{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:06:17Z","timestamp":1784131577202,"version":"3.55.0"},"reference-count":212,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2025,5,26]],"date-time":"2025-05-26T00:00:00Z","timestamp":1748217600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100031478","name":"NextGenerationEU","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100031478","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Italian Ministry of the University and Research MUR","award":["D53D23017310001"],"award-info":[{"award-number":["D53D23017310001"]}]},{"DOI":"10.13039\/100010663","name":"H2020 European Research Council","doi-asserted-by":"crossref","award":["819141"],"award-info":[{"award-number":["819141"]}],"id":[{"id":"10.13039\/100010663","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2025,6,30]]},"abstract":"<jats:p>As our lives, our businesses, and indeed our world economy become increasingly reliant on the secure operation of many interconnected software systems, the software engineering research community is faced with unprecedented research challenges, but also with exciting new opportunities. In this roadmap article, we outline our vision of software security analysis for the systems of the future. Given the recent advances in generative AI, we need new methods to assess and maximize the security of code co-written by machines. As our systems become increasingly heterogeneous, we need practical approaches that work even if some functions are automatically generated, e.g., by deep neural networks. As software systems depend evermore on the software supply chain, we need tools that scale to an entire ecosystem. What kind of vulnerabilities exist in future systems and how do we detect them? When all the shallow bugs are found, how do we discover vulnerabilities hidden deeply in the system? Assuming we cannot find all security flaws, how can we nevertheless protect our system? To answer these questions, we start our roadmap with a survey of recent advances in software security, then discuss open challenges and opportunities, and conclude with a long-term perspective for the field.<\/jats:p>","DOI":"10.1145\/3708533","type":"journal-article","created":{"date-parts":[[2024,12,19]],"date-time":"2024-12-19T14:32:54Z","timestamp":1734618774000},"page":"1-26","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Software Security Analysis in 2030 and Beyond: A Research Roadmap"],"prefix":"10.1145","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4470-1824","authenticated-orcid":false,"given":"Marcel","family":"B\u00f6hme","sequence":"first","affiliation":[{"name":"Max Planck Institute for Security and Privacy, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3470-3647","authenticated-orcid":false,"given":"Eric","family":"Bodden","sequence":"additional","affiliation":[{"name":"Faculty of Electrical Engineering Computer Science and Mathematics, Department of Computer Science, Software Engineering Group, Paderborn University, Paderborn, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2993-1215","authenticated-orcid":false,"given":"Tevfik","family":"Bultan","sequence":"additional","affiliation":[{"name":"University of California at Santa Barbara, Santa Barbara, California, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3599-7264","authenticated-orcid":false,"given":"Cristian","family":"Cadar","sequence":"additional","affiliation":[{"name":"Department of Computing, Imperial College London, United Kingdom of Great Britain and Northern Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0024-7508","authenticated-orcid":false,"given":"Giuseppe","family":"Scanniello","sequence":"additional","affiliation":[{"name":"Department of Informatics, University of Salerno, Fisciano, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,5,26]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Synopsis. What is software supply chain security and how does it Work?\u2014synopsys. Retrieved March 04 2024 from https:\/\/www.synopsys.com\/glossary\/what-is-software-supply-chain-security.html"},{"key":"e_1_3_2_3_2","unstructured":"Google. 2024. Best practices for dependency management\u2014Google Cloud blog. Retrieved March 14 2024 from https:\/\/cloud.google.com\/blog\/topics\/developers-practitioners\/best-practices-dependency-management"},{"key":"e_1_3_2_4_2","unstructured":"Github. 2024. Dependabot. Retrieved March 14 2024 from https:\/\/github.com\/dependabot"},{"key":"e_1_3_2_5_2","unstructured":"Sigstore. 2024. Home. Sigstore. Retrieved March 14 2024 from https:\/\/www.sigstore.dev\/"},{"key":"e_1_3_2_6_2","unstructured":"NIST. 2024. Nvd - Swid. Retrieved March 15 2024 from https:\/\/nvd.nist.gov\/products\/swid"},{"key":"e_1_3_2_7_2","unstructured":"OpenSSF. 2024. Ossf\/criticality \\(\\_\\) score: Gives criticality score for an open source project. Retrieved March 14 2024 from https:\/\/github.com\/ossf\/criticality_score"},{"key":"e_1_3_2_8_2","unstructured":"OpenSSF. 2024. Ossf\/package-manager-best-practices: Collection of security best practices for package managers. Retrieved March 14 2024 from https:\/\/github.com\/ossf\/package-manager-best-practices\/tree\/main"},{"key":"e_1_3_2_9_2","unstructured":"OpenSSF. 2024. Ossf\/scorecard: OpenSSF scorecard - security health metrics for open source. Retrieved March 14 2024 from https:\/\/github.com\/ossf\/scorecard"},{"key":"e_1_3_2_10_2","unstructured":"OWASP. 2024. OWASP CycloneDX software bill of materials (SBOM) standard. Retrieved March 15 2024 from https:\/\/cyclonedx.org\/"},{"key":"e_1_3_2_11_2","unstructured":"OWASP. 2024. OWASP dependency-Check\u2014OWASP foundation. Retrieved March 14 2024 from https:\/\/owasp.org\/www-project-dependency-check\/"},{"key":"e_1_3_2_12_2","unstructured":"NIST. 2024. Secure software development framework\u2014CSRC. Retrieved March 14 2024 from https:\/\/csrc.nist.gov\/projects\/ssdf"},{"key":"e_1_3_2_13_2","unstructured":"Linux Foundation. 2024. SLSA supply-chain levels for software artifacts. Retrieved March 14 2024 from https:\/\/slsa.dev\/"},{"key":"e_1_3_2_14_2","unstructured":"Linux Foundation. 2024. SPDX \u2013 Linux foundation projects site. Retrieved March 15 2024 from https:\/\/spdx.dev\/"},{"key":"e_1_3_2_15_2","unstructured":"Cloud Native Computing Foundation. 2024. SPIFFE \u2013 secure production identity framework for everyone. Retrieved March 14 2024 from https:\/\/spiffe.io\/"},{"issue":"1","key":"e_1_3_2_16_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1609956.1609960","article-title":"Control-flow integrity principles, implementations, and applications","volume":"13","author":"Abadi Mart\u00edn","year":"2009","unstructured":"Mart\u00edn Abadi, Mihai Budiu, Ulfar Erlingsson, and Jay Ligatti. 2009. Control-flow integrity principles, implementations, and applications. ACM Transactions on Information and System Security 13, 1 (2009), 1\u201340.","journal-title":"ACM Transactions on Information and System Security"},{"key":"e_1_3_2_17_2","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1109\/SP.2008.30","volume-title":"Proceedings of the 2008 IEEE Symposium on Security and Privacy (SP 2008)","author":"Akritidis Periklis","year":"2008","unstructured":"Periklis Akritidis, Cristian Cadar, Costin Raiciu, Manuel Costa, and Miguel Castro. 2008. Preventing memory error exploits with WIT. In Proceedings of the 2008 IEEE Symposium on Security and Privacy (SP 2008). IEEE, 263\u2013277."},{"key":"e_1_3_2_18_2","unstructured":"aleak. 2017. Another misconfigured Amazon S3 server leaks data of 50 000 Australians. Retrieved from https:\/\/www.scmagazineuk.com\/another-misconfigured-amazon -s3-server-leaks-data-of-50000-australians\/article\/705125\/"},{"key":"e_1_3_2_19_2","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1145\/2610384.2610401","volume-title":"Proceedings of the 2014 International Symposium on Software Testing and Analysis","author":"Alkhalaf Muath","year":"2014","unstructured":"Muath Alkhalaf, Abdulbaki Aydin, and Tevfik Bultan. 2014. Semantic differential repair for input validation and sanitization. In Proceedings of the 2014 International Symposium on Software Testing and Analysis, 225\u2013236."},{"key":"e_1_3_2_20_2","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/s10664-014-9352-6","article-title":"Empirical assessment of machine learning-based malware detectors for Android: Measuring the gap between in-the-lab and in-the-wild validation scenarios","volume":"21","author":"Allix Kevin","year":"2016","unstructured":"Kevin Allix, Tegawend\u00e9 F. Bissyand\u00e9, Quentin J\u00e9rome, Jacques Klein, Radu State, and Yves Le Traon. 2016. Empirical assessment of machine learning-based malware detectors for Android: Measuring the gap between in-the-lab and in-the-wild validation scenarios. Empirical Software Engineering 21 (2016), 183\u2013211.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_21_2","first-page":"271","volume-title":"Proceedings of the Conference on International Computing Education Research","author":"Almansoori Majed","year":"2020","unstructured":"Majed Almansoori, Jessica Lam, Elias Fang, Kieran Mulligan, Adalbert Gerald Soosai Raj, and Rahul Chatterjee. 2020. How secure are our computer systems courses?. In Proceedings of the Conference on International Computing Education Research. ACM, 271\u2013281."},{"key":"e_1_3_2_22_2","volume-title":"Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201922)","author":"Andronidis Anastasios","year":"2022","unstructured":"Anastasios Andronidis and Cristian Cadar. 2022. SnapFuzz: High-throughput fuzzing of network applications. In Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201922)."},{"key":"e_1_3_2_23_2","volume-title":"Proceedings of the USENIX Security Symposium","author":"Arp Daniel","year":"2022","unstructured":"Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, and Konrad Rieck. 2022. Dos and don\u2019ts of machine learning in computer security. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_3_2_24_2","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1145\/2568225.2568243","volume-title":"Proceedings of the 36th International Conference on Software Engineering","author":"Arzt Steven","year":"2014","unstructured":"Steven Arzt and Eric Bodden. 2014. Reviser: Efficiently updating IDE-\/IFDS-based data-flow analyses in response to incremental program changes. In Proceedings of the 36th International Conference on Software Engineering, 288\u2013298."},{"issue":"6","key":"e_1_3_2_25_2","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1007\/s10664-023-10380-1","article-title":"Is github\u2019s copilot as bad as humans at introducing vulnerabilities in code?","volume":"28","author":"Asare Owura","year":"2023","unstructured":"Owura Asare, Meiyappan Nagappan, and N. Asokan. 2023. Is github\u2019s copilot as bad as humans at introducing vulnerabilities in code? Empirical Software Engineering 28, 6 (2023), 129.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_26_2","unstructured":"azureflaw. 2021. Microsoft Azure Cloud vulnerability is the \u2018Worst you Can imagine\u2019. Retrieved from https:\/\/www.theverge.com\/2021\/8\/27\/22644161\/microsoft-azure-database-vulnerabilty-chaosdb?fbclid=IwAR2nKV8uslH4EGDslnogYT4ulQRGz7NsD0xuIb3lgK2sP1-WG_O1tJbR-eE"},{"key":"e_1_3_2_27_2","first-page":"1","volume-title":"Proceedings of the 18th Conference on Formal Methods in Computer-Aided Design (FMCAD \u201918)","author":"Backes John","year":"2018","unstructured":"John Backes, Pauline Bolignano, Byron Cook, Catherine Dodge, Andrew Gacek, Kasper Luckow, Neha Rungta, Oksana Tkachu, and Carsten Varming. 2018. Semantic-based automated reasoning for AWS access policies using SMT. In Proceedings of the 18th Conference on Formal Methods in Computer-Aided Design (FMCAD \u201918), 1\u20139."},{"key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1109\/SP.2009.18","volume-title":"Proceedings of the 30th IEEE Symposium on Security and Privacy (S & P 2009)","author":"Backes Michael","year":"2009","unstructured":"Michael Backes, Boris K\u00f6pf, and Andrey Rybalchenko. 2009. Automatic discovery and quantification of information leaks. In Proceedings of the 30th IEEE Symposium on Security and Privacy (S & P 2009), 141\u2013153."},{"issue":"4","key":"e_1_3_2_29_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3585004","article-title":"Modern code reviews\u2013survey of literature and practice","volume":"32","author":"Badampudi Deepika","year":"2023","unstructured":"Deepika Badampudi, Michael Unterkalmsteiner, and Ricardo Britto. 2023. Modern code reviews\u2013survey of literature and practice. ACM Transactions on Software Engineering and Methodology 32, 4 (2023), 1\u201361.","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"issue":"3","key":"e_1_3_2_30_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3182657","article-title":"A survey of symbolic execution techniques","volume":"51","author":"Baldoni Roberto","year":"2018","unstructured":"Roberto Baldoni, Emilio Coppa, Daniele Cono D\u2019elia, Camil Demetrescu, and Irene Finocchi. 2018. A survey of symbolic execution techniques. ACM Computing Surveys 51, 3 (2018), 1\u201339.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"387","DOI":"10.1109\/SP.2008.22","volume-title":"Proceedings of the 2008 IEEE Symposium on Security and Privacy (SP \u201908).","author":"Balzarotti Davide","year":"2008","unstructured":"Davide Balzarotti, Marco Cova, Vika Felmetsger, Nenad Jovanovic, Engin Kirda, Christopher Kruegel, and Giovanni Vigna. 2008. Saner: Composing static and dynamic analysis to validate sanitization in web applications. In Proceedings of the 2008 IEEE Symposium on Security and Privacy (SP \u201908). IEEE, 387\u2013401."},{"key":"e_1_3_2_32_2","first-page":"2352","volume-title":"Proceedings of the 44th International Conference on Software Engineering","author":"Bao Lingfeng","year":"2022","unstructured":"Lingfeng Bao, Xin Xia, Ahmed E. Hassan, and Xiaohu Yang. 2022. V-SZZ: Automatic identification of version ranges affected by CVE vulnerabilities. In Proceedings of the 44th International Conference on Software Engineering, 2352\u20132364."},{"issue":"15","key":"e_1_3_2_33_2","doi-asserted-by":"crossref","first-page":"4719","DOI":"10.1080\/00207543.2017.1402140","article-title":"Internet of things and supply chain management: A literature review","volume":"57","author":"Ben-Daya Mohamed","year":"2019","unstructured":"Mohamed Ben-Daya, Elkafi Hassini, and Zied Bahroun. 2019. Internet of things and supply chain management: A literature review. International Journal of Production Research 57, 15\u201316 (2019), 4719\u20134742.","journal-title":"International Journal of Production Research"},{"key":"e_1_3_2_34_2","first-page":"5","volume-title":"Proceedings of the 44th International Conference on Software Engineering (ICSE \u201922)","author":"B\u00f6hme Marcel","year":"2022","unstructured":"Marcel B\u00f6hme. 2022. Statistical reasoning about programs. In Proceedings of the 44th International Conference on Software Engineering (ICSE \u201922), 5 pages. DOI: 10.1145\/3510455.3512796"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2020.3016773"},{"key":"e_1_3_2_36_2","first-page":"2329","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201917)","author":"B\u00f6hme Marcel","year":"2017","unstructured":"Marcel B\u00f6hme, Van-Thuan Pham, Manh-Dung Nguyen, and Abhik Roychoudhury. 2017. Directed greybox fuzzing. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201917), 2329\u20132344."},{"key":"e_1_3_2_37_2","unstructured":"Dillon Bowen Brendan Murphy Will Cai David Khachaturov Adam Gleave and Kellin Pelrine. 2024. Scaling laws for data poisoning in LLMs. arXiv:2408.02946. Retrieved from https:\/\/arxiv.org\/abs\/2408.02946"},{"key":"e_1_3_2_38_2","unstructured":"Sergey Bratus Michael Locasto Meredith Patterson Len Sassaman and Anna Shubina. 2011. From buffer overflows to weird machines and and theory of computation. USENIX; login 13\u201321."},{"key":"e_1_3_2_39_2","doi-asserted-by":"crossref","first-page":"1207","DOI":"10.1109\/SP40000.2020.00007","volume-title":"Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP \u201920)","author":"Brennan Tegan","year":"2020","unstructured":"Tegan Brennan, Nicol\u00e1s Rosner, and Tevfik Bultan. 2020. JIT leaks: Inducing timing side channels through just-in-time compilation. In Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP \u201920). IEEE, 1207\u20131222."},{"key":"e_1_3_2_40_2","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1145\/3368089.3409738","volume-title":"Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Bruce Bobby R.","year":"2020","unstructured":"Bobby R. Bruce, Tianyi Zhang, Jaspreet Arora, Guoqing Harry Xu, and Miryung Kim. 2020. Jshrink: In-depth investigation Into debloating modern Java applications. In Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 135\u2013146."},{"key":"e_1_3_2_41_2","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-68670-7","volume-title":"String Analysis for Software Verification and Security","author":"Bultan Tevfik","year":"2017","unstructured":"Tevfik Bultan, Fang Yu, Muath Alkhalaf, and Abdulbaki Aydin. 2017. String Analysis for Software Verification and Security. Springer."},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1145\/3395363.3397360","volume-title":"Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201920)","author":"Busse Frank","year":"2020","unstructured":"Frank Busse, Martin Nowack, and Cristian Cadar. 2020. Running symbolic execution forever. In Proceedings of the ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201920), 63\u201374."},{"key":"e_1_3_2_43_2","first-page":"209","volume-title":"Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI \u201908)","author":"Cadar Cristian","year":"2008","unstructured":"Cristian Cadar, Daniel Dunbar, and Dawson Engler. 2008. KLEE: Unassisted and automatic generation of high-coverage tests for complex systems programs. In Proceedings of the USENIX Symposium on Operating Systems Design and Implementation (OSDI \u201908), 209\u2013224."},{"key":"e_1_3_2_44_2","first-page":"322","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS \u201906)","author":"Cadar Cristian","year":"2006","unstructured":"Cristian Cadar, Vijay Ganesh, Peter Pawlowski, David Dill, and Dawson Engler. 2006. EXE: Automatically generating inputs of death. In Proceedings of the ACM Conference on Computer and Communications Security (CCS \u201906), 322\u2013335."},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","first-page":"1066","DOI":"10.1145\/1985793.1985995","volume-title":"Proceedings of the 33rd International Conference on Software Engineering","author":"Cadar Cristian","year":"2011","unstructured":"Cristian Cadar, Patrice Godefroid, Sarfraz Khurshid, Corina S. P\u0103s\u0103reanu, Koushik Sen, Nikolai Tillmann, and Willem Visser. 2011. Symbolic execution for software testing in practice: Preliminary assessment. In Proceedings of the 33rd International Conference on Software Engineering, 1066\u20131071."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10009-020-00570-3"},{"key":"e_1_3_2_47_2","unstructured":"Cristian Cadar Lu\u00eds Pina and John Regehr. 2015. Multi-version execution defeats a compiler-bug-based backdoor. Retrieved from https:\/\/ccadar.blogspot.co.uk\/2015\/11\/multi-version-execution-defeats.html"},{"key":"e_1_3_2_48_2","first-page":"39","volume-title":"Proceedings of the 2023 International Conference on Formal Methods in Software Engineering (FormaliSE \u201923)","author":"Cadar Cristian","year":"2023","unstructured":"Cristian Cadar, Daniel Schemmel, and Arindam Sharma. 2023. Patch specifications via product programs. In Proceedings of the 2023 International Conference on Formal Methods in Software Engineering (FormaliSE \u201923), 39\u201343. DOI: 10.1109\/FormaliSE58978.2023.00012"},{"issue":"2","key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1145\/2408776.2408795","article-title":"Symbolic execution for software testing: Three decades later","volume":"56","author":"Cadar Cristian","year":"2013","unstructured":"Cristian Cadar and Koushik Sen. 2013. Symbolic execution for software testing: Three decades later. Communications of the Association for Computing Machinery 56, 2 (2013), 82\u201390.","journal-title":"Communications of the Association for Computing Machinery"},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-3-319-17524-9_1","volume-title":"NASA Formal Methods Symposium","author":"Calcagno Cristiano","year":"2015","unstructured":"Cristiano Calcagno, Dino Distefano, J\u00e9r\u00e9my Dubreil, Dominik Gabi, Pieter Hooimeijer, Martino Luca, Peter O\u2019Hearn, Irene Papakonstantinou, Jim Purbrick, and Dulma Rodriguez. 2015. Moving fast with software verification. In NASA Formal Methods Symposium. Springer, 3\u201311."},{"key":"e_1_3_2_51_2","unstructured":"cancan 2015. ryanb\/cancan GitHub. Retrieved from https:\/\/github.com\/ryanb\/cancan"},{"issue":"5","key":"e_1_3_2_52_2","doi-asserted-by":"crossref","first-page":"1123","DOI":"10.1007\/s10877-023-01013-5","article-title":"The elephant in the room: Cybersecurity in healthcare","volume":"37","author":"Cartwright Anthony James","year":"2023","unstructured":"Anthony James Cartwright. 2023. The elephant in the room: Cybersecurity in healthcare. Journal of Clinical Monitoring and Computing 37, 5 (2023), 1123\u20131132.","journal-title":"Journal of Clinical Monitoring and Computing"},{"key":"e_1_3_2_53_2","article-title":"Deep learning based vulnerability detection: Are we there yet","author":"Chakraborty Saikat","year":"2021","unstructured":"Saikat Chakraborty, Rahul Krishna, Yangruibo Ding, and Baishakhi Ray. 2021. Deep learning based vulnerability detection: Are we there yet. IEEE Transactions on Software Engineering (2021).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3087402"},{"key":"e_1_3_2_55_2","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1145\/3377813.3381360","volume-title":"Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering: Software Engineering in Practice","author":"Chen Yang","year":"2020","unstructured":"Yang Chen, Andrew E. Santosa, Asankhaya Sharma, and David Lo. 2020. Automated identification of libraries from vulnerability data. In Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering: Software Engineering in Practice, 90\u201399."},{"key":"e_1_3_2_56_2","unstructured":"Clang Static Analyzer. [n.d.]. Clang static analyzer. Retrieved from https:\/\/clang-analyzer.llvm.org"},{"key":"e_1_3_2_57_2","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1109\/TSE.1976.233817","article-title":"A system to generate test data and symbolically execute programs","volume":"3","author":"Clarke Lori A.","year":"1976","unstructured":"Lori A. Clarke. 1976. A system to generate test data and symbolically execute programs. IEEE Transactions on Software Engineering 3 (1976), 215\u2013222.","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"6","key":"e_1_3_2_58_2","doi-asserted-by":"crossref","first-page":"1157","DOI":"10.3233\/JCS-2009-0393","article-title":"Hyperproperties","volume":"18","author":"Clarkson Michael R.","year":"2010","unstructured":"Michael R. Clarkson and Fred B. Schneider. 2010. Hyperproperties. Journal of Computer Security 18, 6 (2010), 1157\u20131210.","journal-title":"Journal of Computer Security"},{"key":"e_1_3_2_59_2","doi-asserted-by":"crossref","first-page":"196","DOI":"10.1145\/1273463.1273490","volume-title":"Proceedings of the 2007 International Symposium on Software Testing and Analysis","author":"Clause James","year":"2007","unstructured":"James Clause, Wanchun Li, and Alessandro Orso. 2007. Dytan: A generic dynamic taint analysis framework. In Proceedings of the 2007 International Symposium on Software Testing and Analysis, 196\u2013206."},{"key":"e_1_3_2_60_2","unstructured":"CLion 2024. CLion IDE. Retrieved from https:\/\/www.jetbrains.com\/clion\/"},{"key":"e_1_3_2_61_2","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1145\/3643916.3644416","volume-title":"Proceedings of the 32nd IEEE\/ACM International Conference on Program Comprehension","author":"Cotroneo Domenico","year":"2024","unstructured":"Domenico Cotroneo, Cristina Improta, Pietro Liguori, and Roberto Natella. 2024. Vulnerabilities in AI code generators: Exploring targeted data poisoning attacks. In Proceedings of the 32nd IEEE\/ACM International Conference on Program Comprehension, 280\u2013292."},{"issue":"2","key":"e_1_3_2_62_2","doi-asserted-by":"crossref","first-page":"324","DOI":"10.1145\/234528.234740","article-title":"Abstract interpretation","volume":"28","author":"Cousot Patrick","year":"1996","unstructured":"Patrick Cousot. 1996. Abstract interpretation. ACM Computing Surveys 28, 2 (1996), 324\u2013328.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_63_2","unstructured":"Coverity Software. [n.d.]. Coverity software. Retrieved from http:\/\/www.coverity.com"},{"key":"e_1_3_2_64_2","first-page":"63","volume-title":"USENIX Security Symposium","volume":"98","author":"Cowan Crispan","year":"1998","unstructured":"Crispan Cowan, Calton Pu, Dave Maier, Jonathan Walpole, Peat Bakke, Steve Beattie, Aaron Grier, Perry Wagle, Qian Zhang, and Heather Hinton. 1998. Stackguard: Automatic adaptive detection and prevention of buffer-overflow attacks. In USENIX Security Symposium, Vol. 98, 63\u201378."},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/1323293.1294283"},{"key":"e_1_3_2_66_2","unstructured":"2024. CWE TOP 25 most dangerous software errors. Retrieved from https:\/\/www.sans.org\/top25-software-errors\/"},{"key":"e_1_3_2_67_2","doi-asserted-by":"crossref","first-page":"560","DOI":"10.1109\/MSR52588.2021.00074","volume-title":"Proceedings of the 2021 IEEE\/ACM 18th International Conference on Mining Software Repositories (MSR \u201921).","author":"Dabic Ozren","year":"2021","unstructured":"Ozren Dabic, Emad Aghajani, and Gabriele Bavota. 2021. Sampling projects in github for MSR studies. In Proceedings of the 2021 IEEE\/ACM 18th International Conference on Mining Software Repositories (MSR \u201921). IEEE, 560\u2013564."},{"key":"e_1_3_2_68_2","first-page":"3300","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201921)","author":"Dai Jiarun","year":"2021","unstructured":"Jiarun Dai, Yuan Zhang, Hailong Xu, Haiming Lyu, Zicheng Wu, Xinyu Xing, and Min Yang. 2021. Facilitating vulnerability assessment through PoC migration. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201921). ACM, New York, NY, 3300\u20133317. DOI: 10.1145\/3460120.3484594"},{"issue":"9","key":"e_1_3_2_69_2","doi-asserted-by":"crossref","first-page":"3613","DOI":"10.1109\/TSE.2021.3101739","article-title":"Identifying challenges for OSS vulnerability scanners-a study & test suite","volume":"48","author":"Dann Andreas","year":"2021","unstructured":"Andreas Dann, Henrik Plate, Ben Hermann, Serena Elisa Ponta, and Eric Bodden. 2021. Identifying challenges for OSS vulnerability scanners-a study & test suite. IEEE Transactions on Software Engineering 48, 9 (2021), 3613\u20133625.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_70_2","first-page":"653","volume-title":"Proceedings of the 2016 IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER \u201916)","volume":"1","author":"David Robin","year":"2016","unstructured":"Robin David, S\u00e9bastien Bardin, Thanh Dinh Ta, Laurent Mounier, Josselin Feist, Marie-Laure Potet, and Jean-Yves Marion. 2016. BINSEC\/SE: A dynamic symbolic execution toolkit for binary-level analysis. In Proceedings of the 2016 IEEE 23rd International Conference on Software Analysis, Evolution, and Reengineering (SANER \u201916), Vol. 1. IEEE, 653\u2013656."},{"issue":"9","key":"e_1_3_2_71_2","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1145\/1995376.1995394","article-title":"Satisfiability modulo theories: Introduction and applications","volume":"54","author":"De Moura Leonardo","year":"2011","unstructured":"Leonardo De Moura and Nikolaj Bj\u00f8rner. 2011. Satisfiability modulo theories: Introduction and applications. Communications of the ACM 54, 9 (2011), 69\u201377.","journal-title":"Communications of the ACM"},{"issue":"10","key":"e_1_3_2_72_2","doi-asserted-by":"crossref","first-page":"4087","DOI":"10.1109\/TSE.2021.3112204","article-title":"Back to the past\u2013analysing backporting practices in package dependency networks","volume":"48","author":"Decan Alexandre","year":"2021","unstructured":"Alexandre Decan, Tom Mens, Ahmed Zerouali, and Coen De Roover. 2021. Back to the past\u2013analysing backporting practices in package dependency networks. IEEE Transactions on Software Engineering 48, 10 (2021), 4087\u20134099.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_73_2","doi-asserted-by":"crossref","first-page":"222","DOI":"10.1109\/TSE.1987.232894","article-title":"An intrusion-detection model","volume":"2","author":"Denning Dorothy E.","year":"1987","unstructured":"Dorothy E. Denning. 1987. An intrusion-detection model. IEEE Transactions on Software Engineering 2 (1987), 222\u2013232.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_74_2","unstructured":"djleak. [n.d.]. Cloud Leak: WSJ parent company Dow Jones exposed customer data. Retrieved from https:\/\/www .upguard.com\/breaches\/cloud-leak-dow-jones"},{"key":"e_1_3_2_75_2","unstructured":"Thomas Dullien. 2011. Weird machines exploitability and provable unexploitability. Retrieved from http:\/\/www .dullien.net\/thomas\/weird-machines-exploitability.pdf"},{"key":"e_1_3_2_76_2","first-page":"1805","volume-title":"Proceedings of the 44th IEEE\/ACM 44th International Conference on Software Engineering (ICSE \u201922)","author":"Eiers William","year":"2022","unstructured":"William Eiers, Ganesh Sankaran, Albert Li, Emily O\u2019Mahony, Benjamin Prince, and Tevfik Bultan. 2022. Quantifying permissiveness of access control policies. In Proceedings of the 44th IEEE\/ACM 44th International Conference on Software Engineering (ICSE \u201922). ACM, 1805\u20131817."},{"key":"e_1_3_2_77_2","unstructured":"European Parliament. 2022. Proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending regulation (EU) 2019\/1020. Retrieved from https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex%3A52022PC0454"},{"key":"e_1_3_2_78_2","unstructured":"European Union Agency for Cybersecurity. 2020. Guidelines for securing the Internet of things - ENISA. Retrieved from http:\/\/archive.md\/2023.04.18-071548\/https:\/\/www.enisa.europa.eu\/publications\/guidelines-for-securing-the-internet-of-things\/"},{"issue":"2","key":"e_1_3_2_79_2","doi-asserted-by":"crossref","first-page":"e0228439","DOI":"10.1371\/journal.pone.0228439","article-title":"FastEmbed: Predicting vulnerability exploitation possibility based on ensemble machine learning algorithm","volume":"15","author":"Fang Yong","year":"2020","unstructured":"Yong Fang, Yongcheng Liu, Cheng Huang, and Liang Liu. 2020. FastEmbed: Predicting vulnerability exploitation possibility based on ensemble machine learning algorithm. PLOS One 15, 2 (2020), e0228439.","journal-title":"PLOS One"},{"key":"e_1_3_2_80_2","first-page":"16352","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Feng Shiwei","year":"2023","unstructured":"Shiwei Feng, Guanhong Tao, Siyuan Cheng, Guangyu Shen, Xiangzhe Xu, Yingqi Liu, Kaiyuan Zhang, Shiqing Ma, and Xiangyu Zhang. 2023.Detecting backdoors in pre-trained encoders. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 16352\u201316362."},{"key":"e_1_3_2_81_2","first-page":"196","volume-title":"Proceedings of the 27th International Conference on Software Engineering (ICSE \u201905)","author":"Fisler K.","year":"2005","unstructured":"K. Fisler, S. Krishnamurthi, L. A. Meyerovich, and M. C. Tschantz. 2005. Verification and change-impact analysis of access-control policies. In Proceedings of the 27th International Conference on Software Engineering (ICSE \u201905), 196\u2013205."},{"key":"e_1_3_2_82_2","volume-title":"Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP \u201924)","author":"Fr\u00f6mmgen Alexander","year":"2024","unstructured":"Alexander Fr\u00f6mmgen, Jacob Austin, Peter Choy, Nimesh Ghelani, Lera Kharatyan, Gabriela Surita, Elena Khrapko, Pascal Lamblin, Pierre-Antoine Manzagol, Marcus Revaj, et al. 2024. Resolving code review comments with machine learning. In Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP \u201924)."},{"key":"e_1_3_2_83_2","first-page":"608","volume-title":"Proceedings of the 19th International Conference on Mining Software Repositories","author":"Fu Michael","year":"2022","unstructured":"Michael Fu and Chakkrit Tantithamthavorn. 2022. Linevul: A transformer-based line-level vulnerability prediction. In Proceedings of the 19th International Conference on Mining Software Repositories, 608\u2013620."},{"issue":"6","key":"e_1_3_2_84_2","first-page":"2487","article-title":"Optimizing cloud-based manufacturing: A study on service and development models","volume":"12","author":"Gangadhara Dr Bhargav","year":"2023","unstructured":"Dr Bhargav Gangadhara. 2023. Optimizing cloud-based manufacturing: A study on service and development models. International Journal of Science and Research 12, 6 (2023), 2487\u20132491.","journal-title":"International Journal of Science and Research"},{"key":"e_1_3_2_85_2","first-page":"388","volume-title":"Proceedings of the 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR \u201919).","author":"Gao Jun","year":"2019","unstructured":"Jun Gao, Pingfan Kong, Li Li, Tegawend\u00e9 F. Bissyand\u00e9, and Jacques Klein. 2019. Negative results on mining crypto-Api usage rules in Android Apps. In Proceedings of the 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR \u201919). IEEE, 388\u2013398."},{"key":"e_1_3_2_86_2","unstructured":"GitHub 2024. GitHub website. Retrieved from https:\/\/github.com\/"},{"issue":"3","key":"e_1_3_2_87_2","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1145\/2093548.2093564","article-title":"SAGE: Whitebox fuzzing for security testing","volume":"55","author":"Godefroid Patrice","year":"2012","unstructured":"Patrice Godefroid, Michael Y. Levin, and David Molnar. 2012. SAGE: Whitebox fuzzing for security testing. Communications of the ACM 55, 3 (2012), 40\u201344.","journal-title":"Communications of the ACM"},{"issue":"1","key":"e_1_3_2_88_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3617175","article-title":"Testing restful apis: A survey","volume":"33","author":"Golmohammadi Amid","year":"2023","unstructured":"Amid Golmohammadi, Man Zhang, and Andrea Arcuri. 2023. Testing restful apis: A survey. ACM Transactions on Software Engineering and Methodology 33, 1 (2023), 1\u201341.","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"e_1_3_2_89_2","volume-title":"Proceedings of the 28th IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER \u201921)","author":"Golubev Yaroslav","year":"2021","unstructured":"Yaroslav Golubev, Viktor Poletansky, Nikita Povarov, and Timofey Bryksin. 2021. Multi-threshold token-based code clone detection. In Proceedings of the 28th IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER \u201921)."},{"key":"e_1_3_2_90_2","doi-asserted-by":"crossref","first-page":"1251","DOI":"10.1145\/3357384.3357971","volume-title":"Proceedings of the 28th ACM International Conference on Information and Knowledge Management","author":"Gong Qingyuan","year":"2019","unstructured":"Qingyuan Gong, Jiayun Zhang, Yang Chen, Qi Li, Yu Xiao, Xin Wang, and Pan Hui. 2019. Detecting malicious accounts in online developer communities using deep learning. In Proceedings of the 28th ACM International Conference on Information and Knowledge Management, 1251\u20131260."},{"key":"e_1_3_2_91_2","first-page":"258","volume-title":"Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP \u201921)","author":"Gonzalez Danielle","year":"2021","unstructured":"Danielle Gonzalez, Thomas Zimmermann, Patrice Godefroid, and Max Schaefer. 2021. Anomalicious: Automated detection of anomalous and potentially malicious commits on GitHub. In Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP \u201921), 258\u2013267. DOI: 10.1109\/ICSE-SEIP52600.2021.00035"},{"key":"e_1_3_2_92_2","doi-asserted-by":"crossref","first-page":"735","DOI":"10.1145\/3387940.3392202","volume-title":"Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops","author":"Gonzalez-Barahona Jesus M.","year":"2020","unstructured":"Jesus M. Gonzalez-Barahona. 2020. Characterizing outdateness with technical lag: An exploratory study. In Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops, 735\u2013741."},{"key":"e_1_3_2_93_2","first-page":"1578","volume-title":"Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP \u201923).","author":"Gu Yacong","year":"2023","unstructured":"Yacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu, Huajun Chai, Ruimin Wang, Xing Gao, and Haixin Duan. 2023. Investigating package related security threats in software registries. In Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP \u201923). IEEE, 1578\u20131595."},{"key":"e_1_3_2_94_2","unstructured":"Shangwei Guo Chunlong Xie Jiwei Li Lingjuan Lyu and Tianwei Zhang. 2022. Threats to pre-trained language models: Survey and taxonomy. arXiv:2202.06862. Retrieved from https:\/\/arxiv.org\/abs\/2202.06862"},{"key":"e_1_3_2_95_2","first-page":"166","volume-title":"Proceedings of the 2023 38th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201923).","author":"Guo Wenbo","year":"2023","unstructured":"Wenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang, Yong Fang, and Yang Liu. 2023. An empirical study of malicious code in PyPI ecosystem. In Proceedings of the 2023 38th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201923). IEEE, 166\u2013177."},{"key":"e_1_3_2_96_2","unstructured":"Danny Halawi Alexander Wei Eric Wallace Tony T. Wang Nika Haghtalab and Jacob Steinhardt. 2024. Covert malicious finetuning: Challenges in safeguarding LLM adaptation. arXiv:2406.20053. Retrieved from https:\/\/arxiv.org\/abs\/2406.20053"},{"key":"e_1_3_2_97_2","doi-asserted-by":"crossref","first-page":"107343","DOI":"10.1016\/j.comnet.2020.107343","article-title":"Secure over-the-air software updates in connected vehicles: A survey","volume":"178","author":"Halder Subir","year":"2020","unstructured":"Subir Halder, Amrita Ghosal, and Mauro Conti. 2020. Secure over-the-air software updates in connected vehicles: A survey. Computer Networks 178 (2020), 107343.","journal-title":"Computer Networks"},{"key":"e_1_3_2_98_2","first-page":"72","volume-title":"Proceedings of the 2021 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER \u201921).","author":"He Hao","year":"2021","unstructured":"Hao He, Yulin Xu, Yixiao Ma, Yifei Xu, Guangtai Liang, and Minghui Zhou. 2021. A multi-metric ranking approach for library migration recommendations. In Proceedings of the 2021 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER \u201921). IEEE, 72\u201383."},{"key":"e_1_3_2_99_2","first-page":"612","volume-title":"Proceedings of the International Conference on Software Engineering (ICSE \u201913)","author":"Hosek Petr","year":"2013","unstructured":"Petr Hosek and Cristian Cadar. 2013. Safe software updates via multi-version execution. In Proceedings of the International Conference on Software Engineering (ICSE \u201913), 612\u2013621."},{"key":"e_1_3_2_100_2","unstructured":"Jinchang Hu Lyuye Zhang Chengwei Liu Sen Yang Song Huang and Yang Liu. 2023. Empirical analysis of vulnerabilities life cycle in golang ecosystem. arXiv:2401.00515. Retrieved from https:\/\/arxiv.org\/abs\/2401.00515"},{"issue":"4","key":"e_1_3_2_101_2","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1007\/s10664-022-10131-8","article-title":"Characterizing usages, updates and risks of third-party libraries in Java projects","volume":"27","author":"Huang Kaifeng","year":"2022","unstructured":"Kaifeng Huang, Bihuan Chen, Congying Xu, Ying Wang, Bowen Shi, Xin Peng, Yijian Wu, and Yang Liu. 2022. Characterizing usages, updates and risks of third-party libraries in Java projects. Empirical Software Engineering 27, 4 (2022), 90.","journal-title":"Empirical Software Engineering"},{"issue":"6","key":"e_1_3_2_102_2","doi-asserted-by":"crossref","first-page":"503","DOI":"10.1007\/s10009-008-0087-9","article-title":"Automated verification of access control policies using a SAT solver","volume":"10","author":"Hughes Graham","year":"2008","unstructured":"Graham Hughes and Tevfik Bultan. 2008. Automated verification of access control policies using a SAT solver. Software Tools for Technology Transfer 10, 6 (2008), 503\u2013520.","journal-title":"Software Tools for Technology Transfer"},{"key":"e_1_3_2_103_2","volume-title":"Proceedings of the IEEE 14th International Workshop on Software Clones (IWSC \u201920)","author":"Hung Yu-Liang","year":"2020","unstructured":"Yu-Liang Hung and Shingo Takada. 2020. CPPCD: A token-based approach to detecting potential clones. In Proceedings of the IEEE 14th International Workshop on Software Clones (IWSC \u201920)."},{"key":"e_1_3_2_104_2","unstructured":"IAM. [n.d.]. AWS IAM policy language. Retrieved from http:\/\/docs.aws.amazon.com\/IAM\/latest\/UserGuide\/access_policies.html"},{"key":"e_1_3_2_105_2","first-page":"11","volume-title":"Proceedings of the 15th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM \u201921)","author":"Imtiaz Nasif","year":"2021","unstructured":"Nasif Imtiaz, Seaver Thorn, and Laurie Williams. 2021. A comparative study of vulnerability reporting by software composition analysis tools. In Proceedings of the 15th ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM \u201921). ACM, New York, NY, Article 5, 11 pages. DOI: 10.1145\/3475716.3475769"},{"key":"e_1_3_2_106_2","doi-asserted-by":"crossref","first-page":"1383","DOI":"10.1145\/3597926.3598143","volume-title":"Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201923)","author":"Jiang Ling","year":"2023","unstructured":"Ling Jiang, Hengchen Yuan, Qiyi Tang, Sen Nie, Shi Wu, and Yuqun Zhang. 2023. Third-party library dependency for large-scale SCA in the C\/C++ ecosystem: How far are we?. In Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201923). ACM, New York, NY, 1383\u20131395. DOI: 10.1145\/3597926.3598143"},{"key":"e_1_3_2_107_2","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1145\/3560835.3564547","volume-title":"Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses","author":"Jiang Wenxin","year":"2022","unstructured":"Wenxin Jiang, Nicholas Synovic, Rohan Sethi, Aryan Indarapu, Matt Hyatt, Taylor R. Schorlemmer, George K. Thiruvathukal, and James C. Davis. 2022. An empirical study of artifacts and security risks in the pre-trained model supply chain. In Proceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, 105\u2013114."},{"key":"e_1_3_2_108_2","doi-asserted-by":"crossref","first-page":"432","DOI":"10.1109\/MSR52588.2021.00055","volume-title":"Proceedings of the 2021 IEEE\/ACM 18th International Conference on Mining Software Repositories (MSR \u201921)","author":"Jiarpakdee Jirayus","year":"2021","unstructured":"Jirayus Jiarpakdee, Chakkrit Kla Tantithamthavorn, and John Grundy. 2021. Practitioners\u2019 perceptions of the goals and visual explanations of defect prediction models. In Proceedings of the 2021 IEEE\/ACM 18th International Conference on Mining Software Repositories (MSR \u201921). IEEE, 432\u2013443. DOI: 10.1109\/MSR52588.2021.00055"},{"key":"e_1_3_2_109_2","unstructured":"Joe Biden. 2021. Executive Order on Improving the Nation\u2019s Cybersecurity. Retrieved from https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/"},{"key":"e_1_3_2_110_2","doi-asserted-by":"crossref","first-page":"874","DOI":"10.1145\/3314221.3314610","volume-title":"Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI \u201919)","author":"Kapus Timotej","year":"2019","unstructured":"Timotej Kapus, Oren Ish-Shalom, Shachar Itzhaky, Noam Rinetzky, and Cristian Cadar. 2019. Computing summaries of string loops in C for better testing and refactoring. In Proceedings of the ACM SIGPLAN Conference on Programming Language Design and Implementation (PLDI \u201919), 874\u2013888."},{"issue":"8","key":"e_1_3_2_111_2","doi-asserted-by":"crossref","first-page":"130","DOI":"10.9734\/jerr\/2023\/v25i8965","article-title":"Risk management in medical device industry","volume":"25","author":"Khinvasara Tushar","year":"2023","unstructured":"Tushar Khinvasara, Stephanie Ness, and Nikolaos Tzenios. 2023. Risk management in medical device industry. Journal of Engineering Research and Reports 25, 8 (2023), 130\u2013140.","journal-title":"Journal of Engineering Research and Reports"},{"issue":"7","key":"e_1_3_2_112_2","doi-asserted-by":"crossref","first-page":"385","DOI":"10.1145\/360248.360252","article-title":"Symbolic execution and program testing","volume":"19","author":"King James C.","year":"1976","unstructured":"James C. King. 1976. Symbolic execution and program testing. Communications of the ACM 19, 7 (1976), 385\u2013394.","journal-title":"Communications of the ACM"},{"key":"e_1_3_2_113_2","first-page":"2123","volume-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","author":"Klees George","year":"2018","unstructured":"George Klees, Andrew Ruef, Benji Cooper, Shiyi Wei, and Michael Hicks. 2018. Evaluating fuzz testing. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2123\u20132138."},{"key":"e_1_3_2_114_2","doi-asserted-by":"crossref","first-page":"207","DOI":"10.1145\/1629575.1629596","volume-title":"Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles","author":"Klein Gerwin","year":"2009","unstructured":"Gerwin Klein, Kevin Elphinstone, Gernot Heiser, June Andronick, David Cock, Philip Derrin, Dhammika Elkaduwe, Kai Engelhardt, Rafal Kolanski, Michael Norrish, et al. 2009. seL4: Formal verification of an OS kernel. In Proceedings of the ACM SIGOPS 22nd Symposium on Operating Systems Principles, 207\u2013220."},{"key":"e_1_3_2_115_2","first-page":"25","volume-title":"Proceedings of the 2023 IEEE\/ACM International Workshop on Search-Based and Fuzz Testing (SBFT \u201923)","author":"Klooster Thijs","year":"2023","unstructured":"Thijs Klooster, Fatih Turkmen, Gerben Broenink, Ruben Ten Hove, and Marcel B\u00f6hme. 2023. Continuous fuzzing: A study of the effectiveness and scalability of fuzzing in CI\/CD pipelines. In Proceedings of the 2023 IEEE\/ACM International Workshop on Search-Based and Fuzz Testing (SBFT \u201923), 25\u201332. DOI: 10.1109\/SBFT59156.2023.00015"},{"issue":"5","key":"e_1_3_2_116_2","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MSEC.2023.3287206","article-title":"Why is static application security testing hard to learn?","volume":"21","author":"Krishnan Padmanabhan","year":"2023","unstructured":"Padmanabhan Krishnan, Cristina Cifuentes, Li Li, Tegawend\u00e9 F. Bissyand\u00e9, and Jacques Klein. 2023. Why is static application security testing hard to learn? IEEE Security & Privacy 21, 5 (2023), 68\u201372.","journal-title":"IEEE Security & Privacy"},{"key":"e_1_3_2_117_2","first-page":"1","volume-title":"Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering","author":"Kuchta Tomasz","year":"2022","unstructured":"Tomasz Kuchta and Bartosz Zator. 2022. Auto off-target: Enabling thorough and scalable testing for complex software systems. In Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering, 1\u201312."},{"key":"e_1_3_2_118_2","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1145\/3129743.3129748","volume-title":"the Continuing Arms Race: Code-Reuse Attacks and Defenses","author":"Kuznetzov Volodymyr","year":"2018","unstructured":"Volodymyr Kuznetzov, L\u00e1szl\u00f3 Szekeres, Mathias Payer, George Candea, R. Sekar, and Dawn Song. 2018. Code-pointer integrity. In the Continuing Arms Race: Code-Reuse Attacks and Defenses, 81\u2013116."},{"key":"e_1_3_2_119_2","first-page":"216","volume-title":"11th USENIX Symposium on Operating System Design and Implementation","author":"Le Vu","year":"2014","unstructured":"Vu Le, Mehrdad Afshari, and Zhendong Su. 2014. Compiler validation via equivalence modulo inputs. In 11th USENIX Symposium on Operating System Design and Implementation, 216\u2013226."},{"key":"e_1_3_2_120_2","first-page":"12","volume-title":"Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE \u201923)","author":"Lee Seongmin","year":"2023","unstructured":"Seongmin Lee and Marcel B\u00f6hme. 2023. Statistical reachability analysis. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE \u201923), 12. DOI: 10.1145\/3611643.3616268"},{"key":"e_1_3_2_121_2","volume-title":"Proceedings of the 8th European Congress on Embedded Real Time Software and Systems (ERTS \u201916)","author":"Leroy Xavier","year":"2016","unstructured":"Xavier Leroy, Sandrine Blazy, Daniel K\u00e4stner, Bernhard Schommer, Markus Pister, and Christian Ferdinand. 2016. CompCert - a formally verified optimizing compiler. In Proceedings of the 8th European Congress on Embedded Real Time Software and Systems (ERTS \u201916)."},{"key":"e_1_3_2_122_2","first-page":"609","volume-title":"Proceedings of the 23rd International Conference on Computer Aided Verification (CAV \u201911)","author":"Li Guodong","year":"2011","unstructured":"Guodong Li, Indradeep Ghosh, and Sreeranga P. Rajan. 2011. KLOVER: A symbolic execution and automatic Test generation tool for C++ programs. In Proceedings of the 23rd International Conference on Computer Aided Verification (CAV \u201911). Springer, 609\u2013615."},{"key":"e_1_3_2_123_2","doi-asserted-by":"crossref","first-page":"67","DOI":"10.1016\/j.infsof.2017.04.001","article-title":"Static analysis of Android Apps: A systematic literature review","volume":"88","author":"Li Li","year":"2017","unstructured":"Li Li, Tegawend\u00e9 F Bissyand\u00e9, Mike Papadakis, Siegfried Rasthofer, Alexandre Bartel, Damien Octeau, Jacques Klein, and Le Traon. 2017. Static analysis of Android Apps: A systematic literature review. Information and Software Technology 88 (2017), 67\u201395.","journal-title":"Information and Software Technology"},{"key":"e_1_3_2_124_2","first-page":"335","volume-title":"Proceedings of the 2017 IEEE\/ACM 39th International Conference on Software Engineering (ICSE \u201917).","author":"Li Menghao","year":"2017","unstructured":"Menghao Li, Wei Wang, Pei Wang, Shuai Wang, Dinghao Wu, Jian Liu, Rui Xue, and Wei Huo. 2017. Libd: Scalable and precise third-party library detection in Android markets. In Proceedings of the 2017 IEEE\/ACM 39th International Conference on Software Engineering (ICSE \u201917). IEEE, 335\u2013346."},{"key":"e_1_3_2_125_2","first-page":"2336","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","author":"Li Zongjie","year":"2023","unstructured":"Zongjie Li, Chaozheng Wang, Shuai Wang, and Cuiyun Gao. 2023. Protecting intellectual property of large language model-based code generation apis via watermarks. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2336\u20132350."},{"key":"e_1_3_2_126_2","volume-title":"Network and Distributed Systems Security.","author":"Li Zhen","year":"2018","unstructured":"Zhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin, Sujuan Wang, Zhijun Deng, and Yuyi Zhong. 2018. VulDeePecker: A deep learning-based system for vulnerability detection. In Network and Distributed Systems Security. The Internet Society."},{"key":"e_1_3_2_127_2","unstructured":"LibFuzzer 2022. LibFuzzer website. Retrieved from http:\/\/llvm.org\/docs\/LibFuzzer.html"},{"key":"e_1_3_2_128_2","first-page":"672","volume-title":"Proceedings of the 44th International Conference on Software Engineering","author":"Liu Chengwei","year":"2022","unstructured":"Chengwei Liu, Sen Chen, Lingling Fan, Bihuan Chen, Yang Liu, and Xin Peng. 2022. Demystifying the vulnerability propagation and its evolution via dependency trees in the npm ecosystem. In Proceedings of the 44th International Conference on Software Engineering, 672\u2013684."},{"issue":"12","key":"e_1_3_2_129_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3571156","article-title":"A comprehensive review of the state-of-the-art on security and privacy issues in healthcare","volume":"55","author":"Mart\u00ednez Antonio L\u00f3pez","year":"2023","unstructured":"Antonio L\u00f3pez Mart\u00ednez, Manuel Gil P\u00e9rez, and Antonio Ruiz-Mart\u00ednez. 2023. A comprehensive review of the state-of-the-art on security and privacy issues in healthcare. ACM Computing Surveys 55, 12 (2023), 1\u201338.","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_2_130_2","doi-asserted-by":"crossref","first-page":"925","DOI":"10.1016\/j.cie.2018.11.030","article-title":"A review of Internet of things (IoT) embedded sustainable supply chain for industry 4.0 requirements","volume":"127","author":"Manavalan Ethirajan","year":"2019","unstructured":"Ethirajan Manavalan and Kandasamy Jayakrishna. 2019. A review of Internet of things (IoT) embedded sustainable supply chain for industry 4.0 requirements. Computers & Industrial Engineering 127 (2019), 925\u2013953.","journal-title":"Computers & Industrial Engineering"},{"key":"e_1_3_2_131_2","first-page":"235","volume-title":"European Software Engineering Conference\/ACM SIGSOFT Symposium on the Foundations of Software Engineering (ESEC\/FSE \u201913)","author":"Marinescu Paul Dan","year":"2013","unstructured":"Paul Dan Marinescu and Cristian Cadar. 2013. KATCH: High-coverage testing of software patches. In European Software Engineering Conference\/ACM SIGSOFT Symposium on the Foundations of Software Engineering (ESEC\/FSE \u201913). 235\u2013245."},{"issue":"7","key":"e_1_3_2_132_2","doi-asserted-by":"crossref","first-page":"2547","DOI":"10.1002\/qre.2715","article-title":"Reliability of safety-critical systems: A state-of-the-art review","volume":"36","author":"Maurya Ankur","year":"2020","unstructured":"Ankur Maurya and Divya Kumar. 2020. Reliability of safety-critical systems: A state-of-the-art review. Quality and Reliability Engineering International 36, 7 (2020), 2547\u20132568.","journal-title":"Quality and Reliability Engineering International"},{"key":"e_1_3_2_133_2","first-page":"15","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS \u201924)","author":"Meng Ruijie","year":"2024","unstructured":"Ruijie Meng, Martin Mirchev, Marcel B\u00f6hme, and Abhik Roychoudhury. 2024. Large language model guided protocol fuzzing. In Proceedings of the Network and Distributed System Security Symposium (NDSS \u201924), 15 pages."},{"issue":"10","key":"e_1_3_2_134_2","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1109\/2.161279","article-title":"Applying \u2019Design by contract\u2019","volume":"25","author":"Meyer Bertrand","year":"1992","unstructured":"Bertrand Meyer. 1992. Applying \u2019Design by contract\u2019. IEEE Computer 25, 10 (1992), 40\u201351.","journal-title":"IEEE Computer"},{"key":"e_1_3_2_135_2","unstructured":"Microsoft. [n.d.]. Copilot. Retrieved March 3 2024 from https:\/\/copilot.microsoft.com\/"},{"issue":"24","key":"e_1_3_2_136_2","doi-asserted-by":"crossref","first-page":"7160","DOI":"10.3390\/s20247160","article-title":"Security issues and software updates management in the industrial internet of things (Iiot) era","volume":"20","author":"Mugarza Imanol","year":"2020","unstructured":"Imanol Mugarza, Jose Luis Flores, and Jose Luis Montero. 2020. Security issues and software updates management in the industrial internet of things (Iiot) era. Sensors 20, 24 (2020), 7160.","journal-title":"Sensors"},{"key":"e_1_3_2_137_2","unstructured":"Phil Muncaster. 2021. Global security skills shortage falls to 2.7 million workers - Infosecurity Magazine. Retrieved October 12 2023 from https:\/\/www.infosecurity-magazine.com\/news\/global-security-skills-shortage\/"},{"key":"e_1_3_2_138_2","volume-title":"Proceedings of the 30th International Symposium on Software Testing and Analysis (ISSTA \u201921)","author":"Nielsen Benjamin Barslev","year":"2021","unstructured":"Benjamin Barslev Nielsen, Martin Toldam Torp, and Anders M\u00f8ller. 2021. Modular call graph construction for security scanning of Node.js applications. In Proceedings of the 30th International Symposium on Software Testing and Analysis (ISSTA \u201921)."},{"key":"e_1_3_2_139_2","first-page":"39","volume-title":"Proceedings of International Conference on Software Maintenance and Evolution","author":"Nocera Sabato","year":"2023","unstructured":"Sabato Nocera, Simone Romano, Massimiliano Di Penta, Rita Francese, and Giuseppe Scanniello. 2023. Software bill of materials adoption: A mining study from GitHub. In Proceedings of International Conference on Software Maintenance and Evolution. IEEE, 39\u201349. DOI: 10.1109\/ICSME58846.2023.00016"},{"key":"e_1_3_2_140_2","first-page":"40","volume-title":"Proceedings of the 45th IEEE\/ACM International Conference on Software Engineering: Software Engineering Education and Training (SEET@ICSE \u201923)","author":"Nocera Sabato","year":"2023","unstructured":"Sabato Nocera, Simone Romano, Rita Francese, and Giuseppe Scanniello. 2023. Training for security: Planning the use of a SAT in the development pipeline of web apps. In Proceedings of the 45th IEEE\/ACM International Conference on Software Engineering: Software Engineering Education and Training (SEET@ICSE \u201923), 40\u201345. DOI: 10.1109\/ICSE-SEET58685.2023.00010"},{"key":"e_1_3_2_141_2","first-page":"253","volume-title":"Proceedings of the 46th International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET \u201924)","author":"Nocera Sabato","year":"2024","unstructured":"Sabato Nocera, Simone Romano, Rita Francese, and Giuseppe Scanniello. 2024. Training for security: Results from using a static analysis tool in the development pipeline of web apps. In Proceedings of the 46th International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET \u201924). ACM, New York, NY, 253\u2013263. DOI: 10.1145\/3639474.3640073"},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2020.3011082"},{"key":"e_1_3_2_143_2","unstructured":"OSS-Fuzz. 2024. OSS-Fuzz - continuous fuzzing for open source software. Retrieved from https:\/\/github.com\/google\/oss-fuzz"},{"key":"e_1_3_2_144_2","doi-asserted-by":"crossref","first-page":"398","DOI":"10.1145\/3293882.3339002","volume-title":"Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201919)","author":"Padhye Rohan","year":"2019","unstructured":"Rohan Padhye, Caroline Lemieux, and Koushik Sen. 2019. JQF: Coverage-guided property-based testing in Java. In Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA \u201919), 398\u2013401. DOI: 10.1145\/3293882.3339002"},{"key":"e_1_3_2_145_2","first-page":"1181","volume-title":"Proceedings of the International Conference on Software Engineering (ICSE \u201916)","author":"Palikareva Hristina","year":"2016","unstructured":"Hristina Palikareva, Tomasz Kuchta, and Cristian Cadar. 2016. Shadow of a doubt: Testing for divergences between software versions. In Proceedings of the International Conference on Software Engineering (ICSE \u201916), 1181\u20131192."},{"key":"e_1_3_2_146_2","doi-asserted-by":"crossref","first-page":"102580","DOI":"10.1016\/j.cose.2021.102580","article-title":"Cloud computing security: A survey of service-based models","volume":"114","author":"Parast Fatemeh Khoda","year":"2022","unstructured":"Fatemeh Khoda Parast, Chandni Sindhav, Seema Nikam, Hadiseh Izadi Yekta, Kenneth B. Kent, and Saqib Hakak. 2022. Cloud computing security: A survey of service-based models. Computers & Security 114 (2022), 102580.","journal-title":"Computers & Security"},{"key":"e_1_3_2_147_2","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1145\/1858996.1859035","volume-title":"Proceedings of the 25th IEEE\/ACM International Conference on Automated Software Engineering","author":"P\u0103s\u0103reanu Corina S.","year":"2010","unstructured":"Corina S. P\u0103s\u0103reanu and Neha Rungta. 2010. Symbolic PathFinder: Symbolic execution of Java bytecode. In Proceedings of the 25th IEEE\/ACM International Conference on Automated Software Engineering, 179\u2013180."},{"key":"e_1_3_2_148_2","doi-asserted-by":"crossref","first-page":"1513","DOI":"10.1145\/3372297.3417232","volume-title":"Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security","author":"Pashchenko Ivan","year":"2020","unstructured":"Ivan Pashchenko, Duc-Ly Vu, and Fabio Massacci. 2020. A qualitative study of dependency management and its security implications. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, 1513\u20131531."},{"key":"e_1_3_2_149_2","unstructured":"Pankayaraj Pathmanathan Souradip Chakraborty Xiangyu Liu Yongyuan Liang and Furong Huang. 2024. Is poisoning a real threat to LLM alignment? Maybe more so than you think. arXiv:2406.12091. Retrieved from https:\/\/arxiv.org\/abs\/2406.12091"},{"key":"e_1_3_2_150_2","doi-asserted-by":"crossref","first-page":"331","DOI":"10.1145\/3236024.3236029","volume-title":"Proceedings of the 2018 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Pauck Felix","year":"2018","unstructured":"Felix Pauck, Eric Bodden, and Heike Wehrheim. 2018. Do Android taint analysis tools Keep their promises? In Proceedings of the 2018 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 331\u2013341."},{"key":"e_1_3_2_151_2","doi-asserted-by":"crossref","first-page":"754","DOI":"10.1109\/SP46214.2022.9833571","volume-title":"Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP \u201922).","author":"Pearce Hammond","year":"2022","unstructured":"Hammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt, and Ramesh Karri. 2022. Asleep at the keyboard? Assessing the security of GitHub copilot\u2019s code contributions. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP \u201922). IEEE, 754\u2013768."},{"key":"e_1_3_2_152_2","doi-asserted-by":"crossref","first-page":"754","DOI":"10.1109\/SP46214.2022.9833571","volume-title":"2022 IEEE Symposium on Security and Privacy (SP)","author":"Pearce Hammond","year":"2022","unstructured":"Hammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt, and Ramesh Karri. 2022. Asleep at the keyboard? Assessing the security of github Copilot\u2019S code contributions. In 2022 IEEE Symposium on Security and Privacy (SP). IEEE, 754\u2013768."},{"key":"e_1_3_2_153_2","first-page":"2785","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201923)","author":"Perry Neil","year":"2023","unstructured":"Neil Perry, Megha Srivastava, Deepak Kumar, and Dan Boneh. 2023. Do users write more insecure code with AI assistants?. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS \u201923). ACM, New York, NY, 2785\u20132799. DOI: 10.1145\/3576915.3623157"},{"key":"e_1_3_2_154_2","volume-title":"Elements of Causal Inference: Foundations and Learning Algorithms","author":"Peters Jonas","year":"2017","unstructured":"Jonas Peters, Dominik Janzing, and Bernhard Schlkopf. 2017. Elements of Causal Inference: Foundations and Learning Algorithms. The MIT Press."},{"key":"e_1_3_2_155_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2941681"},{"key":"e_1_3_2_156_2","doi-asserted-by":"crossref","first-page":"328","DOI":"10.1109\/CSF.2017.8","volume-title":"Proceedings of the 30th IEEE Computer Security Foundations Symposium (CSF \u201917)","author":"Phan Quoc-Sang","year":"2017","unstructured":"Quoc-Sang Phan, Lucas Bang, Corina S. Pasareanu, Pasquale Malacaria, and Tevfik Bultan. 2017. Synthesis of adaptive side-channel attacks. In Proceedings of the 30th IEEE Computer Security Foundations Symposium (CSF \u201917). IEEE Computer Society, 328\u2013342."},{"key":"e_1_3_2_157_2","first-page":"573","volume-title":"Proceedings of the International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS \u201919)","author":"Pina Lu\u00eds","year":"2019","unstructured":"Lu\u00eds Pina, Anastasios Andronidis, Michael Hicks, and Cristian Cadar. 2019. Mvedsua: Higher availability dynamic software updates via multi-version execution. In Proceedings of the International Conference on Architectural Support for Programming Languages and Operating Systems (ASPLOS \u201919), 573\u2013585."},{"key":"e_1_3_2_158_2","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1145\/3293882.3330556","volume-title":"Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis","author":"Piskachev Goran","year":"2019","unstructured":"Goran Piskachev, Lisa Nguyen Quang Do, and Eric Bodden. 2019. Codebase-adaptive detection of security-relevant methods. In Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, 181\u2013191."},{"key":"e_1_3_2_159_2","first-page":"24","volume-title":"Proceedings of the 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM \u201921).","author":"Piskachev Goran","year":"2021","unstructured":"Goran Piskachev, Ranjith Krishnamurthy, and Eric Bodden. 2021. Secucheck: Engineering configurable taint analysis for software developers. In Proceedings of the 2021 IEEE 21st International Working Conference on Source Code Analysis and Manipulation (SCAM \u201921). IEEE, 24\u201329."},{"key":"e_1_3_2_160_2","first-page":"181","volume-title":"Proceedings of the 29th USENIX Security Symposium (USENIX Security \u201920)","author":"Poeplau Sebastian","year":"2020","unstructured":"Sebastian Poeplau and Aur\u00e9lien Francillon. 2020. Symbolic execution with SymCC: Don\u2019t interpret, compile!. In Proceedings of the 29th USENIX Security Symposium (USENIX Security \u201920), 181\u2013198."},{"key":"e_1_3_2_161_2","unstructured":"Chromium Project. 2021. Memory safety. Retrieved from https:\/\/www.chromium.org\/Home\/chromium-security\/memory-safety\/"},{"key":"e_1_3_2_162_2","unstructured":"pundit. 2016. GitHub - elabs\/pundit: Minimal authorization through OO design and pure Ruby classes. Retrieved from https:\/\/github.com\/elabs\/pundit"},{"key":"e_1_3_2_163_2","first-page":"667","volume-title":"Proceedings of the 14th USENIX Symposium on Operating Systems Design and Implementation (OSDI \u201920)","author":"Rigger Manuel","year":"2020","unstructured":"Manuel Rigger and Zhendong Su. 2020. Testing database engines via pivoted query synthesis. In Proceedings of the 14th USENIX Symposium on Operating Systems Design and Implementation (OSDI \u201920). USENIX Association, 667\u2013682. Retrieved from https:\/\/www.usenix.org\/conference\/osdi20\/presentation\/rigger"},{"key":"e_1_3_2_164_2","doi-asserted-by":"crossref","unstructured":"Niklas Risse and Marcel B\u00f6hme. 2023. Limits of machine learning for automatic vulnerability detection. arXiv:2306.17193.","DOI":"10.1145\/3611643.3617845"},{"issue":"1","key":"e_1_3_2_165_2","doi-asserted-by":"crossref","first-page":"tyab023","DOI":"10.1093\/cybsec\/tyab023","article-title":"Patching zero-day vulnerabilities: An empirical analysis","volume":"7","author":"Roumani Yaman","year":"2021","unstructured":"Yaman Roumani. 2021. Patching zero-day vulnerabilities: An empirical analysis. Journal of Cybersecurity 7, 1 (2021), tyab023.","journal-title":"Journal of Cybersecurity"},{"key":"e_1_3_2_166_2","first-page":"2205","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security \u201923)","author":"Sandoval Gustavo","year":"2023","unstructured":"Gustavo Sandoval, Hammond Pearce, Teo Nys, Ramesh Karri, Siddharth Garg, and Brendan Dolan-Gavitt. 2023.Lost at C: A user study on the security implications of large language model code assistants. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security \u201923), 2205\u20132222."},{"issue":"5","key":"e_1_3_2_167_2","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1145\/1095430.1081750","article-title":"CUTE: A concolic unit testing engine for C","volume":"30","author":"Sen Koushik","year":"2005","unstructured":"Koushik Sen, Darko Marinov, and Gul Agha. 2005. CUTE: A concolic unit testing engine for C. ACM SIGSOFT Software Engineering Notes 30, 5 (2005), 263\u2013272.","journal-title":"ACM SIGSOFT Software Engineering Notes"},{"key":"e_1_3_2_168_2","unstructured":"Kostya Serebryany. 2017. OSS-fuzz - Google\u2019s continuous fuzzing service for open source software. USENIX Association Vancouver BC."},{"key":"e_1_3_2_169_2","first-page":"309","volume-title":"Proceedings of the 2012 USENIX Annual Technical Conference (USENIX ATC \u201912)","author":"Serebryany Konstantin","year":"2012","unstructured":"Konstantin Serebryany, Derek Bruening, Alexander Potapenko, and Dmitriy Vyukov. 2012. AddressSanitizer: A fast address sanity checker. In Proceedings of the 2012 USENIX Annual Technical Conference (USENIX ATC \u201912), 309\u2013318."},{"key":"e_1_3_2_170_2","first-page":"288","volume-title":"Proceedings of the 12th International Conference on Foundations of Software Science and Computational Structures (FOSSACS \u201909)","author":"Smith Geoffrey","year":"2009","unstructured":"Geoffrey Smith. 2009. On the foundations of quantitative information flow. In Proceedings of the 12th International Conference on Foundations of Software Science and Computational Structures (FOSSACS \u201909), 288\u2013302."},{"issue":"3","key":"e_1_3_2_171_2","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1007\/s10664-021-10114-1","article-title":"The effects of continuous integration on software development: A systematic literature review","volume":"27","author":"Soares Eliezio","year":"2022","unstructured":"Eliezio Soares, Gustavo Sizilio, Jadson Santos, Daniel Alencar da Costa, and Uir\u00e1 Kulesza. 2022. The effects of continuous integration on software development: A systematic literature review. Empirical Software Engineering 27, 3 (2022), 78.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_172_2","first-page":"887","volume-title":"Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering (ICSE \u201924)","author":"Song X.","year":"2024","unstructured":"X. Song, Y. Wang, X. Cheng, G. Liang, W. Qianxiang, and Z. Zhu. 2024. Efficiently trimming the fat: Streamlining software dependencies with Java reflection and dependency analysis. In Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering (ICSE \u201924). IEEE Computer Society, Los Alamitos, CA, 887\u2013887. Retrieved from https:\/\/doi.ieeecomputersociety.org\/"},{"key":"e_1_3_2_173_2","first-page":"1","volume-title":"Proceedings of the ACM on Programming Languages","volume":"3","author":"Sp\u00e4th Johannes","year":"2019","unstructured":"Johannes Sp\u00e4th, Karim Ali, and Eric Bodden. 2019. Context-, flow-, and field-sensitive data-flow analysis using synchronized pushdown systems. Proceedings of the ACM on Programming Languages 3, POPL (2019), 1\u201329."},{"key":"e_1_3_2_174_2","first-page":"46","volume-title":"Proceedings of the 2015 IEEE\/ACM International Symposium on Code Generation and Optimization (CGO \u201915).","author":"Stepanov Evgeniy","year":"2015","unstructured":"Evgeniy Stepanov and Konstantin Serebryany. 2015. MemorySanitizer: Fast detector of uninitialized memory use in C++. In Proceedings of the 2015 IEEE\/ACM International Symposium on Code Generation and Optimization (CGO \u201915). IEEE, 46\u201355."},{"key":"e_1_3_2_175_2","unstructured":"Jeffrey Vander Stoep. 2022. Memory safe languages in Android 13. Retrieved from https:\/\/security.googleblog.com\/2022\/12\/memory-safe-languages-in-android-13.html"},{"key":"e_1_3_2_176_2","doi-asserted-by":"crossref","first-page":"228","DOI":"10.1109\/APSEC51365.2020.00031","volume-title":"Proceedings of the 2020 27th Asia-Pacific Software Engineering Conference (APSEC \u201920).","author":"Stringer Jacob","year":"2020","unstructured":"Jacob Stringer, Amjed Tahir, Kelly Blincoe, and Jens Dietrich. 2020. Technical lag of dependencies in major package managers. In Proceedings of the 2020 27th Asia-Pacific Software Engineering Conference (APSEC \u201920). IEEE, 228\u2013237."},{"key":"e_1_3_2_177_2","first-page":"796","volume-title":"Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Sun Kairan","year":"2023","unstructured":"Kairan Sun, Zhengzi Xu, Chengwei Liu, Kaixuan Li, and Yang Liu. 2023. Demystifying the composition and code reuse in solidity smart contracts. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, 796\u2013807."},{"key":"e_1_3_2_178_2","first-page":"652","volume-title":"Proceedings of the ACM Web Conference 2022","author":"Sun Zhensu","year":"2022","unstructured":"Zhensu Sun, Xiaoning Du, Fu Song, Mingze Ni, and Li Li. 2022. Coprotector: Protect open-source code against unauthorized training usage with data poisoning. In Proceedings of the ACM Web Conference 2022, 652\u2013660."},{"key":"e_1_3_2_179_2","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1109\/SP.2013.13","volume-title":"Proceedings of the 2013 IEEE Symposium on Security and Privacy.","author":"Szekeres Laszlo","year":"2013","unstructured":"Laszlo Szekeres, Mathias Payer, Tao Wei, and Dawn Song. 2013. Sok: Eternal War in memory. In Proceedings of the 2013 IEEE Symposium on Security and Privacy. IEEE, 48\u201362."},{"key":"e_1_3_2_180_2","first-page":"112","volume-title":"Proceedings of the 14th International Conference Network and System Security (NSS \u201920)","author":"Taylor Matthew","year":"2020","unstructured":"Matthew Taylor, Ruturaj Vaidya, Drew Davidson, Lorenzo De Carli, and Vaibhav Rastogi. 2020. Defending against package typosquatting. In Proceedings of the 14th International Conference Network and System Security (NSS \u201920). Springer, 112\u2013131."},{"key":"e_1_3_2_181_2","doi-asserted-by":"publisher","DOI":"10.1145\/358198.358210"},{"issue":"6","key":"e_1_3_2_182_2","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1145\/1543135.1542486","article-title":"TAJ: Effective taint analysis of web applications","volume":"44","author":"Tripp Omer","year":"2009","unstructured":"Omer Tripp, Marco Pistoia, Stephen J. Fink, Manu Sridharan, and Omri Weisman. 2009. TAJ: Effective taint analysis of web applications. ACM Sigplan Notices 44, 6 (2009), 87\u201397.","journal-title":"ACM Sigplan Notices"},{"key":"e_1_3_2_183_2","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1016\/j.cose.2018.11.001","article-title":"Survey of machine learning techniques for malware analysis","volume":"81","author":"Ucci Daniele","year":"2019","unstructured":"Daniele Ucci, Leonardo Aniello, and Roberto Baldoni. 2019. Survey of machine learning techniques for malware analysis. Computers & Security 81 (2019), 123\u2013147.","journal-title":"Computers & Security"},{"key":"e_1_3_2_184_2","first-page":"31","volume-title":"Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS & P \u201916)","author":"Val Celina G.","year":"2016","unstructured":"Celina G. Val, Michael A. Enescu, Sam Bayless, William Aiello, and Alan J. Hu. 2016. Precisely measuring quantitative information flow: 10K lines of code and beyond. In Proceedings of the 2016 IEEE European Symposium on Security and Privacy (EuroS & P \u201916), 31\u201346. DOI: 10.1109\/EuroSP.2016.15"},{"key":"e_1_3_2_185_2","unstructured":"verizonleak. [n.d.]. 14 million verizon subscribers\u2019 details leak from crappily configured AWS S3 data store. Retrieved from https:\/\/www.theregister.co.uk\/2017\/07\/12\/14m_verizon_customers_details_out\/"},{"issue":"6","key":"e_1_3_2_186_2","doi-asserted-by":"crossref","first-page":"329","DOI":"10.1007\/s42979-020-00353-2","article-title":"Cloud computing security issues: A stakeholder\u2019s perspective","volume":"1","author":"Verma Garima","year":"2020","unstructured":"Garima Verma and Sandhya Adhikari. 2020. Cloud computing security issues: A stakeholder\u2019s perspective. SN Computer Science 1, 6 (2020), 329.","journal-title":"SN Computer Science"},{"key":"e_1_3_2_187_2","unstructured":"VSCode. 2024. VSCode IDE. Retrieved from https:\/\/code.visualstudio.com\/"},{"key":"e_1_3_2_188_2","first-page":"509","volume-title":"Proceedings of the 2020 IEEE European Symposium on Security and Privacy Workshops (Euros & PW \u201920).","author":"Vu Duc-Ly","year":"2020","unstructured":"Duc-Ly Vu, Ivan Pashchenko, Fabio Massacci, Henrik Plate, and Antonino Sabetta. 2020. Typosquatting and combosquatting attacks on the Python ecosystem. In Proceedings of the 2020 IEEE European Symposium on Security and Privacy Workshops (Euros & PW \u201920). IEEE, 509\u2013514."},{"key":"e_1_3_2_189_2","article-title":"Plumber: Boosting the propagation of vulnerability fixes in the npm ecosystem","author":"Wang Ying","year":"2023","unstructured":"Ying Wang, Peng Sun, Lin Pei, Yue Yu, Chang Xu, Shing-Chi Cheung, Hai Yu, and Zhiliang Zhu. 2023. Plumber: Boosting the propagation of vulnerability fixes in the npm ecosystem. IEEE Transactions on Software Engineering (2023).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_190_2","unstructured":"Jason Wei Xuezhi Wang Dale Schuurmans Maarten Bosma Ed H. Chi Quoc Le and Denny Zhou. 2022. Chain of thought prompting elicits reasoning in large language models. arXiv:2201.11903. Retrieved from https:\/\/arxiv.org\/abs\/2201.11903"},{"issue":"3","key":"e_1_3_2_191_2","doi-asserted-by":"crossref","first-page":"457","DOI":"10.1145\/2678373.2665740","article-title":"The CHERI capability model: Revisiting RISC in an age of risk","volume":"42","author":"Woodruff Jonathan","year":"2014","unstructured":"Jonathan Woodruff, Robert N. M. Watson, David Chisnall, Simon W. Moore, Jonathan Anderson, Brooks Davis, Ben Laurie, Peter G. Neumann, Robert Norton, and Michael Roe. 2014. The CHERI capability model: Revisiting RISC in an age of risk. ACM SIGARCH Computer Architecture News 42, 3 (2014), 457\u2013468.","journal-title":"ACM SIGARCH Computer Architecture News"},{"key":"e_1_3_2_192_2","unstructured":"Fangzhou Wu Ning Zhang Somesh Jha Patrick McDaniel and Chaowei Xiao. 2024. A new era in llm security: Exploring security concerns in real-world llm-based systems. arXiv:2402.18649. Retrieved from https:\/\/arxiv.org\/abs\/2402.18649"},{"key":"e_1_3_2_193_2","first-page":"128","volume-title":"Proceedings of the 2020 Formal Methods in Computer Aided Design (FMCAD \u201920)","author":"Wu Haoze","year":"2020","unstructured":"Haoze Wu, Alex Ozdemir, Aleksandar Zelji\u0107, Kyle Julian, Ahmed Irfan, Divya Gopinath, Sadjad Fouladi, Guy Katz, Corina Pasareanu, and Clark Barrett. 2020. Parallelization techniques for verifying neural networks. In Proceedings of the 2020 Formal Methods in Computer Aided Design (FMCAD \u201920), 128\u2013137. DOI: 10.34727\/2020\/isbn.978-3-85448-042-6_20"},{"key":"e_1_3_2_194_2","unstructured":"Yueming Wu Chengwei Liu and Yang Liu. 2023. The software genome project: Venture to the genomic pathways of open source software and its applications. arXiv:2311.09881. Retrieved from https:\/\/arxiv.org\/abs\/2311.09881"},{"key":"e_1_3_2_195_2","first-page":"1046","volume-title":"Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE \u201923).","author":"Wu Yulun","year":"2023","unstructured":"Yulun Wu, Zeliang Yu, Ming Wen, Qiang Li, Deqing Zou, and Hai Jin. 2023. Understanding the threats of upstream vulnerabilities to downstream projects in the Maven ecosystem. In Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE \u201923). IEEE, 1046\u20131058."},{"key":"e_1_3_2_196_2","unstructured":"XACML. 2003. EXtensible access control markup language (XACML) Version 1.0. OASIS Standard. Retrieved from http:\/\/www.oasis-open.org\/committees\/tc_home.php?wg_abbrev=xacmlhttp:\/\/www.oasis-open.org\/committees\/tc_home.php?wg_abbrev=xacml"},{"key":"e_1_3_2_197_2","first-page":"144","volume-title":"Proceedings of the 2012 International Symposium on Software Testing and Analysis (ISSTA\u201912)","author":"Yang Guowei","year":"2012","unstructured":"Guowei Yang, Corina S. P\u0103s\u0103reanu, and Sarfraz Khurshid. 2012. Memoized symbolic execution. In Proceedings of the 2012 International Symposium on Software Testing and Analysis (ISSTA\u201912). ACM, New York, NY, 144\u2013154. DOI: 10.1145\/2338965.2336771"},{"key":"e_1_3_2_198_2","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1145\/1993498.1993532","volume-title":"Proceedings of the 32nd ACM SIGPLAN Conference on Programming Language Design and Implementation","author":"Yang Xuejun","year":"2011","unstructured":"Xuejun Yang, Yang Chen, Eric Eide, and John Regehr. 2011. Finding and understanding bugs in C compilers. In Proceedings of the 32nd ACM SIGPLAN Conference on Programming Language Design and Implementation, 283\u2013294."},{"key":"e_1_3_2_199_2","first-page":"100211","article-title":"A survey on large language model (LLM) security and privacy: The good, the bad, and the ugly","author":"Yao Yifan","year":"2024","unstructured":"Yifan Yao, Jinhao Duan, Kaidi Xu, Yuanfang Cai, Zhibo Sun, and Yue Zhang. 2024. A survey on large language model (LLM) security and privacy: The good, the bad, and the ugly. High-Confidence Computing (2024), 100211.","journal-title":"High-Confidence Computing"},{"key":"e_1_3_2_200_2","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1109\/ICSME46990.2020.00024","volume-title":"Proceedings of the 2020 IEEE International Conference on Software Maintenance and Evolution (ICSME \u201920).","author":"Yasmin Jerin","year":"2020","unstructured":"Jerin Yasmin, Yuan Tian, and Jinqiu Yang. 2020.A first look at the deprecation of RESTful APIs: An empirical study. In Proceedings of the 2020 IEEE International Conference on Software Maintenance and Evolution (ICSME \u201920). IEEE, 151\u2013161."},{"key":"e_1_3_2_201_2","first-page":"40373","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Yu Zhiyuan","year":"2023","unstructured":"Zhiyuan Yu, