{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T01:43:42Z","timestamp":1787017422183,"version":"3.56.0"},"reference-count":111,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T00:00:00Z","timestamp":1682467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["CCF-1453474, CNS-1513055, CNS-1513457, CNS-1513572, and CCF-1564162"],"award-info":[{"award-number":["CCF-1453474, CNS-1513055, CNS-1513457, CNS-1513572, and CCF-1564162"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,7,31]]},"abstract":"<jats:p>Blindspots in APIs can cause software engineers to introduce vulnerabilities, but such blindspots are, unfortunately, common. We study the effect APIs with blindspots have on developers in two languages by replicating a 109-developer, 24-Java-API controlled experiment. Our replication applies to Python and involves 129 new developers and 22 new APIs. We find that using APIs with blindspots statistically significantly reduces the developers\u2019 ability to correctly reason about the APIs in both languages, but that the effect is more pronounced for Python. Interestingly, for Java, the effect increased with complexity of the code relying on the API, whereas for Python, the opposite was true. This suggests that Python developers are less likely to notice potential for vulnerabilities in complex code than in simple code, whereas Java developers are more likely to recognize the extra complexity and apply more care, but are more careless with simple code. Whether the developers considered API uses to be more difficult, less clear, and less familiar did not have an effect on their ability to correctly reason about them. Developers with better long-term memory recall were more likely to correctly reason about APIs with blindspots, but short-term memory, processing speed, episodic memory, and memory span had no effect. Surprisingly, professional experience and expertise did not improve the developers\u2019 ability to reason about APIs with blindspots across both languages, with long-term professionals with many years of experience making mistakes as often as relative novices. Finally, personality traits did not significantly affect the Python developers\u2019 ability to reason about APIs with blindspots, but less extroverted and more open developers were better at reasoning about Java APIs with blindspots. Overall, our findings suggest that blindspots in APIs are a serious problem across languages, and that experience and education alone do not overcome that problem, suggesting that tools are needed to help developers recognize blindspots in APIs as they write code that uses those APIs.<\/jats:p>","DOI":"10.1145\/3571850","type":"journal-article","created":{"date-parts":[[2022,11,19]],"date-time":"2022-11-19T05:22:03Z","timestamp":1668835323000},"page":"1-31","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Blindspots in Python and Java APIs Result in Vulnerable Code"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3027-7986","authenticated-orcid":false,"given":"Yuriy","family":"Brun","sequence":"first","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, MA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2615-3577","authenticated-orcid":false,"given":"Tian","family":"Lin","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9721-1004","authenticated-orcid":false,"given":"Jessie Elise","family":"Somerville","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9749-8671","authenticated-orcid":false,"given":"Elisha M.","family":"Myers","sequence":"additional","affiliation":[{"name":"Florida Atlantic University, University of Florida, Gainesville, FL"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2705-7520","authenticated-orcid":false,"given":"Natalie","family":"Ebner","sequence":"additional","affiliation":[{"name":"University of Florida, Gainesville, FL"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,26]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.52"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.24"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2016.013"},{"key":"e_1_3_2_6_2","first-page":"60","volume-title":"International Conference on Machine Learning (ICML\u201918)","volume":"80","author":"Agarwal Alekh","year":"2018","unstructured":"Alekh Agarwal, Alina Beygelzimer, Miroslav Dud\u00edk, John Langford, and Hanna Wallach. 