{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T12:50:46Z","timestamp":1785243046145,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":84,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,10,24]],"date-time":"2024-10-24T00:00:00Z","timestamp":1729728000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Cyber Security Cooperative Research Centre"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,10,24]]},"DOI":"10.1145\/3674805.3686675","type":"proceedings-article","created":{"date-parts":[[2024,10,15]],"date-time":"2024-10-15T18:39:24Z","timestamp":1729017564000},"page":"131-142","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Automatic Data Labeling for Software Vulnerability Prediction Models: How Far Are We?"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1935-037X","authenticated-orcid":false,"given":"Triet Huynh Minh","family":"Le","sequence":"first","affiliation":[{"name":"CREST - the Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9696-3626","authenticated-orcid":false,"given":"Muhammad Ali","family":"Babar","sequence":"additional","affiliation":[{"name":"CREST - the Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,10,24]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Mansooreh Zahedi, and M\u00a0Ali Babar.","author":"Arani Ali\u00a0Kazemi","year":"2024","unstructured":"Ali\u00a0Kazemi Arani, Triet Huynh\u00a0Minh Le, Mansooreh Zahedi, and M\u00a0Ali Babar. 2024. Systematic literature review on application of learning-based approaches in continuous integration. IEEE Access (2024)."},{"key":"e_1_3_2_1_2_1","unstructured":"Authors. [n. d.]. Reproduction package. https:\/\/github.com\/lhmtriet\/AutoVul"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3475960.3475985"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00051"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1191\/1478088706qp063oa"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3511560"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387461"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3192419"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534371"},{"key":"e_1_3_2_1_11_1","volume-title":"Sampling techniques","author":"Cochran G","unstructured":"William\u00a0G Cochran. 2007. Sampling techniques. John Wiley & Sons."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 19th International Conference on Mining Software Repositories. 435\u2013447","author":"Croft Roland","unstructured":"Roland Croft, M.\u00a0Ali Babar, and Huaming Chen. 2022. Noisy label learning for security defects. In Proceedings of the 19th International Conference on Mining Software Repositories. 435\u2013447."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00022"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3475716.3475781"},{"key":"e_1_3_2_1_15_1","volume-title":"Data preparation for software vulnerability prediction: A systematic literature review","author":"Croft Roland","year":"2022","unstructured":"Roland Croft, Yongzheng Xie, and Muhammad\u00a0Ali Babar. 2022. Data preparation for software vulnerability prediction: A systematic literature review. IEEE Transactions on Software Engineering (2022)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2347736.2347755"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC53464.2021.00016"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1002\/smr.2381"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"e_1_3_2_1_21_1","unstructured":"FIRST. [n. d.]. Common vulnerability scoring system. https:\/\/www.first.org\/cvss\/specification-document"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528452"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10197-4"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3092566"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN55064.2022.9892280"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103009"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2013.6624018"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3527949"},{"key":"e_1_3_2_1_29_1","unstructured":"IBM. [n. d.]. Commit message analyzer of D2A. https:\/\/github.com\/IBM\/D2A\/blob\/3f7570a50c62c9058b41e9d706805cb4ac28b8cd\/scripts\/infer_pipeline\/commit_msg_analyzer\/msg_analyzer.py"},{"key":"e_1_3_2_1_30_1","unstructured":"IBM. [n. d.]. D2A benchmarking data. https:\/\/ibm.github.io\/D2A\/"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338941"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2013.6606613"},{"key":"e_1_3_2_1_33_1","volume-title":"An empirical evaluation of the usefulness of word embedding techniques in deep learning-based vulnerability prediction. Security in Computer and Information Sciences","author":"Kalouptsoglou Ilias","year":"2021","unstructured":"Ilias Kalouptsoglou, Miltiadis Siavvas, Dionysios Kehagias, Alexandros Chatzigeorgiou, and Apostolos Ampatzoglou. 2021. An empirical evaluation of the usefulness of word embedding techniques in deep learning-based vulnerability prediction. Security in Computer and Information Sciences (2021), 23."},{"key":"e_1_3_2_1_34_1","first-page":"3146","article-title":"Lightgbm: A highly efficient gradient boosting decision tree","volume":"30","author":"Ke Guolin","year":"2017","unstructured":"Guolin Ke, Qi Meng, Thomas Finley, Taifeng Wang, Wei Chen, Weidong Ma, Qiwei Ye, and Tie-Yan Liu. 2017. Lightgbm: A highly efficient gradient boosting decision tree. Advances in Neural Information Processing Systems 30 (2017), 3146\u20133154.