{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T03:05:15Z","timestamp":1785899115495,"version":"3.56.0"},"reference-count":222,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2022,12,3]],"date-time":"2022-12-03T00:00:00Z","timestamp":1670025600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Cyber Security Research Centre Limited"},{"name":"Australian Government\u2019s Cooperative Research Centres Programme"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2023,5,31]]},"abstract":"<jats:p>Software Vulnerabilities (SVs) are increasing in complexity and scale, posing great security risks to many software systems. Given the limited resources in practice, SV assessment and prioritization help practitioners devise optimal SV mitigation plans based on various SV characteristics. The surges in SV data sources and data-driven techniques such as Machine Learning and Deep Learning have taken SV assessment and prioritization to the next level. Our survey provides a taxonomy of the past research efforts and highlights the best practices for data-driven SV assessment and prioritization. We also discuss the current limitations and propose potential solutions to address such issues.<\/jats:p>","DOI":"10.1145\/3529757","type":"journal-article","created":{"date-parts":[[2022,4,19]],"date-time":"2022-04-19T12:44:24Z","timestamp":1650372264000},"page":"1-39","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":89,"title":["A Survey on Data-driven Software Vulnerability Assessment and Prioritization"],"prefix":"10.1145","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1935-037X","authenticated-orcid":false,"given":"Triet H. M.","family":"Le","sequence":"first","affiliation":[{"name":"CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5678-472X","authenticated-orcid":false,"given":"Huaming","family":"Chen","sequence":"additional","affiliation":[{"name":"CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9696-3626","authenticated-orcid":false,"given":"M. Ali","family":"Babar","sequence":"additional","affiliation":[{"name":"CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide Adelaide, Australia and Cyber Security Cooperative Research Centre, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,3]]},"reference":[{"key":"e_1_3_2_2_2","article-title":"ThreatZoom: CVE2CWE using hierarchical neural network","author":"Aghaei Ehsan","year":"2020","unstructured":"Ehsan Aghaei, Waseem Shadid, and Ehab Al-Shaer. 2020. ThreatZoom: CVE2CWE using hierarchical neural network. arXiv preprint arXiv:2009.11501 (2020).","journal-title":"arXiv preprint arXiv:2009.11501"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2017.02.021"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176339"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3393822.3432335"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CYCONUS.2017.8167501"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-98842-9_4"},{"key":"e_1_3_2_8_2","article-title":"Cleaning the NVD: Comprehensive quality assessment, improvements, and analyses","author":"Anwar Afsah","year":"2020","unstructured":"Afsah Anwar, Ahmed Abusnaina, Songqing Chen, Frank Li, and David Mohaisen. 2020. Cleaning the NVD: Comprehensive quality assessment, improvements, and analyses. arXiv preprint arXiv:2006.15074 (2020).","journal-title":"arXiv preprint arXiv:2006.15074"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC50000.2020.9219568"},{"key":"e_1_3_2_10_2","article-title":"Neural machine translation by jointly learning to align and translate","author":"Bahdanau Dzmitry","year":"2014","unstructured":"Dzmitry Bahdanau, Kyunghyun Cho, and Yoshua Bengio. 2014. Neural machine translation by jointly learning to align and translate. arXiv preprint arXiv:1409.0473 (2014).","journal-title":"arXiv preprint arXiv:1409.0473"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41060-017-0091-9"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23318-5_6"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/504909.504911"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1002\/qre.2754"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3058067"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467159"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.5555\/2981562.2981578"},{"key":"e_1_3_2_18_2","first-page":"993","article-title":"Latent Dirichlet allocation","volume":"3","author":"Blei David M.","year":"2003","unstructured":"David M. Blei, Andrew Y. Ng, and Michael I. Jordan. 2003. Latent Dirichlet allocation. J. Mach. Learn. Res. 3, Jan (2003), 993\u20131022.