{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T23:49:47Z","timestamp":1773013787164,"version":"3.50.1"},"reference-count":66,"publisher":"Institution of Engineering and Technology (IET)","issue":"1","license":[{"start":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:00:00Z","timestamp":1760140800000},"content-version":"vor","delay-in-days":283,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/doi.wiley.com\/10.1002\/tdm_license_1.1"}],"funder":[{"DOI":"10.13039\/100014440","name":"Ministerio de Ciencia, Innovaci\u00f3n y Universidades","doi-asserted-by":"publisher","award":["PID2023-150310OB-I00"],"award-info":[{"award-number":["PID2023-150310OB-I00"]}],"id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100011033","name":"Agencia Estatal de Investigaci\u00f3n","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100011033","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008530","name":"European Regional Development Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008530","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001665","name":"Agence Nationale de la Recherche","doi-asserted-by":"publisher","award":["NF-HiSec ANR-22-PEFT-0009"],"award-info":[{"award-number":["NF-HiSec ANR-22-PEFT-0009"]}],"id":[{"id":"10.13039\/501100001665","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100023561","name":"Ministerio de Universidades","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100023561","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["ietresearch.onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["IET Information Security"],"published-print":{"date-parts":[[2025,1]]},"abstract":"<jats:p>\n                    The complexity of implementations and the interconnection of assorted systems and devices facilitate the emergence of vulnerabilities. Detection systems are developed to fight against this security issue, being the use of artificial intelligence (AI) a common practice. However, the use of AI is not without its problems, especially those affecting the training phase. This article tackles this issue by characterizing the resilience against poisoning attacks using a benchmark for vulnerability detection, extracting simple code features while applying traditional AI algorithms. These choices are beneficial for the fast processing of vulnerabilities required in a triage process. The study is carried out in C#, C\/C++, and PHP. Results show that the vulnerability detection process is specially affected beyond 20% of false data. Remarkably, detecting some of the most frequent common weakness enumeration (CWE) is altered even with lower poison rates. Overall,\n                    <jats:italic>K<\/jats:italic>\n                    \u2010nearest\u2010neighbor (KNN) and support vector machine (SVM) are the most resilient in C# and C\/C++, while multilayer perceptron (MLP) in PHP. Indeed, vulnerability detection in PHP is less affected by attacks, while C# and C\/C++ present comparable results.\n                  <\/jats:p>","DOI":"10.1049\/ise2\/9997989","type":"journal-article","created":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:55:22Z","timestamp":1760176522000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["On the Resilience of Traditional AI Algorithms Toward Poisoning Attacks for Vulnerability Detection"],"prefix":"10.1049","volume":"2025","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3490-621X","authenticated-orcid":false,"given":"Lorena","family":"Gonz\u00e1lez-Manzano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joaquin","family":"Garcia-Alfaro","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"265","published-online":{"date-parts":[[2025,10,11]]},"reference":[{"key":"e_1_2_15_1_2","doi-asserted-by":"crossref","unstructured":"HuangY. XuF. ZhouH. ChenX. ZhouX. andWangT. Towards Exploring the Code Reuse From Stack Overflow During Software Development Proceedings of the 30th IEEE\/ACM International Conference on Program Comprehension 2022 IEEE 548\u2013559.","DOI":"10.1145\/3524610.3527923"},{"key":"e_1_2_15_2_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-021-09976-0"},{"key":"e_1_2_15_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3487890"},{"key":"e_1_2_15_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3585385"},{"key":"e_1_2_15_5_2","first-page":"1721","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Mozaffari H.","year":"2023"},{"key":"e_1_2_15_6_2","doi-asserted-by":"crossref","unstructured":"ChernisB.andVermaR. Machine Learning Methods for Software Vulnerability