{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T02:44:15Z","timestamp":1784342655693,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["623B2006"],"award-info":[{"award-number":["623B2006"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["92464301"],"award-info":[{"award-number":["92464301"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,23]]},"DOI":"10.1145\/3696630.3728551","type":"proceedings-article","created":{"date-parts":[[2025,7,28]],"date-time":"2025-07-28T19:09:27Z","timestamp":1753729767000},"page":"262-273","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Efficient and Robust Security-Patch Localization for Disclosed OSS Vulnerabilities with Fine-Tuned LLMs in an Industrial Setting"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7916-255X","authenticated-orcid":false,"given":"Dezhi","family":"Ran","sequence":"first","affiliation":[{"name":"Key Lab of HCST (PKU), MOE; SCS, Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1572-6640","authenticated-orcid":false,"given":"Lin","family":"Li","sequence":"additional","affiliation":[{"name":"Huawei Cloud Computing Technologies Co., Ltd., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-2794-9987","authenticated-orcid":false,"given":"Liuchuan","family":"Zhu","sequence":"additional","affiliation":[{"name":"Huawei Cloud Computing Technologies Co., Ltd., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-6970-1833","authenticated-orcid":false,"given":"Yuan","family":"Cao","sequence":"additional","affiliation":[{"name":"Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1263-3996","authenticated-orcid":false,"given":"Landelong","family":"Zhao","sequence":"additional","affiliation":[{"name":"Huawei Cloud Computing Technologies Co., Ltd., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-9018-0386","authenticated-orcid":false,"given":"Xin","family":"Tan","sequence":"additional","affiliation":[{"name":"Huawei Cloud Computing Technologies Co., Ltd., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-2454-1706","authenticated-orcid":false,"given":"Guangtai","family":"Liang","sequence":"additional","affiliation":[{"name":"Huawei Technologies Co., Ltd, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6598-0041","authenticated-orcid":false,"given":"Qianxiang","family":"Wang","sequence":"additional","affiliation":[{"name":"Huawei Technologies Co., Ltd, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6731-216X","authenticated-orcid":false,"given":"Tao","family":"Xie","sequence":"additional","affiliation":[{"name":"Key Lab of HCST (PKU), MOE; SCS, Peking University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,7,28]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Premkumar Devanbu, and Earl T. Barr.","author":"Ahmed Toufique","year":"2024","unstructured":"Toufique Ahmed, Kunal Suresh Pai, Premkumar Devanbu, and Earl T. Barr. 2024. Automatic semantic augmentation of language model prompts (for code summarization). arXiv:2304.06815"},{"key":"e_1_3_2_1_2_1","volume-title":"Diego Elias Costa, and Emad Shihab","author":"Alfadel Mahmoud","year":"2023","unstructured":"Mahmoud Alfadel, Diego Elias Costa, and Emad Shihab. 2023. Empirical analysis of security vulnerabilities in Python packages. Empirical Software Engineering (2023)."},{"key":"e_1_3_2_1_3_1","volume-title":"Brian C Van Esesn, Abdul A S. Awwal, and Vijayan K. Asari.","author":"Alom Md Zahangir","year":"2018","unstructured":"Md Zahangir Alom, Tarek M. Taha, Christopher Yakopcic, Stefan Westberg, Paheding Sidike, Mst Shamima Nasrin, Brian C Van Esesn, Abdul A S. Awwal, and Vijayan K. Asari. 2018. The history began from AlexNet: A comprehensive survey on deep learning approaches. arXiv:1803.01164"},{"key":"e_1_3_2_1_4_1","unstructured":"Shamil Ayupov and Nadezhda Chirkova. 2022. Parameter-efficient finetuning of transformers for source code. arXiv:2212.05901"},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering.","author":"Bhandari Guru","year":"2021","unstructured":"Guru Bhandari, Amara Naseer, and Leon Moonen. 2021. CVEfixes: Automated collection of vulnerabilities and their fixes from open-source software. In Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering."},{"key":"e_1_3_2_1_6_1","volume-title":"Considerations and challenges for the adoption of open source components in software-intensive businesses. Journal of Systems and Software","author":"Butler Simon","year":"2022","unstructured":"Simon Butler, Jonas Gamalielsson, Bj\u00f6rn Lundell, Christoffer Brax, Anders Mattsson, Tomas Gustavsson, Jonas Feist, Bengt Kvarnstr\u00f6m, and Erik L\u00f6nroth. 2022. Considerations and challenges for the adoption of open source components in software-intensive businesses. Journal of Systems and Software (2022)."},{"key":"e_1_3_2_1_7_1","volume-title":"Jared Kaplan, Harri Edwards, and et al.","author":"Chen Mark","year":"2021","unstructured":"Mark Chen, Jerry Tworek, Heewoo Jun, Qiming Yuan, Henrique Ponde de Oliveira Pinto, Jared Kaplan, Harri Edwards, and et al. 2021. Evaluating large language models trained on code. arXiv:2107.03374"},{"key":"e_1_3_2_1_8_1","unstructured":"Gobinda Chowdhury. 2010. Introduction to Modern Information Retrieval."},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis.","author":"Deng Yinlin","year":"2023","unstructured":"Yinlin Deng, Chunqiu Steven Xia, Haoran Peng, Chenyuan Yang, and Lingming Zhang. 2023. Large language models are zero-shot fuzzers: Fuzzing deep-learning libraries via large language models. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis."},{"key":"e_1_3_2_1_10_1","volume-title":"Software security patch management - a systematic literature review of challenges, approaches, tools and practices. Information and Software Technology","author":"Dissanayake Nesara","year":"2022","unstructured":"Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, and M. Ali Babar. 2022. Software security patch management - a systematic literature review of challenges, approaches, tools and practices. Information and Software Technology (2022)."},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the 28th USENIX Security Symposium.","author":"Dong Ying","year":"2019","unstructured":"Ying Dong, Wenbo Guo, Yueqi Chen, Xinyu Xing, Yuqing Zhang, and Gang Wang. 2019. Towards the detection of inconsistencies in public security vulnerability reports. In Proceedings of the 28th USENIX Security Symposium."},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security.","author":"Dunlap Trevor","year":"2024","unstructured":"Trevor Dunlap, Elizabeth Lin, William Enck, and Bradley Reaves. 2024. VFCFinder: Pairing security advisories and patches. In Proceedings of the 19th ACM Asia Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_13_1","volume-title":"Djamel Eddine Khelladi, and Benoit Combemale","author":"D\u00f6derlein Jean-Baptiste","year":"2023","unstructured":"Jean-Baptiste D\u00f6derlein, Mathieu Acher, Djamel Eddine Khelladi, and Benoit Combemale. 2023. Piloting Copilot and Codex: Hot temperature, cold prompts, or black magic? arXiv:2210.14699"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 2022 Workshop Meas., Attacks, Defenses Web.","author":"Everson Douglas","year":"2022","unstructured":"Douglas Everson, Long Cheng, and Zhenkai Zhang. 2022. Log4shell: Redefining the web attack surface. In Proceedings of the 2022 Workshop Meas., Attacks, Defenses Web."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Mingyang Geng Shangwen Wang Dezun Dong Haotian Wang Ge Li Zhi Jin Xiaoguang Mao and Xiangke Liao. 2023. Large language models are few-shot summarizers: Multi-intent comment generation via in-context learning. arXiv:2304.11384","DOI":"10.1145\/3597503.3608134"},{"key":"e_1_3_2_1_16_1","unstructured":"GitHub. 2025. GitHub REST API documentation. https:\/\/docs.github.com\/en\/rest?apiVersion=2022-11-28"},{"key":"e_1_3_2_1_17_1","unstructured":"Daya Guo Qihao Zhu Dejian Yang Zhenda Xie and et al. 2024. DeepSeek-Coder: When the large language model meets programming - the rise of code intelligence. arXiv:2401.14196"},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security.","author":"He Jingxuan","year":"2023","unstructured":"Jingxuan He and Martin Vechev. 2023. Large language models for code: security hardening and adversarial testing. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_19_1","volume-title":"Large language models for software engineering: A systematic literature review. ACM Transactions on Software Engineering and Methodology","author":"Hou Xinyi","year":"2024","unstructured":"Xinyi Hou, Yanjie Zhao, Yue Liu, Zhou Yang, Kailong Wang, Li Li, Xiapu Luo, David Lo, John Grundy, and Haoyu Wang. 2024. Large language models for software engineering: A systematic literature review. ACM Transactions on Software Engineering and Methodology (2024)."},{"key":"e_1_3_2_1_20_1","unstructured":"Neil Houlsby Andrei Giurgiu Stanislaw Jastrzebski Bruna Morrone Quentin de Laroussilhe Andrea Gesmundo Mona Attariyan and Sylvain Gelly. 2019. Parameter-efficient transfer learning for NLP. arXiv:1902.00751"},{"key":"e_1_3_2_1_21_1","unstructured":"Edward J. Hu Yelong Shen Phillip Wallis Zeyuan Allen-Zhu Yuanzhi Li Shean Wang Lu Wang and Weizhu Chen. 2021. LoRA: Low-Rank Adaptation of Large Language Models. arXiv:2106.09685"},{"key":"e_1_3_2_1_22_1","unstructured":"Huawei. 2025. Corporation information of Huawei. https:\/\/www.huawei.com\/en\/corporate-information"},{"key":"e_1_3_2_1_23_1","unstructured":"Huawei. 2025. Huawei CodeArts Inspector. https:\/\/www.huaweicloud.com\/product\/vss.html"},{"key":"e_1_3_2_1_24_1","unstructured":"Ziwei Ji Nayeon Lee Rita Frieske Tiezheng Yu and et al. 2023. Survey of hallucination in natural language generation. Comput. Surveys (2023)."},{"key":"e_1_3_2_1_25_1","unstructured":"Shuyang Jiang Yuhao Wang and Yu Wang. 2023. SelfEvolve: A code evolution framework via large language models. arXiv:2306.02907"},{"key":"e_1_3_2_1_26_1","unstructured":"Haolin Jin Linghan Huang Haipeng Cai Jun Yan Bo Li and Huaming Chen. 2025. From LLMs to LLM-based agents for software engineering: a survey of current challenges and future. arXiv:2408.02479"},{"key":"e_1_3_2_1_27_1","unstructured":"Jean Kaddour Joshua Harris Maximilian Mozes Herbie Bradley Roberta Raileanu and Robert McHardy. 2023. Challenges and applications of large language models. arXiv:2307.10169"},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 2014 International Conference on Learning Representations","author":"Kingma Diederik","year":"2014","unstructured":"Diederik Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. In Proceedings of the 2014 International Conference on Learning Representations (2014)."},{"key":"e_1_3_2_1_29_1","volume-title":"Joseph E. Gonzalez, Hao Zhang, and Ion Stoica.","author":"Kwon Woosuk","year":"2023","unstructured":"Woosuk Kwon, Zhuohan Li, Siyuan Zhuang, Ying Sheng, Lianmin Zheng, Cody Hao Yu, Joseph E. Gonzalez, Hao Zhang, and Ion Stoica. 2023. Efficient memory management for large language model serving with PagedAttention. arXiv:2309.06180"},{"key":"e_1_3_2_1_30_1","volume-title":"An effective prompting technique specialized in code generation. ACM Transactions on Software Engineering and Methodology","author":"Li Jia","year":"2024","unstructured":"Jia Li, Yunfei Zhao, Yongmin Li, Ge Li, and Zhi Jin. 2024. AceCoder : An effective prompting technique specialized in code generation. ACM Transactions on Software Engineering and Methodology (2024)."},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis. 590\u2013602","author":"Li Kaixuan","year":"2024","unstructured":"Kaixuan Li, Jian Zhang, Sen Chen, Han Liu, Yang Liu, and Yixiang Chen. 2024. PatchFinder: A two-phase approach to security patch tracing for disclosed vulnerabilities in open-source software. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis. 590\u2013602."},{"key":"e_1_3_2_1_32_1","volume-title":"Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering.","author":"Li Zhiyu","unstructured":"Zhiyu Li, Shuai Lu, Daya Guo, Nan Duan, Shailesh Jannu, and et al. 2022. Automating code review activities by large-scale pre-training. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering."},{"key":"e_1_3_2_1_33_1","volume-title":"Vulnerabilities and security patches detection in OSS: A survey. Comput. Surveys","author":"Lin Ruyan","year":"2024","unstructured":"Ruyan Lin, Yulong Fu, Wei Yi, Jincheng Yang, Jin Cao, Zhiqiang Dong, Fei Xie, and Hui Li. 2024. Vulnerabilities and security patches detection in OSS: A survey. Comput. Surveys (2024)."