{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:40:46Z","timestamp":1783096846914,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":76,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T00:00:00Z","timestamp":1712880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,12]]},"DOI":"10.1145\/3597503.3639202","type":"proceedings-article","created":{"date-parts":[[2024,4,12]],"date-time":"2024-04-12T16:43:26Z","timestamp":1712940206000},"page":"1-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Where is it? Tracing the Vulnerability-relevant Files from Vulnerability Reports"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5212-7068","authenticated-orcid":false,"given":"Jiamou","family":"Sun","sequence":"first","affiliation":[{"name":"CSIRO's Data61, Eveleigh, New South Wales, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2700-7478","authenticated-orcid":false,"given":"Jieshan","family":"Chen","sequence":"additional","affiliation":[{"name":"CSIRO's Data61, Eveleigh, New South Wales, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7663-1421","authenticated-orcid":false,"given":"Zhenchang","family":"Xing","sequence":"additional","affiliation":[{"name":"CSIRO's Data61, Eveleigh, New South Wales, Australia"},{"name":"Australian National University, Canberra, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9466-1672","authenticated-orcid":false,"given":"Qinghua","family":"Lu","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Eveleigh, New South Wales, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2273-1862","authenticated-orcid":false,"given":"Xiwei","family":"Xu","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Eveleigh, New South Wales, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5839-3765","authenticated-orcid":false,"given":"Liming","family":"Zhu","sequence":"additional","affiliation":[{"name":"CSIRO's Data61 &amp; School of CSE, UNSW, Eveleigh, New South Wales, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Deep Learning for Code Workshop (DL4C).","author":"Allal Loubna Ben","year":"2023","unstructured":"Loubna Ben Allal, Raymond Li, Denis Kocetkov, Chenghao Mou, Christopher Akiki, Carlos Munoz Ferrandis, Niklas Muennighoff, Mayank Mishra, Alex Gu, Manan Dey, Logesh Kumar Umapathi, Carolyn Jane Anderson, Yangtian Zi, Joel Lamy Poirier, Hailey Schoelkopf, Sergey Troshin, Dmitry Abulkhanov, Manuel Romero, Michael Lappert, Francesco De Toni, Bernardo Garc\u00eda del R\u00edo, Qian Liu, Shamik Bose, Urvashi Bhattacharyya, Terry Yue Zhuo, Ian Yu, Paulo Villegas, Marco Zocca, Sourab Mangrulkar, David Lansky, Huu Nguyen, Danish Contractor, Luis Villa, Jia Li, Dzmitry Bahdanau, Yacine Jernite, Sean Hughes, Daniel Fried, Arjun Guha, Harm de Vries, and Leandro von Werra. 2023. Santa-Coder: don't reach for the stars!. In Deep Learning for Code Workshop (DL4C)."},{"key":"e_1_3_2_1_2_1","volume-title":"Swapna Krishnakumar Radha, and Jarek Nabrzyski","author":"Barclay Iain","year":"2022","unstructured":"Iain Barclay, Alun Preece, Ian Taylor, Swapna Krishnakumar Radha, and Jarek Nabrzyski. 2022. Providing assurance and scrutability on shared data and machine learning models with verifiable credentials. Concurrency and Computation: Practice and Experience (2022), e6997."},{"key":"e_1_3_2_1_3_1","volume-title":"Towards trace-ability in data ecosystems using a bill of materials model. arXiv preprint arXiv:1904.04253","author":"Barclay Iain","year":"2019","unstructured":"Iain Barclay, Alun Preece, Ian Taylor, and Dinesh Verma. 2019. Towards trace-ability in data ecosystems using a bill of materials model. arXiv preprint arXiv:1904.04253 (2019)."},{"key":"e_1_3_2_1_4_1","volume-title":"On the Way to SBOMs: Investigating Design Issues and Solutions in Practice. arXiv preprint arXiv:2304.13261","author":"Bi Tingting","year":"2023","unstructured":"Tingting Bi, Boming Xia, Zhenchang Xing, Qinghua Lu, and Liming Zhu. 2023. On the Way to SBOMs: Investigating Design Issues and Solutions in Practice. arXiv preprint arXiv:2304.13261 (2023)."},{"key":"e_1_3_2_1_5_1","unstructured":"Tom Brown Benjamin Mann Nick Ryder Melanie Subbiah Jared D Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell et al. 2020. Language models are few-shot learners. Advances in neural information processing systems 33 (2020) 1877--1901."},{"key":"e_1_3_2_1_6_1","volume-title":"Building resilient medical technology supply chains with a software bill of materials. npj Digital Medicine 4, 1","author":"Carmody Seth","year":"2021","unstructured":"Seth Carmody, Andrea Coravos, Ginny Fahs, Audra Hatch, Janine Medina, Beau Woods, and Joshua Corman. 2021. Building resilient medical technology supply chains with a software bill of materials. npj Digital Medicine 4, 1 (2021), 34."