{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:31:39Z","timestamp":1783096299584,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":72,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Cyber Security Cooperative Research Centre"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,15]]},"DOI":"10.1145\/3643991.3644919","type":"proceedings-article","created":{"date-parts":[[2024,7,2]],"date-time":"2024-07-02T13:05:13Z","timestamp":1719925513000},"page":"716-727","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Are Latent Vulnerabilities Hidden Gems for Software Vulnerability Prediction? An Empirical Study"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1935-037X","authenticated-orcid":false,"given":"Triet Huynh Minh","family":"Le","sequence":"first","affiliation":[{"name":"School of Computer Science, The University of Adelaide, Adelaide, South Australia, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3728-9541","authenticated-orcid":false,"given":"Xiaoning","family":"Du","sequence":"additional","affiliation":[{"name":"Monash University, Melbourne, Victoria, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9696-3626","authenticated-orcid":false,"given":"M. Ali","family":"Babar","sequence":"additional","affiliation":[{"name":"School of Computer Science, The University of Adelaide, Adelaide, South Australia, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,7,2]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. The Chromium project. https:\/\/github.com\/chromium\/chromium"},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. Issue of missing links to vulnerability fixing commits in the ReVeal dataset. https:\/\/github.com\/VulDetProject\/ReVeal\/issues\/13"},{"key":"e_1_3_2_1_3_1","unstructured":"[n. d.]. The video formats of the FFmpeg project. https:\/\/ffmpeg.org\/ffmpeg-formats.html"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3125270"},{"key":"e_1_3_2_1_5_1","volume-title":"Mansooreh Zahedi, and Muhammad Ali Babar.","author":"Arani Ali Kazemi","year":"2023","unstructured":"Ali Kazemi Arani, Triet Huynh Minh Le, Mansooreh Zahedi, and Muhammad Ali Babar. 2023. Systematic Literature Review on Application of Machine Learning in Continuous Integration. arXiv preprint arXiv:2305.12695 (2023)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/AIOps59134.2023.00006"},{"key":"e_1_3_2_1_7_1","unstructured":"Authors. [n. d.]. Reproduction package. https:\/\/github.com\/lhmtriet\/Latent-Vulnerability"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-021-10072-8"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510113"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3544558"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340482.3342742"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635880"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1191\/1478088706qp063oa"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528482"},{"key":"e_1_3_2_1_15_1","volume-title":"Deep learning based vulnerability detection: Are we there yet","author":"Chakraborty Saikat","year":"2021","unstructured":"Saikat Chakraborty, Rahul Krishna, Yangruibo Ding, and Baishakhi Ray. 2021. Deep learning based vulnerability detection: Are we there yet. IEEE Transactions on Software Engineering (2021)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.2009.2015974"},{"key":"e_1_3_2_1_17_1","volume-title":"Sampling techniques","author":"Cochran William G","unstructured":"William G Cochran. 2007. Sampling techniques. John Wiley & Sons."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 19th International Conference on Mining Software Repositories. 435--447","author":"Croft Roland","unstructured":"Roland Croft, M. Ali Babar, and Huaming Chen. 2022. Noisy label learning for security defects. In Proceedings of the 19th International Conference on Mining Software Repositories. 435--447."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00022"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3171202"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2016.2616306"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC53464.2021.00016"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2929761"},{"key":"e_1_3_2_1_25_1","volume-title":"Codebert: A pre-trained model for programming and natural languages. arXiv preprint arXiv:2002.08155","author":"Feng Zhangyin","year":"2020","unstructured":"Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, Daxin Jiang, et al. 2020. Codebert: A pre-trained model for programming and natural languages. arXiv preprint arXiv:2002.08155 (2020)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528452"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3092566"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103009"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00123"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-021-10092-4"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2019.00016"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2982385"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR52588.2021.00055"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2006.23"},{"key":"e_1_3_2_1_36_1","volume-title":"Towards an improved understanding of software vulnerability assessment using data-driven approaches. arXiv preprint arXiv:2207.11708","author":"Triet HM Le.","year":"2022","unstructured":"Triet HM Le. 2022. Towards an improved understanding of software vulnerability assessment using data-driven approaches. arXiv preprint arXiv:2207.11708 (2022)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3383458"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3529757"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 19th International Conference on Mining Software Repositories. 621--633","author":"Minh Le Triet Huynh","year":"2022","unstructured":"Triet Huynh Minh Le and M Ali Babar. 2022. On the use of fine-grained vulnerable code statements for software vulnerability assessment models. In Proceedings of the 19th International Conference on Mining Software Repositories. 621--633."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Triet Huynh Minh Le Roland Croft David Hin and Muhammad Ali Babar. 2021. A large-scale study of security vulnerability support on developer q&a websites. In Evaluation and assessment in software engineering. 