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00051"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635880"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835821"},{"key":"e_1_3_2_22_2","unstructured":"Broadcom. [n. d.]. Symantec attack signatures. Retrieved from https:\/\/bit.ly\/symantec_att_sign."},{"key":"e_1_3_2_23_2","unstructured":"Broadcom. [n. d.]. Symantec threat explorer. Retrieved from https:\/\/bit.ly\/symantec_threats."},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3041008.3041009"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00076"},{"key":"e_1_3_2_26_2","unstructured":"CERT. [n. d.]. Basic fuzzing framework. Retrieved from https:\/\/bit.ly\/basic_fuzzing_framework."},{"key":"e_1_3_2_27_2","unstructured":"Sang Kil Cha. [n. d.]. OFuzz. Retrieved from https:\/\/github.com\/sangkilc\/ofuzz."},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.31"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2013.11.024"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2019.00110"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/937"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330742"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2020.110616"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2016.09.009"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387461"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxp040"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"e_1_3_2_39_2","unstructured":"Koby Crammer Ofer Dekel Joseph Keshet Shai Shalev-Shwartz and Yoram Singer. 2006. Online passive aggressive algorithms. (2006)."},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2011.01.004"},{"key":"e_1_3_2_41_2","article-title":"V2W-BERT: A framework for effective hierarchical multiclass classification of software vulnerabilities","author":"Das Siddhartha Shankar","year":"2021","unstructured":"Siddhartha Shankar Das, Edoardo Serra, Mahantesh Halappanavar, Alex Pothen, and Ehab Al-Shaer. 2021. V2W-BERT: A framework for effective hierarchical multiclass classification of software vulnerabilities. arXiv preprint arXiv:2102.11498 (2021).","journal-title":"arXiv preprint arXiv:2102.11498"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2019.07.002"},{"key":"e_1_3_2_43_2","article-title":"Evaluating the performance of Twitter-based exploit detectors","author":"Sousa Daniel Alves de","year":"2020","unstructured":"Daniel Alves de Sousa, Elaine Ribeiro de Faria, and Rodrigo Sanches Miani. 2020. Evaluating the performance of Twitter-based exploit detectors. arXiv preprint arXiv:2011.03113 (2020).","journal-title":"arXiv preprint arXiv:2011.03113"},{"key":"e_1_3_2_44_2","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. BERT: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018).","journal-title":"arXiv preprint arXiv:1810.04805"},{"key":"e_1_3_2_45_2","article-title":"Software security patch management\u2014a systematic literature review of challenges, approaches, tools and practices","author":"Dissanayake Nesara","year":"2020","unstructured":"Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, and M. Ali Babar. 2020. Software security patch management\u2014a systematic literature review of challenges, approaches, tools and practices. arXiv preprint arXiv:2012.00544 (2020).","journal-title":"arXiv preprint arXiv:2012.00544"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.15"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.5555\/3361338.3361399"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC53464.2021.00016"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/648"},{"key":"e_1_3_2_50_2","first-page":"123e30","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Dzeroski Saso","year":"2002","unstructured":"Saso Dzeroski and Bernard Zenko. 2002. Is combining classifiers better than selecting the best one? In Proceedings of the International Conference on Machine Learning. Citeseer, 123e30."},{"key":"e_1_3_2_51_2","volume-title":"Predicting Exploit Likelihood for Cyber Vulnerabilities with Machine Learning","author":"Edkrantz Michel","year":"2015","unstructured":"Michel Edkrantz. 2015. Predicting Exploit Likelihood for Cyber Vulnerabilities with Machine Learning. Master\u2019s thesis."},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSCloud.2015.56"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407038"},{"key":"e_1_3_2_54_2","unstructured":"ESET. [n. d.]. ESET security advisories. Retrieved from https:\/\/bit.ly\/eset_virus."