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1985793.1985859"},{"key":"e_1_3_2_1_36_1","volume-title":"International Conference on Machine Learning. PMLR, 1188\u20131196","author":"Le Quoc","year":"2014","unstructured":"Quoc Le and Tomas Mikolov. 2014. Distributed representations of sentences and documents. In International Conference on Machine Learning. PMLR, 1188\u20131196."},{"key":"e_1_3_2_1_37_1","volume-title":"Towards an improved understanding of software vulnerability assessment using data-driven approaches. arXiv preprint arXiv:2207.11708","author":"HM Le.","year":"2022","unstructured":"Triet\u00a0HM Le. 2022. Towards an improved understanding of software vulnerability assessment using data-driven approaches. arXiv preprint arXiv:2207.11708 (2022)."},{"key":"e_1_3_2_1_38_1","volume-title":"Mitigating data imbalance for software vulnerability assessment: Does data augmentation help?arXiv preprint arXiv:2407.10722","author":"Le HM","year":"2024","unstructured":"Triet\u00a0HM Le and M\u00a0Ali Babar. 2024. Mitigating data imbalance for software vulnerability assessment: Does data augmentation help?arXiv preprint arXiv:2407.10722 (2024)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3529757"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 19th International Conference on Mining Software Repositories. 621\u2013633","author":"Huynh\u00a0Minh Le Triet","year":"2022","unstructured":"Triet Huynh\u00a0Minh Le and M\u00a0Ali Babar. 2022. On the use of fine-grained vulnerable code statements for software vulnerability assessment models. In Proceedings of the 19th International Conference on Mining Software Repositories. 621\u2013633."},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering. 679\u2013685","author":"Huynh\u00a0Minh Le Triet","year":"2024","unstructured":"Triet Huynh\u00a0Minh Le, M\u00a0Ali Babar, and Tung\u00a0Hoang Thai. 2024. Software vulnerability prediction in low-resource languages: An empirical study of codebert and chatgpt. In Proceedings of the 28th International Conference on Evaluation and Assessment in Software Engineering. 679\u2013685."},{"key":"e_1_3_2_1_42_1","first-page":"1","article-title":"Deep learning for source code modeling and generation: Models, applications, and challenges","volume":"53","author":"Huynh\u00a0Minh Le Triet","year":"2020","unstructured":"Triet Huynh\u00a0Minh Le, Hao Chen, and M\u00a0Ali Babar. 2020. Deep learning for source code modeling and generation: Models, applications, and challenges. ACM Computing Surveys (CSUR) 53, 3 (2020), 1\u201338.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the 25th International Conference on Evaluation and Assessment in Software Engineering. 109\u2013118","author":"Huynh\u00a0Minh Le Triet","year":"2021","unstructured":"Triet Huynh\u00a0Minh Le, Roland Croft, David Hin, and Muhammad\u00a0Ali Babar. 2021. A large-scale study of security vulnerability support on developer q&a websites. In Proceedings of the 25th International Conference on Evaluation and Assessment in Software Engineering. 109\u2013118."},{"key":"e_1_3_2_1_44_1","volume-title":"2024 IEEE\/ACM 21st International Conference on Mining Software Repositories (MSR). IEEE, 716\u2013727","author":"Huynh\u00a0Minh Le Triet","year":"2024","unstructured":"Triet Huynh\u00a0Minh Le, Xiaoning Du, and M\u00a0Ali Babar. 2024. Are latent vulnerabilities hidden gems for software vulnerability prediction? An empirical study. In 2024 IEEE\/ACM 21st International Conference on Mining Software Repositories (MSR). IEEE, 716\u2013727."},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 17th International Conference on Mining Software Repositories. 350\u2013361","author":"Huynh\u00a0Minh Le Triet","year":"2020","unstructured":"Triet Huynh\u00a0Minh Le, David Hin, Roland Croft, and M\u00a0Ali Babar. 2020. PUMiner: Mining security posts from developer question and answer websites with PU learning. In Proceedings of the 17th International Conference on Mining Software Repositories. 350\u2013361."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678622"},{"key":"e_1_3_2_1_47_1","volume-title":"2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). 371\u2013382","author":"Huynh\u00a0Minh Le Triet","year":"2019","unstructured":"Triet Huynh\u00a0Minh Le, Bushra Sabir, and Muhammad\u00a0Ali Babar. 2019. Automated software vulnerability assessment with concept drift. In 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR). 371\u2013382."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468597"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W54100.2022.00032"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2019.02.023"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2013.19"},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the 26th International Conference on Neural Information Processing Systems -","volume":"2","author":"Mikolov Tomas","year":"2013","unstructured":"Tomas Mikolov, Ilya Sutskever, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013. Distributed representations of words and phrases and their compositionality. In Proceedings of the 26th International Conference on Neural Information Processing Systems - Volume 2. 