109--118.","DOI":"10.1145\/3463274.3463331"},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 17th International Conference on Mining Software Repositories. 350--361","author":"Minh Le Triet Huynh","year":"2020","unstructured":"Triet Huynh Minh Le, David Hin, Roland Croft, and M Ali Babar. 2020. PUMiner: Mining security posts from developer question and answer websites with PU learning. In Proceedings of the 17th International Conference on Mining Software Repositories. 350--361."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678622"},{"key":"e_1_3_2_1_43_1","volume-title":"2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). IEEE, 371--382","author":"Minh Le Triet Huynh","year":"2019","unstructured":"Triet Huynh Minh Le, Bushra Sabir, and Muhammad Ali Babar. 2019. Automated software vulnerability assessment with concept drift. In 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). IEEE, 371--382."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468597"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2993293"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W54100.2022.00032"},{"key":"e_1_3_2_1_48_1","volume-title":"Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692","author":"Liu Yinhan","year":"2019","unstructured":"Yinhan Liu, Myle Ott, Naman Goyal, Jingfei Du, Mandar Joshi, Danqi Chen, Omer Levy, Mike Lewis, Luke Zettlemoyer, and Veselin Stoyanov. 2019. Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692 (2019)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2022.111283"},{"key":"e_1_3_2_1_50_1","volume-title":"Interrater reliability: The kappa statistic. Biochemia medica 22, 3","author":"McHugh Mary L","year":"2012","unstructured":"Mary L McHugh. 2012. Interrater reliability: The kappa statistic. Biochemia medica 22, 3 (2012), 276--282."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2013.19"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2004.1265817"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330225"},{"key":"e_1_3_2_1_54_1","volume-title":"Deep domain adaptation for vulnerable code function identification. In 2019 international joint conference on neural networks (IJCNN)","author":"Nguyen Van","unstructured":"Van Nguyen, Trung Le, Tue Le, Khanh Nguyen, Olivier DeVel, Paul Montague, Lizhen Qu, and Dinh Phung. 2019. Deep domain adaptation for vulnerable code function identification. In 2019 international joint conference on neural networks (IJCNN). IEEE, 1--8."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER53432.2022.00018"},{"key":"e_1_3_2_1_56_1","unstructured":"NIST. [n. d.]. National Vulnerability Database. https:\/\/nvd.nist.gov"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2012.6224298"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00124"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813604"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106552"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10168-9"},{"key":"e_1_3_2_1_62_1","unstructured":"SecurityScorecard. [n. d.]. CVE Details Vulnerability Database. https:\/\/www.cvedetails.com"},{"key":"e_1_3_2_1_63_1","volume-title":"When do changes induce fixes? ACM sigsoft software engineering notes 30, 4","author":"\u015aliwerski Jacek","year":"2005","unstructured":"Jacek \u015aliwerski, Thomas Zimmermann, and Andreas Zeller. 2005. When do changes induce fixes? ACM sigsoft software engineering notes 30, 4 (2005), 1--5."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00188"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227176"},{"key":"e_1_3_2_1_66_1","first-page":"19","article-title":"The need to report effect size estimates revisited. An overview of some recommended measures of effect size","volume":"1","author":"Tomczak Maciej","year":"2014","unstructured":"Maciej Tomczak and Ewa Tomczak. 2014. The need to report effect size estimates revisited. An overview of some recommended measures of effect size. Trends in Sport Sciences 1, 21 (2014), 19--25.","journal-title":"Trends in Sport Sciences"},{"key":"e_1_3_2_1_67_1","volume-title":"Perfect Software and other illusions about testing","author":"Weinberg Gerald M","unstructured":"Gerald M Weinberg. 2008. Perfect Software and other illusions about testing. Dorset House Pub. New York, NY, USA."},{"key":"e_1_3_2_1_68_1","volume-title":"Breakthroughs in Statistics","author":"Wilcoxon Frank","unstructured":"Frank Wilcoxon. 1992. Individual comparisons by ranking methods. In Breakthroughs in Statistics. Springer, 196--202."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2017.8254428"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00020"},{"key":"e_1_3_2_1_71_1","volume-title":"Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in neural information processing systems 32","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jingkai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_72_1","volume-title":"Data augmentation approaches for source code models: A survey. arXiv preprint arXiv:2305.19915","author":"Zhuo Terry Yue","year":"2023","unstructured":"Terry Yue Zhuo, Zhou Yang, Zhensu Sun, Yufei Wang, Li Li, Xiaoning Du, Zhenchang Xing, and David Lo. 2023. Data augmentation approaches for source code models: A survey. arXiv preprint arXiv:2305.19915 (2023)."}],"event":{"name":"MSR '24: 21st International Conference on Mining Software Repositories","location":"Lisbon Portugal","acronym":"MSR '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS"]},"container-title":["Proceedings of the 21st International Conference on Mining Software Repositories"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643991.3644919","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3643991.3644919","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:56:44Z","timestamp":1750291004000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643991.3644919"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,15]]},"references-count":72,"alternative-id":["10.1145\/3643991.3644919","10.1145\/3643991"],"URL":"https:\/\/doi.org\/10.1145\/3643991.3644919","relation":{},"subject":[],"published":{"date-parts":[[2024,4,15]]},"assertion":[{"value":"2024-07-02","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}