},{"key":"e_1_3_2_55_2","first-page":"1","article-title":"Systematic literature review to investigate the application of open source intelligence (OSINT) with artificial intelligence","author":"Evangelista Jo\u00e3o Rafael Gon\u00e7alves","year":"2020","unstructured":"Jo\u00e3o Rafael Gon\u00e7alves Evangelista, Renato Jos\u00e9 Sassi, M\u00e1rcio Romero, and Domingos Napolitano. 2020. Systematic literature review to investigate the application of open source intelligence (OSINT) with artificial intelligence. J. Appl. Secur. Res. (2020), 1\u201325.","journal-title":"J. Appl. Secur. Res."},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0228439"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.3115\/1219840.1219885"},{"key":"e_1_3_2_58_2","unstructured":"FIRST. [n. d.]. Common Vulnerability Scoring System. Retrieved from https:\/\/www.first.org\/cvss."},{"key":"e_1_3_2_59_2","unstructured":"FIRST. [n. d.]. CVSS version 2. Retrieved from https:\/\/www.first.org\/cvss\/v2\/guide."},{"key":"e_1_3_2_60_2","unstructured":"FIRST. [n. d.]. CVSS version 3. Retrieved from https:\/\/www.first.org\/cvss\/v3.0\/specification-document."},{"key":"e_1_3_2_61_2","unstructured":"FIRST. [n. d.]. CVSS version 3.1. Retrieved from https:\/\/www.first.org\/cvss\/v3.1\/specification-document."},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1201\/9780429289651"},{"key":"e_1_3_2_63_2","unstructured":"Wikimedia Foundation. [n. d.]. Wikipedia pages. Retrieved from https:\/\/www.wikipedia.org."},{"key":"e_1_3_2_64_2","unstructured":"Recorded Future. [n. d.]. Recorded Future security advisories. Retrieved from https:\/\/bit.ly\/rf_sec."},{"key":"e_1_3_2_65_2","first-page":"3","volume-title":"Proceedings of the International Conference on Risks and Security of Internet and Systems","author":"Gawron Marian","year":"2017","unstructured":"Marian Gawron, Feng Cheng, and Christoph Meinel. 2017. Automatic vulnerability classification using machine learning. In Proceedings of the International Conference on Risks and Security of Internet and Systems. Springer, 3\u201317."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2010.5463340"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092566"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS.2019.00011"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2019.00023"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.5555\/3086952"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857720"},{"key":"e_1_3_2_72_2","article-title":"Predicting missing information of key aspects in vulnerability reports","author":"Guo Hao","year":"2020","unstructured":"Hao Guo, Zhenchang Xing, and Xiaohong Li. 2020. Predicting missing information of key aspects in vulnerability reports. arXiv preprint arXiv:2008.02456 (2020).","journal-title":"arXiv preprint arXiv:2008.02456"},{"issue":"4","key":"e_1_3_2_73_2","first-page":"83","article-title":"Data mining concepts and techniques third edition","volume":"5","author":"Han Jiawei","year":"2011","unstructured":"Jiawei Han, Micheline Kamber, and Jian Pei. 2011. Data mining concepts and techniques third edition. Morg. Kauf. Series Data Manag. Syst. 5, 4 (2011), 83\u2013124.","journal-title":"Morg. Kauf. Series Data Manag. Syst."},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1145\/335191.335372"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330232"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2017.52"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-84858-7"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_79_2","article-title":"Automated mapping of vulnerability advisories onto their fix commits in open source repositories","author":"Hommersom Daan","year":"2021","unstructured":"Daan Hommersom, Antonino Sabetta, Bonaventura Coppola, and Damian A. Tamburri. 2021. Automated mapping of vulnerability advisories onto their fix commits in open source repositories. arXiv preprint arXiv:2103.13375 (2021).","journal-title":"arXiv preprint arXiv:2103.13375"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3350546.3352519"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1145\/77606.77608"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2900462"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/3320269.3405435"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00019"},{"key":"e_1_3_2_85_2","unstructured":"SecurityFocus Inc. [n. d.]. BugTraq vulnerability database. Retrieved from http:\/\/www.securityfocus.com."},{"key":"e_1_3_2_86_2","unstructured":"Secunia Inc.[n. d.]. Secunia vulnerability advisories. Retrieved from http:\/\/secunia.com."},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyaa015"},{"key":"e_1_3_2_88_2","article-title":"Exploit prediction scoring system (EPSS)","author":"Jacobs Jay","year":"2019","unstructured":"Jay Jacobs, Sasha Romanosky, Benjamin Edwards, Michael Roytman, and Idris Adjerid. 