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1613\/jair.953"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377813.3381360"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.3115\/1072064.1072067"},{"key":"e_1_3_2_1_10_1","volume-title":"A coefficient of agreement for nominal scales. Educational and psychological measurement 20, 1","author":"Cohen Jacob","year":"1960","unstructured":"Jacob Cohen. 1960. A coefficient of agreement for nominal scales. Educational and psychological measurement 20, 1 (1960), 37--46."},{"key":"e_1_3_2_1_11_1","unstructured":"Common Attack Pattern Enumeration and Classification. 2023. https:\/\/capec.mitre.org\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_12_1","unstructured":"Common Platform Enumeration. 2023. https:\/\/csrc.nist.gov\/projects\/security-content-automation-protocol\/specifications\/cpe. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_13_1","volume-title":"CWE","author":"Enumeration Common Weakness","year":"2023","unstructured":"Common Weakness Enumeration: CWE. 2023. https:\/\/cwe.mitre.org\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_14_1","unstructured":"CVE Request Template. 2023. http:\/\/cveproject.github.io\/docs\/content\/key-details-phrasing.pdf. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies","volume":"1","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers). Association for Computational Linguistics, 4171--4186."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1002\/smr.567"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23126"},{"key":"e_1_3_2_1_18_1","volume-title":"FIRMSCOPE: Automatic uncovering of Privilege-Escalation vulnerabilities in Pre-Installed apps in android firmware. In 29th USENIX security symposium (USENIX Security 20). 2379--2396.","author":"Elsabagh Mohamed","year":"2020","unstructured":"Mohamed Elsabagh, Ryan Johnson, Angelos Stavrou, Chaoshun Zuo, Qingchuan Zhao, and Zhiqiang Lin. 2020. FIRMSCOPE: Automatic uncovering of Privilege-Escalation vulnerabilities in Pre-Installed apps in android firmware. In 29th USENIX security symposium (USENIX Security 20). 2379--2396."},{"key":"e_1_3_2_1_19_1","unstructured":"English Wikipedia. 2023. https:\/\/en.wikipedia.org\/wiki\/Main_Page. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_20_1","volume-title":"CodeBERT: A Pre-Trained Model for Programming and Natural Languages. In Findings of the Association for Computational Linguistics: EMNLP","author":"Feng Zhangyin","year":"2020","unstructured":"Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, Daxin Jiang, and Ming Zhou. 2020. CodeBERT: A Pre-Trained Model for Programming and Natural Languages. In Findings of the Association for Computational Linguistics: EMNLP 2020. Association for Computational Linguistics, 1536--1547."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528452"},{"key":"e_1_3_2_1_22_1","volume-title":"Comparative evaluation of pretrained transfer learning models on automatic short answer grading. arXiv preprint arXiv:2009.01303","author":"Gaddipati Sasi Kiran","year":"2020","unstructured":"Sasi Kiran Gaddipati, Deebul Nair, and Paul G Pl\u00f6ger. 2020. Comparative evaluation of pretrained transfer learning models on automatic short answer grading. arXiv preprint arXiv:2009.01303 (2020)."},{"key":"e_1_3_2_1_23_1","unstructured":"GitHub Advisory Database. 2023. https:\/\/github.com\/advisories. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_24_1","unstructured":"Dan Goodin. 2021. The Internet's biggest players are all affected by critical Log4Shell 0-day. https:\/\/arstechnica.com\/information-technology\/2021\/12\/the-critical-log4shell-zero-day-affects-a-whos-who-of-big-cloud-services\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1148\/radiology.143.1.7063747"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524610.3527893"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.62"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678622"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.3390\/app10051692"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3076142"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3051525"},{"key":"e_1_3_2_1_32_1","volume-title":"VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In 25th Annual Network and Distributed System Security Symposium.","author":"Li Zhen","year":"2018","unstructured":"Zhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin, Sujuan Wang, Zhijun Deng, and Yuyi Zhong. 2018. VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. In 25th Annual Network and Distributed System Security Symposium."},{"key":"e_1_3_2_1_33_1","volume-title":"Hassan","author":"Lin Jiahuei","year":"2023","unstructured":"Jiahuei Lin, Bram Adams, and Ahmed E. Hassan. 2023. On the coordination of vulnerability fixes: An empirical study of practices from 13 CVE numbering authorities. Empirical Software Engineering 28, 151 (2023)."