Detection Proceedings of the Fourth ACM International Workshop on Security and Privacy Analytics 2018 Association for Computing Machinery 31\u201339.","DOI":"10.1145\/3180445.3180453"},{"key":"e_1_2_15_7_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2022.111283"},{"key":"e_1_2_15_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-023-10346-3"},{"key":"e_1_2_15_9_2","volume-title":"31st USENIX Security Symposium, Security 2022","author":"Mirsky Y.","year":"2023"},{"key":"e_1_2_15_10_2","first-page":"1559","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Schuster R.","year":"2021"},{"key":"e_1_2_15_11_2","doi-asserted-by":"crossref","unstructured":"SunW. ChenY. andTaoG. et al.Backdooring Neural Code Search Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (ACL 2023) 2023 Association for Computational Linguistics 9692\u20139708.","DOI":"10.18653\/v1\/2023.acl-long.540"},{"key":"e_1_2_15_12_2","doi-asserted-by":"crossref","unstructured":"AghakhaniH. DaiW. andManoelA. et al.Trojanpuzzle: Covertly Poisoning Code-Suggestion Models 2024 IEEE Symposium on Security and Privacy (SP) 2024 IEEE 1122\u20131140.","DOI":"10.1109\/SP54263.2024.00140"},{"key":"e_1_2_15_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3630008"},{"key":"e_1_2_15_14_2","unstructured":"XuH. Thesis: Environment Poisoning in Reinforcement Learning: Attacks and Resilience 2023."},{"key":"e_1_2_15_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3551636"},{"key":"e_1_2_15_16_2","unstructured":"TranB. LiJ. andMadryA. Spectral Signatures in Backdoor Attacks 31 Advances in Neural Information Processing Systems 2018 Curran Associates Inc.."},{"key":"e_1_2_15_17_2","unstructured":"ChenB. CarvalhoW. andBaracaldoN. et al.Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering 2018 arXiv preprint arXiv: 1811.03728."},{"key":"e_1_2_15_18_2","first-page":"1487","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Severi G.","year":"2021"},{"key":"e_1_2_15_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2988557"},{"key":"e_1_2_15_20_2","doi-asserted-by":"crossref","unstructured":"WuY. ZouD. DouS. YangW. XuD. andJinH. VulCNN: An Image-Inspired Scalable Vulnerability Detection System Proceedings of the 44th International Conference on Software Engineering 2022 Pittsburgh PA USA IEEE 2365\u20132376.","DOI":"10.1145\/3510003.3510229"},{"key":"e_1_2_15_21_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111623"},{"key":"e_1_2_15_22_2","doi-asserted-by":"crossref","unstructured":"ChenY. DingZ. AlowainL. ChenX. andWagnerD. Diversevul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection 2023 [Online]. Available:https:\/\/github.com\/wagner-group\/diversevul.","DOI":"10.1145\/3607199.3607242"},{"key":"e_1_2_15_23_2","doi-asserted-by":"crossref","unstructured":"HanifH.andMaffeisS. Vulberta: Simplified Source Code Pre-Training for Vulnerability Detection 2022 International Joint Conference on Neural Networks (IJCNN) 2022 IEEE 1\u20138.","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"key":"e_1_2_15_24_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106809"},{"key":"e_1_2_15_25_2","doi-asserted-by":"crossref","unstructured":"FidalgoA. MedeirosI. AntunesP. andNevesN. Towards a Deep Learning Model for Vulnerability Detection on Web Application Variants 2020 IEEE International Conference on Software Testing Verification and Validation Workshops (ICSTW) 2020 IEEE 465\u2013476.","DOI":"10.1109\/ICSTW50294.2020.00083"},{"key":"e_1_2_15_26_2","doi-asserted-by":"crossref","unstructured":"LiZ. ZouD. andXuS. et al.\u03bcVulDeePecker: A Deep Learning-Based System for Vulnerability Detection Network and Distributed System Security (NDSS) Symposium 2018 IEEE 2224\u20132236.","DOI":"10.14722\/ndss.2018.23158"},{"key":"e_1_2_15_27_2","doi-asserted-by":"crossref","unstructured":"LiY. WangS. andNguyenT. N. Vulnerability Detection With Finegrained Interpretations Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering 2021 Association for Computing Machinery 292\u2013303.","DOI":"10.1145\/3468264.3468597"},{"key":"e_1_2_15_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2024.3361661"},{"key":"e_1_2_15_29_2","doi-asserted-by":"crossref","unstructured":"HenkelJ. RamakrishnanG. WangZ. AlbarghouthiA. JhaS. andRepsT. Semantic Robustness of Models of Source Code 2022 IEEE International Conference on Software Analysis Evolution and Reengineering (SANER) 2022 IEEE 526\u2013537.","DOI":"10.1109\/SANER53432.2022.00070"},{"key":"e_1_2_15_30_2","doi-asserted-by":"crossref","unstructured":"WanY. ZhangS. andZhangH. et al.You See What i Want You to See: Poisoning Vulnerabilities in Neural Code Search Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering 2022 Association for Computing Machinery 1233\u20131245.","DOI":"10.1145\/3540250.3549153"},{"key":"e_1_2_15_31_2","unstructured":"QiS. YangY. GaoS. GaoC. andXuZ. Badcs: A Backdoor Attack Framework for Code Search 2023 arXiv preprint arXiv: 2305.05503."