2019. Exploit prediction scoring system (EPSS). arXiv preprint arXiv:1908.04856 (2019).","journal-title":"arXiv preprint arXiv:1908.04856"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/3433174.3433612"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1007\/s40484-016-0081-2"},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2021.841"},{"key":"e_1_3_2_92_2","first-page":"3146","article-title":"LightGBM: A highly efficient gradient boosting decision tree","volume":"30","author":"Ke Guolin","year":"2017","unstructured":"Guolin Ke, Qi Meng, Thomas Finley, Taifeng Wang, Wei Chen, Weidong Ma, Qiwei Ye, and Tie-Yan Liu. 2017. LightGBM: A highly efficient gradient boosting decision tree. Adv. Neural Inf. Process. Syst. 30 (2017), 3146\u20133154.","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"e_1_3_2_93_2","volume-title":"Guidelines for Performing Systematic Literature Reviews in Software Engineering","author":"Keele Staffs","year":"2007","unstructured":"Staffs Keele et\u00a0al. 2007. Guidelines for Performing Systematic Literature Reviews in Software Engineering. Technical Report. Technical report, Ver. 2.3 EBSE Technical Report. EBSE."},{"key":"e_1_3_2_94_2","unstructured":"Inc. Kenna Security. [n. d.]. Kenna Security. Retrieved from http:\/\/www.kennasecurity.com."},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-92624-7_1"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.3233\/IFS-151733"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1181"},{"key":"e_1_3_2_98_2","article-title":"Semi-supervised classification with graph convolutional networks","author":"Kipf Thomas N.","year":"2016","unstructured":"Thomas N. Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016).","journal-title":"arXiv preprint arXiv:1609.02907"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1093\/comnet\/cnu016"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.58325"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.array.2019.100011"},{"key":"e_1_3_2_102_2","first-page":"1","article-title":"The effect of bellwether analysis on software vulnerability severity prediction models","author":"Kudjo Patrick Kwaku","year":"2020","unstructured":"Patrick Kwaku Kudjo, Jinfu Chen, Solomon Mensah, Richard Amankwah, and Christopher Kudjo. 2020. The effect of bellwether analysis on software vulnerability severity prediction models. Softw. Qual. J. (2020), 1\u201334.","journal-title":"Softw. Qual. J."},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2019.00041"},{"key":"e_1_3_2_104_2","article-title":"Legal risks of adversarial machine learning research","author":"Kumar Ram Shankar Siva","year":"2020","unstructured":"Ram Shankar Siva Kumar, Jonathon Penney, Bruce Schneier, and Kendra Albert. 2020. Legal risks of adversarial machine learning research. arXiv preprint arXiv:2006.16179 (2020).","journal-title":"arXiv preprint arXiv:2006.16179"},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.5555\/1883472.1883474"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v29i1.9513"},{"key":"e_1_3_2_107_2","first-page":"1188","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Le Quoc","year":"2014","unstructured":"Quoc Le and Tomas Mikolov. 2014. Distributed representations of sentences and documents. In Proceedings of the International Conference on Machine Learning. PMLR, 1188\u20131196."},{"key":"e_1_3_2_108_2","article-title":"On the use of fine-grained vulnerable code statements for software vulnerability assessment models","author":"Le Triet H. M.","year":"2022","unstructured":"Triet H. M. Le and M. Ali Babar. 2022. On the use of fine-grained vulnerable code statements for software vulnerability assessment models. arXiv preprint arXiv:2203.08417 (2022).","journal-title":"arXiv preprint arXiv:2203.08417"},{"key":"e_1_3_2_109_2","unstructured":"Triet H. M. Le Huaming Chen and M. Ali Babar. [n. d.]. Supplementary materials. Retrieved from https:\/\/figshare.com\/s\/da4d238ecdf9123dc0b8."},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383458"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1145\/3463274.3463331"},{"key":"e_1_3_2_112_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387443"},{"key":"e_1_3_2_113_2","first-page":"717","volume-title":"Proceedings of the 36th IEEE\/ACM International Conference on Automated Software Engineering (ASE)","author":"Le Triet H. M.","year":"2021","unstructured":"Triet H. M. Le, David Hin, Roland Croft, and M. Ali Babar. 