3111\u20133119."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2746194.2746198"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315311"},{"key":"e_1_3_2_1_55_1","volume-title":"Triet Huynh\u00a0Minh Le, and M.\u00a0Ali Babar","author":"Nguyen Anh\u00a0The","year":"2024","unstructured":"Anh\u00a0The Nguyen, Triet Huynh\u00a0Minh Le, and M.\u00a0Ali Babar. 2024. Automated code-centric software vulnerability assessment: How far are we? An empirical study in C\/C++. arXiv preprint arXiv:2407.17053 (2024)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER53432.2022.00018"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473122"},{"key":"e_1_3_2_1_58_1","unstructured":"NIST. [n. d.]. Infer static analyzer. https:\/\/fbinfer.com\/"},{"key":"e_1_3_2_1_59_1","unstructured":"NIST. [n. d.]. Juliet test suite. https:\/\/samate.nist.gov\/SARD\/testsuite.php"},{"key":"e_1_3_2_1_60_1","unstructured":"NIST. [n. d.]. Log4Shell vulnerability on NVD. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-44228"},{"key":"e_1_3_2_1_61_1","unstructured":"NIST. [n. d.]. National Vulnerability Database. https:\/\/nvd.nist.gov\/"},{"key":"e_1_3_2_1_62_1","volume-title":"d.]. Vulnerabilities reported on NVD","author":"NIST.","year":"2022","unstructured":"NIST. [n. d.]. Vulnerabilities reported on NVD in 2022. https:\/\/nvd.nist.gov\/vuln\/search\/statistics?form_type=Basic&results_type=statistics&search_type=all&isCpeNameSearch=false"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549128"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1613\/jair.1.12125"},{"key":"e_1_3_2_1_65_1","unstructured":"Stack Overflow. [n. d.]. Favorite programming languages in practice. https:\/\/survey.stackoverflow.co\/2022\/#most-loved-dreaded-and-wanted-language-love-dread"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3533378"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2021.106665"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/2597073.2597117"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME.2018.00058"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-022-10168-9"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2340398"},{"key":"e_1_3_2_1_73_1","volume-title":"Can traditional fault prediction models be used for vulnerability prediction?Empirical Software Engineering 18, 1","author":"Shin Yonghee","year":"2013","unstructured":"Yonghee Shin and Laurie Williams. 2013. Can traditional fault prediction models be used for vulnerability prediction?Empirical Software Engineering 18, 1 (2013), 25\u201359."},{"key":"e_1_3_2_1_74_1","volume-title":"HGVul: A code vulnerability detection method based on heterogeneous source-level intermediate representation. Security and Communication Networks 2022","author":"Song Zihua","year":"2022","unstructured":"Zihua Song, Junfeng Wang, Shengli Liu, Zhiyang Fang, and Kaiyuan Yang. 2022. HGVul: A code vulnerability detection method based on heterogeneous source-level intermediate representation. Security and Communication Networks 2022 (2022)."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.09.039"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00188"},{"key":"e_1_3_2_1_77_1","unstructured":"Inc. Synopsys. [n. d.]. Heartbleed bug. https:\/\/heartbleed.com\/"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2019.106204"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227176"},{"key":"e_1_3_2_1_80_1","first-page":"19","article-title":"The need to report effect size estimates revisited. An overview of some recommended measures of effect size","volume":"1","author":"Tomczak Maciej","year":"2014","unstructured":"Maciej Tomczak and Ewa Tomczak. 2014. The need to report effect size estimates revisited. An overview of some recommended measures of effect size. Trends in Sport Sciences 1, 21 (2014), 19\u201325.","journal-title":"Trends in Sport Sciences"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.3023177"},{"key":"e_1_3_2_1_82_1","volume-title":"Breakthroughs in Statistics","author":"Wilcoxon Frank","unstructured":"Frank Wilcoxon. 1992. Individual comparisons by ranking methods. In Breakthroughs in Statistics. Springer, 196\u2013202."},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00020"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3117771"}],"event":{"name":"ESEM '24: ACM \/ IEEE International Symposium on Empirical Software Engineering and Measurement","location":"Barcelona Spain","acronym":"ESEM '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 18th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3674805.3686675","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3674805.3686675","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T12:55:53Z","timestamp":1755867353000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3674805.3686675"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,24]]},"references-count":84,"alternative-id":["10.1145\/3674805.3686675","10.1145\/3674805"],"URL":"https:\/\/doi.org\/10.1145\/3674805.3686675","relation":{},"subject":[],"published":{"date-parts":[[2024,10,24]]},"assertion":[{"value":"2024-10-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}