2018. A reductions approach to fair classification. In International Conference on Machine Learning (ICML\u201918), Vol. PMLR 80. 60\u201369."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3264590"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134336"},{"key":"e_1_3_2_9_2","volume-title":"Workshop on Usable Security","author":"Balebako Rebecca","year":"2014","unstructured":"Rebecca Balebako, Abigail Marsh, Jialiu Lin, Jason I Hong, and Lorrie Faith Cranor. 2014. The privacy and security behaviors of smartphone app developers. In Workshop on Usable Security. Internet Society."},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3340571"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025188"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606571"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2369047"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568246"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/2094091.2094101"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025151"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3375633"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/2909480"},{"key":"e_1_3_2_19_2","volume-title":"Reversible Debugging Software","author":"Britton Tom","year":"2013","unstructured":"Tom Britton, Lisa Jeng, Graham Carver, Paul Cheak, and Tomer Katzenellenbogen. 2013. Reversible Debugging Software. Technical Report. University of Cambridge, Judge Business School."},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2011.25"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025187"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/2025113.2025139"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2013.28"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SEAMS.2007.4"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/1316550.1316557"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/CLOUD.2012.126"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.13"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3264838"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/2683467.2683472"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.52"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884798"},{"key":"e_1_3_2_32_2","unstructured":"Common Weakness Enumeration 2011. Common Weakness Enumeration (CWE)\/SANS Top 25 Most Dangerous Software Errors. Retrieved from http:\/\/cwe.mitre.org\/top25\/."},{"key":"e_1_3_2_33_2","volume-title":"Revised NEO Personality Inventory (NEO PI-R) and NEO Five-Factor Inventory (NEO-FFI): Professional Manual","author":"Costa Paul T.","year":"1992","unstructured":"Paul T. Costa and Robert R. MacCrae. 1992. Revised NEO Personality Inventory (NEO PI-R) and NEO Five-Factor Inventory (NEO-FFI): Professional Manual. Psychological Assessment Resources, Incorporated."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/1882291.1882312"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/1831708.1831719"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1007\/11531142_23"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.3389\/fpsyg.2014.00781"},{"key":"e_1_3_2_38_2","first-page":"214","volume-title":"Innovations in Theoretical Computer Science Conference (ITCS\u201912)","author":"Dwork Cynthia","year":"2012","unstructured":"Cynthia Dwork, Moritz Hardt, Toniann Pitassi, Omer Reingold, and Richard Zemel. 2012. Fairness through awareness. In Innovations in Theoretical Computer Science Conference (ITCS\u201912). 214\u2013226."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2007.85"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510138"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3428299"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.31"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106277"},{"key":"e_1_3_2_44_2","volume-title":"Design Patterns: Elements of Reusable Object-oriented Software","author":"Gamma Erich","year":"1995","unstructured":"Erich Gamma, Richard Helm, Ralph Johnson, and John Vlissides. 1995. Design Patterns: Elements of Reusable Object-oriented Software. Addison-Wesley Longman Publishing Co., Inc."},{"issue":"11","key":"e_1_3_2_45_2","first-page":"S2\u2013S6","article-title":"NIH toolbox for assessment of neurological and behavioral function","volume":"80","author":"Gershon Richard C.","year":"2013","unstructured":"Richard C. Gershon, Molly V. Wagster, Hugh C. Hendrie, Nathan A. Fox, Karon F. Cook, and Cindy J. Nowinski. 