2021. DeepCVA: Automated commit-level vulnerability assessment with deep multi-task learning. In Proceedings of the 36th IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 717\u2013729."},{"key":"e_1_3_2_114_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2019.00063"},{"key":"e_1_3_2_115_2","volume-title":"Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering","author":"Li Yi","year":"2021","unstructured":"Yi Li, Shaohua Wang, and Tien N. Nguyen. 2021. Vulnerability detection with fine-grained interpretations. In Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering."},{"key":"e_1_3_2_116_2","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2993293"},{"key":"e_1_3_2_117_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCID.2017.24"},{"key":"e_1_3_2_118_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-34139-8_18"},{"key":"e_1_3_2_119_2","first-page":"1","volume-title":"Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering: Software Engineering in Society","author":"Liu Jiakun","year":"2020","unstructured":"Jiakun Liu, Qiao Huang, Xin Xia, Emad Shihab, David Lo, and Shanping Li. 2020. Is using deep learning frameworks free? Characterizing technical debt in deep learning frameworks. In Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering: Software Engineering in Society. 1\u201310."},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigDIA.2019.8802851"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-7234-0_41"},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"key":"e_1_3_2_123_2","doi-asserted-by":"crossref","unstructured":"Mitchell Marcus Beatrice Santorini and Mary Ann Marcinkiewicz. 1993. Building a large annotated corpus of English: The Penn Treebank. (1993).","DOI":"10.21236\/ADA273556"},{"key":"e_1_3_2_124_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC52881.2021.00034"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2013.19"},{"key":"e_1_3_2_126_2","first-page":"554","volume-title":"Proceedings of the IEEE\/ACM 15th International Conference on Mining Software Repositories (MSR)","author":"Menzies Tim","year":"2018","unstructured":"Tim Menzies, Suvodeep Majumder, Nikhila Balaji, Katie Brey, and Wei Fu. 2018. 500+ times faster than deep learning: A case study exploring faster methods for text mining stackoverflow. In Proceedings of the IEEE\/ACM 15th International Conference on Mining Software Repositories (MSR). IEEE, 554\u2013563."},{"key":"e_1_3_2_127_2","unstructured":"Trend Micro. [n. d.]. Trend Micro security advisories. Retrieved from https:\/\/bit.ly\/trend_micro_sec."},{"key":"e_1_3_2_128_2","unstructured":"Trend Micro. [n. d.]. ZeroDay Initiative security advisories. Retrieved from https:\/\/bit.ly\/zeroday_sec."},{"key":"e_1_3_2_129_2","unstructured":"Microsoft. [n. d.]. Microsoft security advisories. Retrieved from https:\/\/bit.ly\/ms_sec_advisories."},{"key":"e_1_3_2_130_2","article-title":"Distributed representations of words and phrases and their compositionality","author":"Mikolov Tomas","year":"2013","unstructured":"Tomas Mikolov, Ilya Sutskever, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013. Distributed representations of words and phrases and their compositionality. arXiv preprint arXiv:1310.4546 (2013).","journal-title":"arXiv preprint arXiv:1310.4546"},{"key":"e_1_3_2_131_2","unstructured":"MITRE. [n. d.]. Common Attack Pattern Enumeration and Classification. Retrieved from https:\/\/capec.mitre.org."},{"key":"e_1_3_2_132_2","unstructured":"MITRE. [n. d.]. Common Platform Enumeration. Retrieved from https:\/\/cpe.mitre.org."},{"key":"e_1_3_2_133_2","unstructured":"MITRE. [n. d.]. Common Vulnerabilities and Exposures. Retrieved from https:\/\/cve.mitre.org\/."},{"key":"e_1_3_2_134_2","unstructured":"MITRE. [n. d.]. Common Weakness Enumeration. Retrieved from https:\/\/cwe.mitre.org."},{"key":"e_1_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSCI49370.2019.00019"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2016.02.048"},{"key":"e_1_3_2_137_2","first-page":"657","volume-title":"Proceedings of the International Conference on Broadband and Wireless Computing, Communication and Applications","author":"Na Sarang","year":"2016","unstructured":"Sarang Na, Taeeun Kim, and Hwankuk Kim. 2016. A study on the classification of common vulnerabilities and exposures using na\u00efve Bayes. In Proceedings of the International Conference on Broadband and Wireless Computing, Communication and Applications. Springer, 657\u2013662."