},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of the 2022 Neural Information Processing Systems.","author":"Liu Haokun","year":"2022","unstructured":"Haokun Liu, Derek Tam, Muqeeth Mohammed, Jay Mohta, Tenghao Huang, Mohit Bansal, and Colin Raffel. 2022. Few-shot parameter-efficient fine-tuning is better and cheaper than in-context learning. In Proceedings of the 2022 Neural Information Processing Systems."},{"key":"e_1_3_2_1_35_1","volume-title":"prompt, and predict: A systematic survey of prompting methods in natural language processing. ACM Computing Surveys Home","author":"Liu Pengfei","year":"2023","unstructured":"Pengfei Liu, Weizhe Yuan, Jinlan Fu, Zhengbao Jiang, Hiroaki Hayashi, and Graham Neubig. 2023. Pre-train, prompt, and predict: A systematic survey of prompting methods in natural language processing. ACM Computing Surveys Home (2023)."},{"key":"e_1_3_2_1_36_1","unstructured":"Xueqing Liu Jiangrui Zheng Guanqun Yang Siyan Wen and Qiushi Liu. 2025. Improving the context length and efficiency of code retrieval for tracing security vulnerability fixes. arXiv:2503.22935"},{"key":"e_1_3_2_1_37_1","volume-title":"Proceddings of the 2023 IEEE 34th International Symposium on Software Reliability Engineering.","author":"Lu Junyi","year":"2023","unstructured":"Junyi Lu, Lei Yu, Xiaojia Li, Li Yang, and Chun Zuo. 2023. LLaMA-reviewer: Advancing code review automation with large language models through parameter-efficient fine-tuning. In Proceddings of the 2023 IEEE 34th International Symposium on Software Reliability Engineering."},{"key":"e_1_3_2_1_38_1","volume-title":"Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering.","author":"Nguyen Truong Giang","year":"2022","unstructured":"Truong Giang Nguyen, Thanh Le-Cong, Hong Jin Kang, Xuan-Bach D. Le, and David Lo. 2022. VulCurator: a vulnerability-fixing commit detector. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering."},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering.","author":"Nguyen-Truong Giang","year":"2022","unstructured":"Giang Nguyen-Truong, Hong Jin Kang, David Lo, Abhishek Sharma, Andrew E. Santosa, Asankhaya Sharma, and Ming Yi Ang. 2022. HERMES: Using commit-Issue linking to detect vulnerability-fixing commits. In Proceedings of the 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering."},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis.","author":"Ran Dezhi","year":"2024","unstructured":"Dezhi Ran, Hao Wang, Zihe Song, Mengzhou Wu, Yuan Cao, Ying Zhang, Wei Yang, and Tao Xie. 2024. Guardian: A runtime framework for LLM-based UI exploration. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis."},{"key":"e_1_3_2_1_41_1","volume-title":"An infrastructure software perspective toward computation offloading between executable specifications and foundation models. Science China Information Sciences","author":"Ran Dezhi","year":"2025","unstructured":"Dezhi Ran, Mengzhou Wu, Yuan Cao, Assaf Marron, David Harel, and Tao Xie. 2025. An infrastructure software perspective toward computation offloading between executable specifications and foundation models. Science China Information Sciences (2025)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Dezhi Ran Mengzhou Wu Wei Yang and Tao Xie. 2025. Foundation model engineering: Engineering foundation models just as engineering software. ACM Trans. Softw. Eng. Methodol. (2025).","DOI":"10.1145\/3719005"},{"key":"e_1_3_2_1_43_1","unstructured":"Dezhi Ran Mengzhou Wu Hao Yu Yuetong Li Jun Ren Yuan Cao and et al. 2025. Beyond pass or fail: Multi-dimensional benchmarking of foundation models for goal-based mobile UI navigation. arXiv:2501.02863"},{"key":"e_1_3_2_1_44_1","volume-title":"Code Llama: Open foundation models for code. arXiv:2308.12950","author":"Rozi\u00e8re Baptiste","year":"2024","unstructured":"Baptiste Rozi\u00e8re, Jonas Gehring, Fabian Gloeckle, and Sten Sootla et al. 2024. Code Llama: Open foundation models for code. arXiv:2308.12950"},{"key":"e_1_3_2_1_45_1","volume-title":"Utilization of pre-trained language models for adapter-based knowledge transfer in software engineering. Empirical Software Engineering","author":"Saberi Iman","year":"2024","unstructured":"Iman Saberi, Fatemeh Fard, and Fuxiang Chen. 2024. Utilization of pre-trained language models for adapter-based knowledge transfer in software engineering. Empirical Software Engineering (2024)."