},{"key":"e_1_3_2_1_34_1","unstructured":"Linux kernel. 2023. https:\/\/github.com\/torvalds\/linux. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_35_1","volume-title":"Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692","author":"Liu Yinhan","year":"2019","unstructured":"Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692 (2019)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00094"},{"key":"e_1_3_2_1_37_1","volume-title":"On the Effect of Transitivity and Granularity on Vulnerability Propagation in the Maven Ecosystem. In 2023 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)","author":"Mir Amir M","unstructured":"Amir M Mir, Mehdi Keshani, and Sebastian Proksch. 2023. On the Effect of Transitivity and Granularity on Vulnerability Propagation in the Maven Ecosystem. In 2023 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 201--211."},{"key":"e_1_3_2_1_38_1","unstructured":"MITRE ATT&CK. 2023. https:\/\/attack.mitre.org\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_39_1","unstructured":"National Vulnerability Database. 2023. https:\/\/nvd.nist.gov\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3558936"},{"key":"e_1_3_2_1_41_1","volume-title":"DIMVA 2020, Lisbon, Portugal, 2020, Proceedings 17","author":"Ohm Marc","year":"2020","unstructured":"Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier. 2020. Backstabber's knife collection: A review of open source software supply chain attacks. In Detection of Intrusions and Malware, and Vulnerability Assessment: 17th International Conference, DIMVA 2020, Lisbon, Portugal, 2020, Proceedings 17. Springer, 23--43."},{"key":"e_1_3_2_1_42_1","unstructured":"Open Source Insights. 2023. https:\/\/deps.dev\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_44_1","unstructured":"OWASP CycloneDX Software Bill of Materials (SBOM) Standard. 2023. https:\/\/cyclonedx.org\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_45_1","unstructured":"path-to-regexp - npm. 2023. https:\/\/www.npmjs.com\/package\/path-to-regexp. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3120928"},{"key":"e_1_3_2_1_47_1","unstructured":"Alec Radford Jeffrey Wu Rewon Child David Luan Dario Amodei Ilya Sutskever et al. 2019. Language models are unsupervised multitask learners. OpenAI blog 1 8 (2019) 9."},{"key":"e_1_3_2_1_48_1","unstructured":"S. C. R. Center. 2021. https:\/\/www.synopsys.com\/content\/dam\/synopsys\/sig-assets\/reports\/rep-ossra-2021.pdf. Accessed: 2021-09-31."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00058"},{"key":"e_1_3_2_1_50_1","volume-title":"Introduction to Modern Information Retrieval","author":"Salton G.","unstructured":"G. Salton and M.J. McGill. 1983. Introduction to Modern Information Retrieval. McGraw-Hill."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/361219.361220"},{"key":"e_1_3_2_1_52_1","unstructured":"Security Bug Tracker. 2023. https:\/\/security-tracker.debian.org\/tracker\/. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_53_1","unstructured":"Security Working Group. 2023. https:\/\/github.com\/nodejs\/security-wg. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_54_1","unstructured":"server - npm. 2023. https:\/\/www.npmjs.com\/package\/server. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_55_1","volume-title":"USENIX Security Symposium","author":"Shcherbakov Mikhail","year":"2023","unstructured":"Mikhail Shcherbakov, Musard Balliu, and Cristian-Alexandru Staicu. 2023. Silent spring: Prototype pollution leads to remote code execution in Node. js. In USENIX Security Symposium 2023."},{"key":"e_1_3_2_1_56_1","volume-title":"Elements Of Practical Geography","author":"Singh R.L.","unstructured":"R.L. Singh and S.P. B. 1979. Elements Of Practical Geography. Kalyani Publishers."},{"key":"e_1_3_2_1_57_1","unstructured":"Snyk Vulnerability Database. 2023. https:\/\/snyk.io\/vuln. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00089"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME55016.2022.00024"},{"key":"e_1_3_2_1_60_1","volume-title":"Attention is all you need. Advances in neural information processing systems 30","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. Advances in neural information processing systems 30 (2017)."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3178469"},{"key":"e_1_3_2_1_62_1","unstructured":"Vulnerability Database - OSV. 2023. https:\/\/osv.dev\/list. Accessed: 2023-07-31."},{"key":"e_1_3_2_1_63_1","volume-title":"DeepVD: Toward Class-Separation Features for Neural Network Vulnerability Detection. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2249--2261","author":"Wang Wenbo","year":"2023","unstructured":"Wenbo Wang, Tien N Nguyen, Shaohua Wang, Yi Li, Jiyuan Zhang, and Aashish Yadavally. 