},{"key":"e_1_3_2_138_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2017.8257988"},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","DOI":"10.1587\/transinf.2018OFL0006"},{"key":"e_1_3_2_140_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2010.53"},{"key":"e_1_3_2_141_2","unstructured":"NIST. [n. d.]. National Vulnerability Database. Retrieved from https:\/\/nvd.nist.gov."},{"key":"e_1_3_2_142_2","unstructured":"NIST. [n. d.]. Software Assurance Reference Dataset (SARD). Retrieved from https:\/\/samate.nist.gov\/SRD."},{"key":"e_1_3_2_143_2","unstructured":"NIST. [n. d.]. Vulnerability description ontology. Retrieved from https:\/\/bit.ly\/nist_vdo."},{"key":"e_1_3_2_144_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2016.7745435"},{"key":"e_1_3_2_145_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243127.3243130"},{"key":"e_1_3_2_146_2","doi-asserted-by":"publisher","DOI":"10.1145\/2970276.2970281"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2015.78"},{"key":"e_1_3_2_148_2","doi-asserted-by":"publisher","DOI":"10.1007\/s41019-016-0019-8"},{"key":"e_1_3_2_149_2","first-page":"113","volume-title":"Proceedings of the USENIX Security Symposium","author":"Ou Xinming","year":"2005","unstructured":"Xinming Ou, Sudhakar Govindavajhala, and Andrew W. Appel. 2005. MulVAL: A logic-based network security analyzer. In Proceedings of the USENIX Security Symposium. 113\u2013128."},{"key":"e_1_3_2_150_2","unstructured":"OWASP. [n. d.]. Open Web Application Security Project. Retrieved from https:\/\/bit.ly\/owasp_main."},{"key":"e_1_3_2_151_2","article-title":"Evaluation metrics for unsupervised learning algorithms","author":"Palacio-Ni\u00f1o Julio-Omar","year":"2019","unstructured":"Julio-Omar Palacio-Ni\u00f1o and Fernando Berzal. 2019. Evaluation metrics for unsupervised learning algorithms. arXiv preprint arXiv:1905.05667 (2019).","journal-title":"arXiv preprint arXiv:1905.05667"},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2009.191"},{"key":"e_1_3_2_153_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2965257"},{"key":"e_1_3_2_154_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2017.2787653"},{"key":"e_1_3_2_155_2","article-title":"Deep contextualized word representations","author":"Peters Matthew E.","year":"2018","unstructured":"Matthew E. Peters, Mark Neumann, Mohit Iyyer, Matt Gardner, Christopher Clark, Kenton Lee, and Luke Zettlemoyer. 2018. Deep contextualized word representations. arXiv preprint arXiv:1802.05365 (2018).","journal-title":"arXiv preprint arXiv:1802.05365"},{"key":"e_1_3_2_156_2","unstructured":"Openwall Project. [n. d.]. Openwall security advisories. Retrieved from https:\/\/bit.ly\/sec_openwall."},{"key":"e_1_3_2_157_2","unstructured":"Rapid7. [n. d.]. Metasploit security advisories. Retrieved from https:\/\/www.rapid7.com\/db\/modules."},{"key":"e_1_3_2_158_2","article-title":"Model evaluation, model selection, and algorithm selection in machine learning","author":"Raschka Sebastian","year":"2018","unstructured":"Sebastian Raschka. 2018. Model evaluation, model selection, and algorithm selection in machine learning. arXiv preprint arXiv:1811.12808 (2018).","journal-title":"arXiv preprint arXiv:1811.12808"},{"key":"e_1_3_2_159_2","article-title":"Sentence-BERT: Sentence embeddings using siamese BERT-networks","author":"Reimers Nils","year":"2019","unstructured":"Nils Reimers and Iryna Gurevych. 2019. Sentence-BERT: Sentence embeddings using siamese BERT-networks. arXiv preprint arXiv:1908.10084 (2019).","journal-title":"arXiv preprint arXiv:1908.10084"},{"key":"e_1_3_2_160_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"e_1_3_2_161_2","doi-asserted-by":"publisher","DOI":"10.1109\/DEXA.2017.35"},{"key":"e_1_3_2_162_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-99133-7_22"},{"key":"e_1_3_2_163_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_3_2_164_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2019.06.001"},{"key":"e_1_3_2_165_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442181"},{"key":"e_1_3_2_166_2","first-page":"1041","volume-title":"Proceedings of the 24th USENIX Security Symposium","author":"Sabottke Carl","year":"2015","unstructured":"Carl Sabottke, Octavian Suciu, and Tudor Dumitra\u015f. 2015. Vulnerability disclosure in the age of social media: Exploiting Twitter for predicting real-world exploits. In Proceedings of the 24th USENIX Security Symposium. 1041\u20131056."},{"key":"e_1_3_2_167_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319008.3319033"},{"key":"e_1_3_2_168_2","article-title":"Learning to catch security patches","author":"Sawadogo Arthur D.","year":"2020","unstructured":"Arthur D. Sawadogo, Tegawend\u00e9 F. Bissyand\u00e9, Naouel Moha, Kevin Allix, Jacques Klein, Li Li, and Yves Le Traon. 