},{"key":"e_1_2_15_32_2","doi-asserted-by":"crossref","unstructured":"LiY. LiuS. ChenK. XieX. ZhangT. andLiuY. Multi-Target Backdoor Attacks for Code Pre-Trained Models Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics 2023 Association for Computational Linguistics.","DOI":"10.18653\/v1\/2023.acl-long.399"},{"key":"e_1_2_15_33_2","doi-asserted-by":"crossref","unstructured":"RamakrishnanG.andAlbarghouthiA. Backdoors in Neural Models of Source Code 2022 26th International Conference on Pattern Recognition (ICPR) 2022 IEEE 2892\u20132899.","DOI":"10.1109\/ICPR56361.2022.9956690"},{"key":"e_1_2_15_34_2","doi-asserted-by":"crossref","unstructured":"SunZ. DuX. SongF. NiM. andLiL. Coprotector: Protect Opensource Code Against Unauthorized Training Usage With Data Poisoning Proceedings of the ACM Web Conference 2022 2022 Association for Computing Machinery 652\u2013660.","DOI":"10.1145\/3485447.3512225"},{"key":"e_1_2_15_35_2","doi-asserted-by":"publisher","DOI":"10.1002\/smr.2571"},{"key":"e_1_2_15_36_2","doi-asserted-by":"crossref","unstructured":"CotroneoD. ImprotaC. LiguoriP. andNatellaR. Vulnerabilities in AI Code Generators: Exploring Targeted Data Poisoning Attacks Proceedings of the 32nd IEEE\/ACM International Conference on Program Comprehension 2024 Association for Computing Machinery 280\u2013292.","DOI":"10.1145\/3643916.3644416"},{"key":"e_1_2_15_37_2","doi-asserted-by":"crossref","unstructured":"ShinY.andWilliamsL. An Empirical Model to Predict Security Vulnerabilities Using Code Complexity Metrics Proceedings of the Second ACM-IEEE International Symposium on Empirical Software Engineering and Measurement 2008 Association for Computing Machinery 315\u2013317.","DOI":"10.1145\/1414004.1414065"},{"key":"e_1_2_15_38_2","first-page":"111","article-title":"Performance Analysis of Various Activation Functions in Generalized Mlp Architectures of Neural Networks","volume":"1","author":"Karlik B.","year":"2011","journal-title":"International Journal of Artificial Intelligence and Expert Systems"},{"key":"e_1_2_15_39_2","doi-asserted-by":"crossref","unstructured":"GuptaA. ParmarR. SuriP. andKumarR. Determining Accuracy Rate of Artificial Intelligence Models Using Python and R-Studio 2021 3rd International Conference on Advances in Computing Communication Control and Networking (ICAC3N) 2021 IEEE 889\u2013894.","DOI":"10.1109\/ICAC3N53548.2021.9725687"},{"key":"e_1_2_15_40_2","doi-asserted-by":"crossref","unstructured":"AlibrahimH.andLudwigS. A. Hyperparameter Optimization: Comparing Genetic Algorithm Against Grid Search and Bayesian Optimization 2021 IEEE Congress on Evolutionary Computation (CEC) 2021 IEEE 1551\u20131559.","DOI":"10.1109\/CEC45853.2021.9504761"},{"key":"e_1_2_15_41_2","doi-asserted-by":"publisher","DOI":"10.1504\/IJAPR.2016.079733"},{"key":"e_1_2_15_42_2","doi-asserted-by":"crossref","unstructured":"CharikarM. GuruswamiV. KumarR. RajagopalanS. andSahaiA. Combinatorial Feature Selection Problems Proceedings 41st Annual Symposium on Foundations of Computer Science 2000 IEEE 631\u2013640.","DOI":"10.1109\/SFCS.2000.892331"},{"key":"e_1_2_15_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10126-5"},{"key":"e_1_2_15_44_2","doi-asserted-by":"crossref","unstructured":"RomanoS. TorielloG. CassieriP. FranceseR. andScannielloG. A Folklore Confirmation on the Removal of Dead Code Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering 2024 Association for Computing Machinery 333\u2013338.","DOI":"10.1145\/3661167.3661188"},{"key":"e_1_2_15_45_2","unstructured":"BlackP. E. Sard: A Software Assurance Reference Dataset 2017 [Online]. Available:https:\/\/samate.nist.gov\/SARD."},{"key":"e_1_2_15_46_2","unstructured":"ChenB. CarvalhoW. andBaracaldoN. et al.Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering SafeAI Workshop 20192019."},{"key":"e_1_2_15_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2023.3267848"},{"key":"e_1_2_15_48_2","unstructured":"TranB. LiJ. andMadryA. Spectral Signatures in Backdoor Attacks Advances in Neural Information Processing Systems (NeurIPS) 2018 Curran Associates Inc. 8011\u20138021."