2013. NIH toolbox for assessment of neurological and behavioral function. Neurology 80, 11 Supplement 3 (2013), S2\u2013S6.","journal-title":"Neurology"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568234"},{"key":"e_1_3_2_47_2","volume-title":"10th International Conference on Learning Representations (ICLR\u201922)","author":"Giguere Stephen","year":"2022","unstructured":"Stephen Giguere, Blossom Metevier, Yuriy Brun, Bruno Castro da Silva, Philip S. Thomas, and Scott Niekum. 2022. Fairness guarantees under demographic shift. In 10th International Conference on Learning Representations (ICLR\u201922). Retrieved from https:\/\/openreview.net\/forum?id=wbPObLm6ueA."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106264"},{"key":"e_1_3_2_49_2","unstructured":"GraphicsMagick 2017. GraphicsMagick 1.4 Heap-based Buffer Overflow Vulnerability. Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-17915."},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2016.111"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186138"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1080\/09658211.2013.795974"},{"issue":"1999","key":"e_1_3_2_53_2","first-page":"102","article-title":"The big five trait taxonomy: History, measurement, and theoretical perspectives","volume":"2","author":"John Oliver P.","year":"1999","unstructured":"Oliver P. John and Sanjay Srivastava. 1999. The big five trait taxonomy: History, measurement, and theoretical perspectives. Handb. Personal.: Theor. Res. 2, 1999 (1999), 102\u2013138.","journal-title":"Handb. Personal.: Theor. Res."},{"key":"e_1_3_2_54_2","article-title":"Fairkit, fairkit, on the wall, who\u2019s the fairest of them all? Supporting data scientists in training fair models","volume":"2012","author":"Johnson Brittany","year":"2020","unstructured":"Brittany Johnson, Jesse Bartola, Rico Angell, Katherine Keith, Sam Witty, Stephen J. Giguere, and Yuriy Brun. 2020. Fairkit, fairkit, on the wall, who\u2019s the fairest of them all? Supporting data scientists in training fair models. CoRR abs\/2012.09951 (2020).","journal-title":"CoRR"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510454.3516830"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380377"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/2950290.2950304"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/581339.581397"},{"key":"e_1_3_2_59_2","article-title":"The Cost of Poor Software Quality in the US: A 2020 Report","author":"Krasner Herb","year":"2020","unstructured":"Herb Krasner. 2020. The Cost of Poor Software Quality in the US: A 2020 Report. Retrieved from https:\/\/www.it-cisq.org\/pdf\/CPSQ-2020-report.pdf.","journal-title":"Retrieved from https:\/\/www.it-cisq.org\/pdf\/CPSQ-2020-report.pdf"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635890"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1177\/1073191113508807"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1145\/1065010.1065014"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1976.233837"},{"key":"e_1_3_2_64_2","unstructured":"Joe McManus and Sandy Shrum. 2015. SEI CERT Oracle Coding Standard for Java. Retrieved from https:\/\/wiki.sei.cmu.edu\/confluence\/display\/java\/JavaCodingGuidelines."},{"key":"e_1_3_2_65_2","first-page":"14893","volume-title":"Annual Conference on Neural Information Processing Systems (NeurIPS), Advances in Neural Information Processing Systems 32","author":"Metevier Blossom","year":"2019","unstructured":"Blossom Metevier, Stephen Giguere, Sarah Brockman, Ari Kobren, Yuriy Brun, Emma Brunskill, and Philip Thomas. 2019. Offline contextual bandits with high probability fairness guarantees. In Annual Conference on Neural Information Processing Systems (NeurIPS), Advances in Neural Information Processing Systems 32. 14893\u201314904."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10606-015-9230-9"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/2896587"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884790"},{"key":"e_1_3_2_69_2","unstructured":"National Vulnerability Database 1999. National Vulnerability Database. Retrieved from https:\/\/nvd.nist.gov\/."