2020. Learning to catch security patches. arXiv preprint arXiv:2001.09148 (2020).","journal-title":"arXiv preprint arXiv:2001.09148"},{"key":"e_1_3_2_169_2","unstructured":"Offensive Security. [n. d.]. Exploit Database. Retrieved from https:\/\/www.exploit-db.com."},{"key":"e_1_3_2_170_2","unstructured":"SecurityTracker. [n. d.]. SecurityTracker vulnerability database. Retrieved from https:\/\/securitytracker.com."},{"key":"e_1_3_2_171_2","doi-asserted-by":"publisher","DOI":"10.1049\/iet-sen.2020.0084"},{"key":"e_1_3_2_172_2","unstructured":"Internet Security Services. [n. d.]. Online database X-Force. Retrieved from http:\/\/www.iss.net\/xforce."},{"key":"e_1_3_2_173_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13198-020-01021-7"},{"key":"e_1_3_2_174_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0230250"},{"key":"e_1_3_2_175_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICInfA.2013.6720316"},{"key":"e_1_3_2_176_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-4032-5_59"},{"key":"e_1_3_2_177_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(17)30027-2"},{"key":"e_1_3_2_178_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.09.039"},{"key":"e_1_3_2_179_2","doi-asserted-by":"publisher","DOI":"10.1145\/3139367.3139390"},{"key":"e_1_3_2_180_2","doi-asserted-by":"publisher","DOI":"10.1145\/2491845.2491871"},{"key":"e_1_3_2_181_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.3044475"},{"key":"e_1_3_2_182_2","doi-asserted-by":"publisher","DOI":"10.1162\/106365602320169811"},{"key":"e_1_3_2_183_2","article-title":"Expected exploitability: Predicting the development of functional vulnerability exploits","author":"Suciu Octavian","year":"2021","unstructured":"Octavian Suciu, Connor Nelson, Zhuoer Lyu, Tiffany Bao, and Tudor Dumitras. 2021. Expected exploitability: Predicting the development of functional vulnerability exploits. arXiv preprint arXiv:2102.07869 (2021).","journal-title":"arXiv preprint arXiv:2102.07869"},{"key":"e_1_3_2_184_2","article-title":"Generating informative CVE description from ExploitDB posts by extractive summarization","author":"Sun Jiamou","year":"2021","unstructured":"Jiamou Sun, Zhenchang Xing, Hao Guo, Deheng Ye, Xiaohong Li, Xiwei Xu, and Liming Zhu. 2021. Generating informative CVE description from ExploitDB posts by extractive summarization. arXiv preprint arXiv:2101.01431 (2021).","journal-title":"arXiv preprint arXiv:2101.01431"},{"key":"e_1_3_2_185_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2885561"},{"key":"e_1_3_2_186_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11428"},{"key":"e_1_3_2_187_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-39564-7_22"},{"key":"e_1_3_2_188_2","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC.2017.30"},{"key":"e_1_3_2_189_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-019-05855-6"},{"key":"e_1_3_2_190_2","doi-asserted-by":"publisher","DOI":"10.1109\/icABCD49160.2020.9183814"},{"key":"e_1_3_2_191_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.04.002"},{"key":"e_1_3_2_192_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387465"},{"key":"e_1_3_2_193_2","article-title":"How does machine learning change software development practices?","author":"Wan Zhiyuan","year":"2019","unstructured":"Zhiyuan Wan, Xin Xia, David Lo, and Gail C. Murphy. 2019. How does machine learning change software development practices? IEEE Trans. Softw. Eng. (2019).","journal-title":"IEEE Trans. Softw. Eng."},{"key":"e_1_3_2_194_2","doi-asserted-by":"publisher","DOI":"10.1145\/1852666.1852699"},{"key":"e_1_3_2_195_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICACI.2019.8778469"},{"key":"e_1_3_2_196_2","doi-asserted-by":"publisher","DOI":"10.1145\/3386252"},{"key":"e_1_3_2_197_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_1"},{"key":"e_1_3_2_198_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00018"},{"key":"e_1_3_2_199_2","first-page":"356","volume-title":"Proceedings of the International Symposium on Foundations and Practice of Security","author":"Weerawardhana Sachini","year":"2014","unstructured":"Sachini Weerawardhana, Subhojeet Mukherjee, Indrajit Ray, and Adele Howe. 2014. Automated extraction of vulnerability information for home computer security. In Proceedings of the International Symposium on Foundations and Practice of Security. Springer, 356\u2013366."},{"issue":"5","key":"e_1_3_2_200_2","first-page":"320","article-title":"A novel automatic severity vulnerability assessment framework","volume":"10","author":"Wen Tao","year":"2015","unstructured":"Tao Wen, Yuqing Zhang, Ying Dong, and Gang Yang. 2015. A novel automatic severity vulnerability assessment framework. J. Commun. 