},{"key":"e_1_2_15_49_2","unstructured":"SahaS. ZhangT. andOthers Check Your Other Door! Creating Backdoor Attacks in the Frequency Domain 2021 arXiv preprint arXiv: 2109.05507."},{"key":"e_1_2_15_50_2","doi-asserted-by":"publisher","DOI":"10.1002\/sam.11583"},{"key":"e_1_2_15_51_2","doi-asserted-by":"crossref","unstructured":"VirvilisN.andGritzalisD. The Big Four-What we did Wrong in Advanced Persistent Threat Detection? 2013 International Conference on Availability Reliability and Security 2013 IEEE 248\u2013254.","DOI":"10.1109\/ARES.2013.32"},{"key":"e_1_2_15_52_2","doi-asserted-by":"crossref","unstructured":"CarliniN. JagielskiM. andChoquette-ChooC. A. et al.Poisoning Webscale Training Datasets is Practical 2024 IEEE Symposium on Security and Privacy (SP) 2024 IEEE 407\u2013425.","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_2_15_53_2","unstructured":"BiggioB. NelsonB. andLaskovP. Poisoning Attacks Against Support Vector Machines Proceedings of the 29th International Coference on International Conference on Machine Learning (ICML\u201912) 2012 Omnipress 1467\u20131474."},{"key":"e_1_2_15_54_2","unstructured":"ChenX. LiuC. LiB. LuK. andSongD. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning 2017 arXiv preprint arXiv: 1712.05526."},{"key":"e_1_2_15_55_2","first-page":"1","volume-title":"Wiley Statsref: Statistics Reference Online","author":"Anderson M. J.","year":"2014"},{"key":"e_1_2_15_56_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.mlwa.2024.100598"},{"key":"e_1_2_15_57_2","doi-asserted-by":"crossref","unstructured":"MahyariA. A. Harnessing the Power of LLMs in Source Code Vulnerability Detection MILCOM 2024-2024 IEEE Military Communications Conference (MILCOM) 2024 IEEE 251\u2013256.","DOI":"10.1109\/MILCOM61039.2024.10774025"},{"key":"e_1_2_15_58_2","doi-asserted-by":"crossref","unstructured":"JensenR. I. T. TawosiV. andAlamirS. Software Vulnerability and Functionality Assessment Using Llms 2024 IEEE\/ACM International Workshop on Natural Language-Based Software Engineering (NLBSE) 2024 IEEE 25\u201328.","DOI":"10.1145\/3643787.3648036"},{"key":"e_1_2_15_59_2","volume-title":"T\u00edtulo del Libro","author":"Shamoo Y.","year":"2024"},{"key":"e_1_2_15_60_2","unstructured":"AlamM. T. HalderR. andMaitiA. Detection Made Easy: Potentials of Large Language Models for Solidity Vulnerabilities 2024 arXiv preprint arXiv: 2409.10574."},{"key":"e_1_2_15_61_2","unstructured":"ShengZ. ChenZ. GuS. HuangH. GuG. andHuangJ. Llms in Software Security: A Survey of Vulnerability Detection Techniques and Insights 2025 arXiv e-prints pp. arXiv\u20132502."},{"key":"e_1_2_15_62_2","unstructured":"CortesC. MohriM. andRostamizadehA. L2Regularization for Learning Kernels Proceedings of the Twenty-Fifth Conference on Uncertainty in Artificial Intelligence (UAI2009) 2012 AUAI Press 109\u2013116."},{"key":"e_1_2_15_63_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-31150-6_13"},{"key":"e_1_2_15_64_2","doi-asserted-by":"publisher","DOI":"10.4304\/jcp.6.5.833-840"},{"key":"e_1_2_15_65_2","doi-asserted-by":"crossref","unstructured":"Gonz\u00e1lez-ManzanoL.andGarcia-AlfaroJ. Vulnerability Detection Under Poisoning Attacks Through Code and Token Features 2024 (Preprint)https:\/\/www.researchsquare.com\/article\/rs-4355876\/v1.","DOI":"10.21203\/rs.3.rs-4355876\/v1"},{"key":"e_1_2_15_66_2","volume-title":"Permanova+ for Primer: Guide to Software and Statistical Methods","author":"Anderson M.","year":"2008"}],"container-title":["IET Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/9997989","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/full-xml\/10.1049\/ise2\/9997989","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/ise2\/9997989","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T22:34:49Z","timestamp":1773009289000},"score":1,"resource":{"primary":{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/10.1049\/ise2\/9997989"}},"subtitle":[],"editor":[{"given":"Naghmeh","family":"Moradpoor","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2025,1]]},"references-count":66,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["10.1049\/ise2\/9997989"],"URL":"https:\/\/doi.org\/10.1049\/ise2\/9997989","archive":["Portico"],"relation":{},"ISSN":["1751-8709","1751-8717"],"issn-type":[{"value":"1751-8709","type":"print"},{"value":"1751-8717","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1]]},"assertion":[{"value":"2024-08-10","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-21","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-10-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"9997989"}}