{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:43:41Z","timestamp":1785512621489,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":76,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T00:00:00Z","timestamp":1712880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["CNS-2046361"],"award-info":[{"award-number":["CNS-2046361"]}]},{"name":"NSF","award":["CNS-2052947"],"award-info":[{"award-number":["CNS-2052947"]}]},{"name":"NSF","award":["CNS-2154404"],"award-info":[{"award-number":["CNS-2154404"]}]},{"name":"NSF","award":["CNS-2247370"],"award-info":[{"award-number":["CNS-2247370"]}]},{"name":"NSF","award":["CCF-2124080"],"award-info":[{"award-number":["CCF-2124080"]}]},{"name":"DARPA","award":["N66001-21-C-4018"],"award-info":[{"award-number":["N66001-21-C-4018"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,12]]},"DOI":"10.1145\/3597503.3639199","type":"proceedings-article","created":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T16:43:26Z","timestamp":1712940206000},"page":"1-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["RogueOne: Detecting Rogue Updates via Differential Data-flow Analysis Using Trust Domains"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-7924-6436","authenticated-orcid":false,"given":"Raphael J.","family":"Sofaer","sequence":"first","affiliation":[{"name":"Columbia University, New York, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1630-7723","authenticated-orcid":false,"given":"Yaniv","family":"David","sequence":"additional","affiliation":[{"name":"Columbia University, New York, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9476-9247","authenticated-orcid":false,"given":"Mingqing","family":"Kang","sequence":"additional","affiliation":[{"name":"Johns Hopkins University, Baltimore, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0051-8385","authenticated-orcid":false,"given":"Jianjia","family":"Yu","sequence":"additional","affiliation":[{"name":"Johns Hopkins University, Baltimore, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9618-4830","authenticated-orcid":false,"given":"Yinzhi","family":"Cao","sequence":"additional","affiliation":[{"name":"Johns Hopkins University, Baltimore, Maryland, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-2277-6545","authenticated-orcid":false,"given":"Junfeng","family":"Yang","sequence":"additional","affiliation":[{"name":"Columbia University, New York, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-8301-4479","authenticated-orcid":false,"given":"Jason","family":"Nieh","sequence":"additional","affiliation":[{"name":"Columbia University, New York, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM.2018.00028"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.3390\/technologies9010003"},{"key":"e_1_3_2_1_3_1","volume-title":"Prototype Pollution Attack in NodeJS Application. NorthSec. Retrieved","author":"Arteau Olivier","year":"2023","unstructured":"Olivier Arteau. 2018. Prototype Pollution Attack in NodeJS Application. NorthSec. Retrieved 2 Feb 2023 from https:\/\/github.com\/HoLyVieR\/prototype-pollution-nsec18\/blob\/master\/paper\/JavaScript_prototype_pollution_attack_in_NodeJS.pdf"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884816"},{"key":"e_1_3_2_1_5_1","volume-title":"Retrieved","author":"Minimal Axios","year":"2024","unstructured":"Axios 2024. Minimal Example | Axios Docs. Axios. Retrieved 12 Jan 2024 from https:\/\/axios-http.com\/docs\/example"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635916"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00077"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23829-6_45"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2022.3"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23124"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/512950.512973"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI '22)","author":"David Yaniv","year":"2022","unstructured":"Yaniv David, Xudong Sun, Raphael J Sofaer, Aditya Senthilnathan, Junfeng Yang, Zhiqiang Zuo, Guoqing Harry Xu, Jason Nieh, and Ronghui Gu. 2022. UPGRADVISOR: Early Adopting Dependency Updates Using Hybrid Program Analysis and Hardware Tracing. In Proceedings of the 16th USENIX Symposium on Operating Systems Design and Implementation (OSDI '22). Carlsbad, CA, 751--767. https:\/\/par.nsf.gov\/biblio\/10356086"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (SEC '18)","author":"Davis James C","year":"2018","unstructured":"James C Davis, Eric R Williamson, and Dongyoon Lee. 2018. A Sense of Time for JavaScript and Node.js: First-Class Timeouts as a Cure for Event Handler Poisoning. In Proceedings of the 27th USENIX Security Symposium (SEC '18). Baltimore, MD, 343--359. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/davis"},{"key":"e_1_3_2_1_14_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID '20)","author":"DeMarinis Nicholas","year":"2020","unstructured":"Nicholas DeMarinis, Kent Williams-King, Di Jin, Rodrigo Fonseca, and Vasileios P. Kemerlis. 2020. sysfilter: Automated System Call Filtering for Commodity Software. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID '20). Virtual, 459--474. https:\/\/www.usenix.org\/conference\/raid2020\/presentation\/demarinis"},{"key":"e_1_3_2_1_16_1","volume-title":"event-stream. Retrieved","year":"2023","unstructured":"dominictarr. 2023. event-stream. Retrieved 2 February 2023 from https:\/\/github.com\/dominictarr\/event-stream\/issues\/116"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.23055"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICST46399.2020.00022"},{"key":"e_1_3_2_1_19_1","volume-title":"17th USENIX Security Symposium (SEC '08)","author":"Engler Dawson","year":"2008","unstructured":"Dawson Engler, Ben Chelf, Andy Chou, and Seth Hallem. 2008. A Couple Billion Lines of Code Later: Static Checking in the Real World. In 17th USENIX Security Symposium (SEC '08). San Jose, CA. https:\/\/www.usenix.org\/conference\/17th-usenix-security-symposium\/couple-billion-lines-code-later-static-checking-real-world"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3345656"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359813"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484745"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606621"},{"key":"e_1_3_2_1_24_1","volume-title":"Global objects | Node.js v21.1.0 Documentation. Retrieved","author":"Foundation JS","year":"2023","unstructured":"OpenJS Foundation. 2023. Global objects | Node.js v21.1.0 Documentation. Retrieved 13 November 2023 from https:\/\/nodejs.org\/api\/globals.html"},{"key":"e_1_3_2_1_25_1","volume-title":"Modules: CommonJS modules | Node.js v21.2.0 Documentation. Retrieved","author":"Foundation JS","year":"2023","unstructured":"OpenJS Foundation. 2023. Modules: CommonJS modules | Node.js v21.2.0 Documentation. Retrieved 15 November 2023 from https:\/\/nodejs.org\/api\/modules.html#moduleexports"},{"key":"e_1_3_2_1_26_1","volume-title":"npm. Retrieved","author":"Foundation JS","year":"2023","unstructured":"OpenJS Foundation. 2023. npm. Retrieved 4 February 2023 from https:\/\/www.npmjs.com"},{"key":"e_1_3_2_1_27_1","volume-title":"scripts | npm Docs. Retrieved","author":"Foundation JS","year":"2023","unstructured":"OpenJS Foundation. 2023. scripts | npm Docs. Retrieved 12 April 2023 from https:\/\/docs.npmjs.com\/cli\/v9\/using-npm\/scripts"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446728"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133926"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03237-0_17"},{"key":"e_1_3_2_1_31_1","volume-title":"fast. Retrieved","author":"Kang Mingqing","year":"2023","unstructured":"Mingqing Kang. 2023. fast. Retrieved 14 November 2023 from https:\/\/github.com\/fast-sp-2023\/fast"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179352"},{"key":"e_1_3_2_1_33_1","volume-title":"Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites. In 29th Annual Network and Distributed System Security Symposium, (NDSS '22)","author":"Kang Zifeng","year":"2022","unstructured":"Zifeng Kang, Song Li, and Yinzhi Cao. 2022. Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites. In 29th Annual Network and Distributed System Security Symposium, (NDSS '22). The Internet Society, San Diego, CA. https:\/\/www.ndss-symposium.org\/ndss-paper\/auto-draft-207\/"},{"key":"e_1_3_2_1_34_1","volume-title":"npm rank. Retrieved","author":"Kashcha Andrei","year":"2023","unstructured":"Andrei Kashcha. 2023. npm rank. Retrieved 2 February 2023 from https:\/\/gist.github.com\/anvaka\/8e8fa57c7ee1350e3491"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635904"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606626"},{"key":"e_1_3_2_1_37_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID '20)","author":"Koishybayev Igibek","year":"2020","unstructured":"Igibek Koishybayev and Alexandros Kapravelos. 2020. Mininode: Reducing the Attack Surface of Node.js Applications. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID '20). Virtual, 121--134. https:\/\/www.usenix.org\/conference\/raid2020\/presentation\/koishybayev"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179304"},{"key":"e_1_3_2_1_39_1","volume-title":"19th International Workshop on Foundations of Object-Oriented Languages (FOOL '12)","volume":"10","author":"Lee Hongki","year":"2012","unstructured":"Hongki Lee, Sooncheol Won, Joonho Jin, Junhee Cho, and Sukyoung Ryu. 2012. SAFE: Formal specification and implementation of a scalable analysis framework for ECMAScript. In 19th International Workshop on Foundations of Object-Oriented Languages (FOOL '12), Vol. 10. Tuscon, AZ. https:\/\/github.com\/sukyoung\/safe"},{"key":"e_1_3_2_1_40_1","volume-title":"ODGen Source Code. Retrieved","author":"Song Li.","year":"2024","unstructured":"Song Li. 2021. ODGen Source Code. Retrieved 11 January 2024 from https:\/\/github.com\/Song-Li\/ODGen\/."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468542"},{"key":"e_1_3_2_1_42_1","volume-title":"31st USENIX Security Symposium (SEC '22)","author":"Li Song","year":"2022","unstructured":"Song Li, Mingqing Kang, Jianwei Hou, and Yinzhi Cao. 2022. Mining Node.js Vulnerabilities via Object Dependence Graph and Query. In 31st USENIX Security Symposium (SEC '22). Boston, MA, 143--160. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/li-song"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106253"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2837614.2837617"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3092282.3092295"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00065"},{"key":"e_1_3_2_1_47_1","volume-title":"Inheritance and the prototype chain - JavaScript | MDN. Retrieved","year":"2023","unstructured":"Mozilla. 2023. Inheritance and the prototype chain - JavaScript | MDN. Retrieved 13 November 2023 from https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/JavaScript\/Inheritance_and_the_prototype_chain"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338933"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464836"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-52683-2_2"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3560835.3564556"},{"key":"e_1_3_2_1_52_1","volume-title":"How Two Malicious NPM Packages Targeted & Sabotaged Others. Retrieved","author":"Overson Jarrod","year":"2023","unstructured":"Jarrod Overson. 2021. How Two Malicious NPM Packages Targeted & Sabotaged Others. Retrieved 2 February 2023 from https:\/\/jsoverson.medium.com\/how-two-malicious-npm-packages-targeted-sabotaged-one-other-fed7199099c8"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468556"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2013.6596048"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236950.3236956"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.38"},{"key":"e_1_3_2_1_57_1","unstructured":"Max Schaefer. 2023. Amalfi Classifier. Private email communication."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2010.26"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510457.3513059"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510104"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/2491411.2491447"},{"key":"e_1_3_2_1_62_1","volume-title":"Trick or treat: that 'twilio-npm' package is brandjacking malware in disguise! Retrieved","author":"Sharma Ax","year":"2023","unstructured":"Ax Sharma. 2020. Trick or treat: that 'twilio-npm' package is brandjacking malware in disguise! Retrieved 10 March 2023 from https:\/\/blog.sonatype.com\/twilio-npm-is-brandjacking-malware-in-disguise"},{"key":"e_1_3_2_1_63_1","volume-title":"Proceedings of the 32th USENIX Security Symposium (SEC '23)","author":"Shcherbakov Mikhail","year":"2023","unstructured":"Mikhail Shcherbakov, Musard Balliu, and Cristian-Alexandru Staicu. 2023. Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js. In Proceedings of the 32th USENIX Security Symposium (SEC '23). Anaheim, CA. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/shcherbakov"},{"key":"e_1_3_2_1_64_1","volume-title":"Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches. In 31st USENIX Security Symposium (SEC '22)","author":"Shi Youkun","year":"2022","unstructured":"Youkun Shi, Yuan Zhang, Tianhan Luo, Xiangyu Mao, Yinzhi Cao, Ziwen Wang, Yudi Zhao, Zongan Huang, and Min Yang. 2022. Backporting Security Patches of Web Applications: A Prototype Design and Implementation on Injection Vulnerability Patches. In 31st USENIX Security Symposium (SEC '22). Boston, MA, 1993--2010. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/shi"},{"key":"e_1_3_2_1_65_1","volume-title":"A post-mortem of the malicious event-stream backdoor | Snyk. Retrieved","year":"2023","unstructured":"Snyk. 2022. A post-mortem of the malicious event-stream backdoor | Snyk. Retrieved 2 February 2023 from https:\/\/snyk.io\/blog\/a-post-mortem-of-the-malicious-event-stream-backdoor"},{"key":"e_1_3_2_1_66_1","volume-title":"Proceedings of the 27th USENIX Security Symposium (SEC '18)","author":"Staicu Cristian-Alexandru","year":"2018","unstructured":"Cristian-Alexandru Staicu and Michael Pradel. 2018. Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web Servers. In Proceedings of the 27th USENIX Security Symposium (SEC '18). Baltimore, MD, 361--376. https:\/\/www.usenix.org\/conference\/usenixsecurity18\/presentation\/staicu"},{"key":"e_1_3_2_1_67_1","volume-title":"Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem. Retrieved","author":"Tal Liran","year":"2023","unstructured":"Liran Tal. 2019. Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem. Retrieved 1 August 2023 from https:\/\/snyk.io\/blog\/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65745-1_7"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIEV.2014.6850807"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542476.1542486"},{"key":"e_1_3_2_1_71_1","volume-title":"Drew Davidson, and Vaibhav Rastogi.","author":"Vaidya Ruturaj K.","year":"2021","unstructured":"Ruturaj K. Vaidya, Lorenzo De Carli, Drew Davidson, and Vaibhav Rastogi. 2021. Security Issues in Language-based Software Ecosystems. arXiv:1903.02613 http:\/\/arxiv.org\/abs\/1903.02613"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484535"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180233"},{"key":"e_1_3_2_1_74_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (SEC '21)","author":"Xiao Feng","year":"2021","unstructured":"Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu, and Wenke Lee. 2021. Abusing Hidden Properties to Attack the Node.js Ecosystem. In Proceedings of the 30th USENIX Security Symposium (SEC '21). Virtual, 2951--2968. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/xiao"},{"key":"e_1_3_2_1_75_1","volume-title":"Automatic Hot Patch Generation for Android Kernels. In 29th USENIX Security Symposium (SEC '20)","author":"Xu Zhengzi","year":"2020","unstructured":"Zhengzi Xu, Yulong Zhang, Longri Zheng, Liangzhao Xia, Chenfu Bao, Zhi Wang, and Yang Liu. 2020. Automatic Hot Patch Generation for Android Kernels. In 29th USENIX Security Symposium (SEC '20). Virtual, 2397--2414. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/xu"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468577"},{"key":"e_1_3_2_1_77_1","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium (SEC '19)","author":"Zimmermann Markus","year":"2019","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Smallworld with High Risks: A Study of Security Threats in the npm Ecosystem. In Proceedings of the 28th USENIX Conference on Security Symposium (SEC '19). Santa Clara, CA, 995--1010. https:\/\/www.usenix.net\/system\/files\/sec19-zimmermann.pdf"}],"event":{"name":"ICSE '24: IEEE\/ACM 46th International Conference on Software Engineering","location":"Lisbon Portugal","acronym":"ICSE '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639199","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597503.3639199","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597503.3639199","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:49:13Z","timestamp":1750286953000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639199"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,12]]},"references-count":76,"alternative-id":["10.1145\/3597503.3639199","10.1145\/3597503"],"URL":"https:\/\/doi.org\/10.1145\/3597503.3639199","relation":{},"subject":[],"published":{"date-parts":[[2024,4,12]]},"assertion":[{"value":"2024-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}