10, 5 (2015), 320\u2013329.","journal-title":"J. Commun."},{"key":"e_1_3_2_201_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101751"},{"key":"e_1_3_2_202_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2018.8622299"},{"key":"e_1_3_2_203_2","doi-asserted-by":"publisher","DOI":"10.1016\/0169-7439(87)80084-9"},{"key":"e_1_3_2_204_2","article-title":"Data quality matters: A case study on data label correctness for security bug report prediction","author":"Wu Xiaoxue","year":"2021","unstructured":"Xiaoxue Wu, Wei Zheng, Xin Xia, and David Lo. 2021. Data quality matters: A case study on data label correctness for security bug report prediction. IEEE Trans. Softw. Eng. (2021).","journal-title":"IEEE Trans. Softw. Eng."},{"key":"e_1_3_2_205_2","first-page":"903","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918)","author":"Xiao Chaowei","year":"2018","unstructured":"Chaowei Xiao, Armin Sarabi, Yang Liu, Bo Li, Mingyan Liu, and Tudor Dumitras. 2018. From patching delays to infection symptoms: Using risk profiles for an early discovery of vulnerabilities exploited in the wild. In Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918). 903\u2013918."},{"key":"e_1_3_2_206_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-36718-3_5"},{"key":"e_1_3_2_207_2","doi-asserted-by":"publisher","DOI":"10.1109\/BADGERS.2015.018"},{"key":"e_1_3_2_208_2","doi-asserted-by":"publisher","DOI":"10.1109\/PAC.2017.10"},{"key":"e_1_3_2_209_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.106529"},{"key":"e_1_3_2_210_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00016"},{"key":"e_1_3_2_211_2","doi-asserted-by":"publisher","DOI":"10.1109\/SERE-C.2014.17"},{"key":"e_1_3_2_212_2","article-title":"Software vulnerability analysis and discovery using deep learning techniques: A survey","author":"Zeng Peng","year":"2020","unstructured":"Peng Zeng, Guanjun Lin, Lei Pan, Yonghang Tai, and Jun Zhang. 2020. Software vulnerability analysis and discovery using deep learning techniques: A survey. IEEE Access (2020).","journal-title":"IEEE Access"},{"key":"e_1_3_2_213_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606654"},{"key":"e_1_3_2_214_2","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON.2018.8650188"},{"key":"e_1_3_2_215_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3006361"},{"key":"e_1_3_2_216_2","article-title":"Character-level convolutional networks for text classification","author":"Zhang Xiang","year":"2015","unstructured":"Xiang Zhang, Junbo Zhao, and Yann LeCun. 2015. Character-level convolutional networks for text classification. arXiv preprint arXiv:1509.01626 (2015).","journal-title":"arXiv preprint arXiv:1509.01626"},{"key":"e_1_3_2_217_2","article-title":"A survey on neural network interpretability","author":"Zhang Yu","year":"2020","unstructured":"Yu Zhang, Peter Ti\u0148o, Ale\u0161 Leonardis, and Ke Tang. 2020. A survey on neural network interpretability. arXiv preprint arXiv:2012.14261 (2020).","journal-title":"arXiv preprint arXiv:2012.14261"},{"key":"e_1_3_2_218_2","article-title":"A survey on multi-task learning","author":"Zhang Yu","year":"2021","unstructured":"Yu Zhang and Qiang Yang. 2021. A survey on multi-task learning. IEEE Trans. Knowl. Data Eng. (2021).","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"e_1_3_2_219_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.11"},{"key":"e_1_3_2_220_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.63"},{"key":"e_1_3_2_221_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2942930"},{"key":"e_1_3_2_222_2","doi-asserted-by":"publisher","DOI":"10.1145\/3429444"},{"key":"e_1_3_2_223_2","unstructured":"Serkan \u00d6zkan. [n. d.]. CVE Details. Retrieved from https:\/\/www.cvedetails.com."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3529757","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3529757","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:31:24Z","timestamp":1750188684000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3529757"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,3]]},"references-count":222,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2023,5,31]]}},"alternative-id":["10.1145\/3529757"],"URL":"https:\/\/doi.org\/10.1145\/3529757","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,3]]},"assertion":[{"value":"2021-07-25","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-03-30","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}