2023. DeepVD: Toward Class-Separation Features for Neural Network Vulnerability Detection. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2249--2261."},{"key":"e_1_3_2_1_64_1","volume-title":"Updates and Risks of Third-Party Libraries in Java Projects. In 2020 IEEE International Conference on Software Maintenance and Evolution (ICSME). 35--45","author":"Wang Ying","year":"2020","unstructured":"Ying Wang, Bihuan Chen, Kaifeng Huang, Bowen Shi, Congying Xu, Xin Peng, Yijian Wu, and Yang Liu. 2020. An Empirical Study of Usages, Updates and Risks of Third-Party Libraries in Java Projects. In 2020 IEEE International Conference on Software Maintenance and Evolution (ICSME). 35--45."},{"key":"e_1_3_2_1_65_1","volume-title":"Sylvain Gugger, Mariama Drame, Quentin Lhoest, and Alexander M. Rush.","author":"Wolf Thomas","year":"2020","unstructured":"Thomas Wolf, Lysandre Debut, Victor Sanh, Julien Chaumond, Clement Delangue, Anthony Moi, Pierric Cistac, Tim Rault, R\u00e9mi Louf, Morgan Funtowicz, Joe Davison, Sam Shleifer, Patrick von Platen, Clara Ma, Yacine Jernite, Julien Plu, Canwen Xu, Teven Le Scao, Sylvain Gugger, Mariama Drame, Quentin Lhoest, and Alexander M. Rush. 2020. Transformers: State-of-the-Art Natural Language Processing. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing: System Demonstrations. Association for Computational Linguistics, 38--45."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00219"},{"key":"e_1_3_2_1_67_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Xiao Yang","year":"2020","unstructured":"Yang Xiao, Bihuan Chen, Chendong Yu, Zhengzi Xu, Zimu Yuan, Feng Li, Binghong Liu, Yang Liu, Wei Huo, Wei Zou, et al. 2020. {MVP}: Detecting Vulnerabilities using {Patch-Enhanced} Vulnerability Signatures. In 29th USENIX Security Symposium (USENIX Security 20). 1165--1182."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549125"},{"key":"e_1_3_2_1_69_1","volume-title":"Automatic Hot Patch Generation for Android Kernels. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Xu Zhengzi","year":"2020","unstructured":"Zhengzi Xu, Yulong Zhang, Longri Zheng, Liangzhao Xia, Chenfu Bao, Zhi Wang, and Yang Liu. 2020. Automatic Hot Patch Generation for Android Kernels. In 29th USENIX Security Symposium (USENIX Security 20). USENIX Association, 2397--2414."},{"key":"e_1_3_2_1_70_1","volume-title":"International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel\/Distributed Computing","author":"Yang Jeong","unstructured":"Jeong Yang, Young Lee, and Arlen P McDonald. 2021. SolarWinds Software Supply Chain Security: Better Protection with Enforced Policies and Technologies. In International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel\/Distributed Computing. Springer, 43--58."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134085"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00067"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3117771"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3117771"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3468854","article-title":"Spi: Automated identification of security patches via commits","volume":"31","author":"Zhou Yaqin","year":"2021","unstructured":"Yaqin Zhou, Jing Kai Siow, Chenyu Wang, Shangqing Liu, and Yang Liu. 2021. Spi: Automated identification of security patches via commits. ACM Transactions on Software Engineering and Methodology (TOSEM) 31, 1 (2021), 1--27.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.11"},{"key":"e_1_3_2_1_77_1","first-page":"2224","article-title":"\u03bcVulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability Detection","volume":"18","author":"Zou Deqing","year":"2019","unstructured":"Deqing Zou, Sujuan Wang, Shouhuai Xu, Zhen Li, and Hai Jin. 2019. \u03bcVulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability Detection. IEEE Transactions on Dependable and Secure Computing 18, 5 (2019), 2224--2236.","journal-title":"IEEE Transactions on Dependable and Secure Computing"}],"event":{"name":"ICSE '24: IEEE\/ACM 46th International Conference on Software Engineering","location":"Lisbon Portugal","acronym":"ICSE '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639202","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3597503.3639202","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:49:13Z","timestamp":1750286953000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3597503.3639202"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,12]]},"references-count":76,"alternative-id":["10.1145\/3597503.3639202","10.1145\/3597503"],"URL":"https:\/\/doi.org\/10.1145\/3597503.3639202","relation":{},"subject":[],"published":{"date-parts":[[2024,4,12]]},"assertion":[{"value":"2024-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}