based vulnerability matching for binary programs. In Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis. 376\u2013387.","DOI":"10.1145\/3395363.3397361"},{"key":"9760_CR10","doi-asserted-by":"publisher","first-page":"107043","DOI":"10.1016\/j.infsof.2022.107043","volume":"152","author":"D Yan","year":"2022","unstructured":"Yan, D., et al. (2022). Crex: Predicting patch correctness in automated repair of C programs through transfer learning of execution semantics. Information and Software Technology, 152, 107043.","journal-title":"Information and Software Technology"},{"key":"9760_CR8","unstructured":"Zhang, H., & Qian, Z. (2018). Precise and Accurate Patch presence test for Binaries. In USENIX Security Symposium. 887\u2013902."},{"key":"9760_CR31","doi-asserted-by":"crossref","unstructured":"Zhan, Q. (2024). REACT: IR-Level Patch presence test for Binary. Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering.","DOI":"10.1145\/3691620.3695012"}],"container-title":["Software Quality Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-026-09760-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11219-026-09760-9","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-026-09760-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:54:19Z","timestamp":1783511659000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11219-026-09760-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,25]]},"references-count":39,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["9760"],"URL":"https:\/\/doi.org\/10.1007\/s11219-026-09760-9","relation":{},"ISSN":["0963-9314","1573-1367"],"issn-type":[{"value":"0963-9314","type":"print"},{"value":"1573-1367","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,25]]},"assertion":[{"value":"13 November 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 May 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"26"}}