},{"key":"e_1_3_2_1_46_1","volume-title":"An empirical evaluation of using large language models for automated unit test generation","author":"Sch\u00e4fer Max","year":"2023","unstructured":"Max Sch\u00e4fer, Sarah Nadi, Aryaz Eghbali, and Frank Tip. 2023. An empirical evaluation of using large language models for automated unit test generation. IEEE Transactions on Software Engineering 1 (2023)."},{"key":"e_1_3_2_1_47_1","unstructured":"SecurityScorecard. 2025. Number of CVEs per year. https:\/\/www.cvedetails.com\/browse-by-date.php."},{"key":"e_1_3_2_1_48_1","volume-title":"An overview of deep learning architecture of deep neural networks and autoencoders. Journal of Computational and Theoretical Nanoscience","author":"Sewak Mohit","year":"2020","unstructured":"Mohit Sewak, Sanjay Sahay, and Hemant Rathore. 2020. An overview of deep learning architecture of deep neural networks and autoencoders. Journal of Computational and Theoretical Nanoscience (2020)."},{"key":"e_1_3_2_1_49_1","unstructured":"Jiho Shin Clark Tang Tahmineh Mohati Maleknaz Nayebi Song Wang and Hadi Hemmati. 2023. Prompt engineering or fine tuning: An empirical assessment of large language models in automated software engineering tasks. arXiv:2310.10508"},{"key":"e_1_3_2_1_50_1","volume-title":"Organizational adoption of open source software. Journal of systems and software","author":"Spinellis Diomidis","year":"2012","unstructured":"Diomidis Spinellis and Vaggelis Giannikas. 2012. Organizational adoption of open source software. Journal of systems and software (2012)."},{"key":"e_1_3_2_1_51_1","volume-title":"Proceedings of the ACM Web Conference","author":"Tan Xin","year":"2022","unstructured":"Xin Tan, Yuan Zhang, Jiajun Cao, Kun Sun, Mi Zhang, and Min Yang. [n. d.]. Understanding the practice of security patch management across multiple branches in OSS projects. In Proceedings of the ACM Web Conference 2022."},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security.","author":"Tan Xin","year":"2021","unstructured":"Xin Tan, Yuan Zhang, Chenyuan Mi, Jiajun Cao, Kun Sun, Yifan Lin, and Min Yang. 2021. Locating the security patches for disclosed OSS vulnerabilities with vulnerability-commit correlation ranking. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_53_1","volume-title":"Hashimoto","author":"Taori Rohan","year":"2023","unstructured":"Rohan Taori, Ishaan Gulrajani, Tianyi Zhang, Yann Dubois, Xuechen Li, Carlos Guestrin, Percy Liang, and Tatsunori B. Hashimoto. 2023. Stanford Alpaca: An instruction-following LLaMA model. https:\/\/github.com\/tatsu-lab\/stanford_alpaca."},{"key":"e_1_3_2_1_54_1","unstructured":"Meta-Llama Team. 2024. Introducing Llama 3.1: Our most capable models to date. https:\/\/ai.meta.com\/blog\/meta-llama-3-1\/"},{"key":"e_1_3_2_1_55_1","unstructured":"Qwen Team. 2024. Qwen2.5: A party of foundation models. https:\/\/qwenlm.github.io\/blog\/qwen2.5\/"},{"key":"e_1_3_2_1_56_1","volume-title":"Common vulnerabilities and exposures","author":"Vulnerabilities Common","year":"2005","unstructured":"Common Vulnerabilities. 2005. Common vulnerabilities and exposures. The MITRE Corporation (2005)."},{"key":"e_1_3_2_1_57_1","volume-title":"Proceedings of the 45th International Conference on Software Engineering.","author":"Wang Deze","year":"2023","unstructured":"Deze Wang, Boxing Chen, Shanshan Li, Wei Luo, Shaoliang Peng, Wei Dong, and Xiangke Liao. 2023. One adapter for all programming languages? Adapter tuning for code search and summarization. In Proceedings of the 45th International Conference on Software Engineering."