},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/2642937.2642988"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664254"},{"key":"e_1_3_2_72_2","first-page":"315","volume-title":"USENIX Symposium on Usable Privacy and Security (SOUPS\u201918)","author":"Oliveira Daniela Seabra","year":"2018","unstructured":"Daniela Seabra Oliveira, Tian Lin, Muhammad Sajidur Rahman, Rad Akefirad, Donovan Ellis, Eliany Perez, Rahul Bobhate, Lois A. DeLong, Justin Cappos, Yuriy Brun, and Natalie C. Ebner. 2018. API blindspots: Why experienced developers write vulnerable code. In USENIX Symposium on Usable Privacy and Security (SOUPS\u201918). 315\u2013328. Retrieved from https:\/\/www.usenix.org\/system\/files\/conference\/soups2018\/soups2018-oliveira.pdf."},{"key":"e_1_3_2_73_2","first-page":"239","volume-title":"USENIX Conference on Security Symposium (SEC\u201915)","author":"Oltrogge Marten","year":"2015","unstructured":"Marten Oltrogge, Yasemin Acar, Sergej Dechand, Matthew Smith, and Sascha Fahl. 2015. To pin or not to pin helping app developers bullet proof their TLS connections. In USENIX Conference on Security Symposium (SEC\u201915). USENIX Association, 239\u2013254."},{"key":"e_1_3_2_74_2","unstructured":"Open Web Application Security Project 2013. The Open Web Application Security Project (OWASP) Top 10 Most Critical Web Application Security Risks. Retrieved from https:\/\/www.owasp.org\/images\/f\/f8\/OWASP_Top_10_-_2013.pdf."},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1236233"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383773"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/2851581.2892392"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/2998181.2998191"},{"key":"e_1_3_2_79_2","article-title":"An Empirical Case Study on Stack Overflow to Explore Developers\u2019 Security Challenges","author":"Rahman Muhammad Sajidur","year":"2016","unstructured":"Muhammad Sajidur Rahman. 2016. An Empirical Case Study on Stack Overflow to Explore Developers\u2019 Security Challenges. Masters Report. Retrieved from http:\/\/krex.k-state.edu\/dspace\/handle\/2097\/34563.","journal-title":"Masters Report. Retrieved from http:\/\/krex.k-state.edu\/dspace\/handle\/2097\/34563"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2009.193"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-010-9150-8"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1037\/0882-7974.2.1.43"},{"key":"e_1_3_2_83_2","article-title":"Passport: Improving automated formal verification using identifiers","volume":"2204","author":"Sanchez-Stern Alex","year":"2022","unstructured":"Alex Sanchez-Stern, Emily First, Timothy Zhou, Zhanna Kaufman, Yuriy Brun, and Talia Ringer. 2022. Passport: Improving automated formal verification using identifiers. CoRR abs\/2204.10370 (2022).","journal-title":"CoRR"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2003.1201222"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2011.64"},{"key":"e_1_3_2_86_2","volume-title":"Intellectual Development in Adulthood: The Seattle Longitudinal Study","author":"Schaie K. Warner","year":"1996","unstructured":"K. Warner Schaie. 1996. Intellectual Development in Adulthood: The Seattle Longitudinal Study. Cambridge University Press, New York, NY."},{"key":"e_1_3_2_87_2","unstructured":"Secure Coding Guidelines 2022. Secure Coding Guidelines for Java SE Oracle. Retrieved from http:\/\/www.oracle.com\/technetwork\/java\/seccodeguide-139067.html#6."},{"key":"e_1_3_2_88_2","unstructured":"Security Focus Vulnerability Database 2021. Security Focus Vulnerability Database Accenture. Retrieved from https:\/\/www.securityfocus.com\/."},{"key":"e_1_3_2_89_2","unstructured":"Security Vulnerabilities. 2017. Security Vulnerabilities (SQL Injection) MITRE Corporation. Retrieved from https:\/\/www.cvedetails.com\/vulnerability-list\/opsqli-1\/sql-injection.html."},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-71067-7_6"},{"key":"e_1_3_2_91_2","unstructured":"Stack Overflow 2008. Stack Overflow: A Q\/A Site for Professional and Enthusiast Programmers Stack Overflow. Retrieved from https:\/\/www.stackoverflow.com\/."},{"key":"e_1_3_2_92_2","unstructured":"State of Software Security. 2016. State of Software Security Veracode. Retrieved from https:\/\/www.veracode.com\/sites\/default\/files\/Resources\/Reports\/state-of-software-security-volume-7-veracode-report.pdf."},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1145\/2534973"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2007.92"},{"key":"e_1_3_2_95_2","unstructured":"Symantec. 2017. Symantec Internet Security Threat Report. Retrieved from https:\/\/www.symantec.com\/content\/dam\/symantec\/docs\/reports\/istr-22-2017-en.pdf."},{"key":"e_1_3_2_96_2","article-title":"Coq, v.8.7","author":"Team The Coq Development","year":"2017","unstructured":"The Coq Development Team. 2017. Coq, v.8.7. Retrieved from https:\/\/coq.inria.fr.","journal-title":"Retrieved from https:\/\/coq.inria.fr"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.aag3311"},{"key":"e_1_3_2_98_2","volume-title":"IEEE European Symposium on Security and Privacy (EuroS&P\u201917)","author":"Tramer Florian","year":"2017","unstructured":"Florian Tramer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, Jean-Pierre Hubaux, Mathias Humbert, Ari Juels, and Huang Lin. 2017. FairTest: Discovering unwarranted associations in data-driven applications. In IEEE European Symposium on Security and Privacy (EuroS&P\u201917)."},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1093\/ageing\/afl095"},{"key":"e_1_3_2_100_2","volume-title":"11th USENIX Workshop on Offensive Technologies (WOOT\u201917)","author":"Unruh Tommi","year":"2017","unstructured":"Tommi Unruh, Bhargava Shastry, Malte Skoruppa, Federico Maggi, Konrad Rieck, Jean-Pierre Seifert, and Fabian Yamaguchi. 2017. Leveraging flawed tutorials for seeding large-scale web vulnerability discovery. In 11th USENIX Workshop on Offensive Technologies (WOOT\u201917). USENIX Association. Retrieved from https:\/\/www.usenix.org\/conference\/woot17\/workshop-program\/presentation\/unruh."},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380394"},{"key":"e_1_3_2_102_2","volume-title":"29th USENIX Security Symposium (USENIX Security)","author":"Votipka Daniel","year":"2020","unstructured":"Daniel Votipka, Kelsey R. Fulton, James Parker, Matthew Hou, Michelle L. Mazurek, and Michael Hicks. 2020. Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix It. In 29th USENIX Security Symposium (USENIX Security). Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/votipka-understanding."},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00003"},{"key":"e_1_3_2_104_2","volume-title":"International Conference on Software Engineering (ICSE\u201921)","author":"Wan Zhiyuan","year":"2021","unstructured":"Zhiyuan Wan, Xin Xia, David Lo, Jiachi Chen, Xiapu Luo, and Xiaohu Yang. 2021. Smart contract security: A practitioners\u2019 perspective. In International Conference on Software Engineering (ICSE\u201921)."},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev.2017.21"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2019.07.007"},{"key":"e_1_3_2_107_2","doi-asserted-by":"publisher","DOI":"10.1145\/2663887.2663898"},{"key":"e_1_3_2_108_2","doi-asserted-by":"publisher","DOI":"10.1145\/2786805.2786816"},{"key":"e_1_3_2_109_2","doi-asserted-by":"publisher","DOI":"10.1145\/2531602.2531722"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.1145\/2207676.2208665"},{"key":"e_1_3_2_111_2","first-page":"161","volume-title":"IEEE Symposium on Visual Languages and Human-Centric Computing (VL\/HCC)","author":"Xie Jing","year":"2011","unstructured":"Jing Xie, Heather Richter Lipford, and Bill Chu. 2011. Why do programmers make security errors? In IEEE Symposium on Visual Languages and Human-Centric Computing (VL\/HCC). IEEE, 161\u2013164."},{"key":"e_1_3_2_112_2","volume-title":"International Conference on Machine Learning (ICML\u201919)","author":"Yang Kaiyu","year":"2019","unstructured":"Kaiyu Yang and Jia Deng. 2019. Learning to prove theorems via interacting with proof assistants. In International Conference on Machine Learning (ICML\u201919). Retrieved from http:\/\/proceedings.mlr.press\/v97\/yang19a\/yang19a.pdf."}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3571850","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3571850","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T13:48:48Z","timestamp":1750168128000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3571850"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,26]]},"references-count":111,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,7,31]]}},"alternative-id":["10.1145\/3571850"],"URL":"https:\/\/doi.org\/10.1145\/3571850","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,26]]},"assertion":[{"value":"2021-12-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-10-18","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-04-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}