},{"key":"e_1_3_2_1_58_1","volume-title":"Proceedings of the 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering.","author":"Wang Shichao","year":"2022","unstructured":"Shichao Wang, Yun Zhang, Liagfeng Bao, Xin Xia, and Minghui Wu. 2022. VC-Match: A ranking-based approach for automatic security patches localization for OSS vulnerabilities. In Proceedings of the 2022 IEEE International Conference on Software Analysis, Evolution and Reengineering."},{"key":"e_1_3_2_1_59_1","unstructured":"Mengzhou Wu Hao Wang Jun Ren Yuan Cao Yuetong Li Alex Jiang Dezhi Ran Yitao Hu Wei Yang and Tao Xie. 2024. Skill-adpative imitation learning for UI test reuse. arXiv:2409.13311"},{"key":"e_1_3_2_1_60_1","unstructured":"An Yang Baosong Yang Beichen Zhang Binyuan Hui and et al. 2025. Qwen2.5 technical report. arXiv:2412.15115"},{"key":"e_1_3_2_1_61_1","volume-title":"Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering.","author":"Yu Hao","year":"2024","unstructured":"Hao Yu, Bo Shen, Dezhi Ran, Jiaxin Zhang, Qi Zhang, Yuchi Ma, Guangtai Liang, Ying Li, Qianxiang Wang, and Tao Xie. 2024. CoderEval: A benchmark of pragmatic code generation with generative pre-trained models. In Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering."},{"key":"e_1_3_2_1_62_1","unstructured":"Tong Yu and Hong Zhu. 2020. Hyper-parameter optimization: A review of algorithms and applications. arXiv:2003.05689"},{"key":"e_1_3_2_1_63_1","volume-title":"Proceedings of the 2024 IEEE International Conference on Software Analysis, Evolution and Reengineering.","author":"Zhang Junwei","year":"2024","unstructured":"Junwei Zhang, Xing Hu, Lingfeng Bao, Xin Xia, and Shanping Li. 2024. Dual prompt-based few-shot learning for automated vulnerability patch localization. In Proceedings of the 2024 IEEE International Conference on Software Analysis, Evolution and Reengineering."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"crossref","unstructured":"Lyuye Zhang Chengwei Liu Sen Chen Zhengzi Xu and et al. 2023. Mitigating persistence of open-source vulnerabilities in Maven ecosystem. arXiv:2308.03419","DOI":"10.1109\/ASE56229.2023.00058"},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the 38th Annual Conference on Neural Information Processing Systems.","author":"Zheng Lianmin","year":"2024","unstructured":"Lianmin Zheng, Liangsheng Yin, Zhiqiang Xie, Chuyue Sun, Jeff Huang, Cody Hao Yu, Shiyi Cao, Christos Kozyrakis, Ion Stoica, Joseph E. Gonzalez, Clark Barrett, and Ying Sheng. 2024. SGLang: Efficient execution of structured language model programs. In Proceedings of the 38th Annual Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_1_66_1","volume-title":"Proceedings of the 37th Conference on Neural Information Processing Systems.","author":"Zhou Chunting","unstructured":"Chunting Zhou, Pengfei Liu, Puxin Xu, Srini Iyer, Jiao Sun, and et al. 2023. LIMA: Less is more for alignment. In Proceedings of the 37th Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_1_67_1","volume-title":"Experimental evaluation of parameter-efficient fine-tuning for software rngineering tasks. ACM Transactions on Software Engineering and Methodology","author":"Zou Wentao","year":"2025","unstructured":"Wentao Zou, Zongwen Shen, Qi Li, Jidong Ge, Chuanyi Li, Xiang Chen, Xiaoyu Shen, LiGuo Huang, and Bin Luo. 2025. Experimental evaluation of parameter-efficient fine-tuning for software rngineering tasks. ACM Transactions on Software Engineering and Methodology (2025)."}],"event":{"name":"FSE Companion '25: 33rd ACM International Conference on the Foundations of Software Engineering","location":"Clarion Hotel Trondheim Trondheim Norway","acronym":"FSE Companion '25","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3696630.3728551","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,28]],"date-time":"2025-07-28T19:11:13Z","timestamp":1753729873000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3696630.3728551"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,23]]},"references-count":67,"alternative-id":["10.1145\/3696630.3728551","10.1145\/3696630"],"URL":"https:\/\/doi.org\/10.1145\/3696630.3728551","relation":{},"subject":[],"published":{"date-parts":[[2025,6,23]]},"assertion":[{"value":"2025-07-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}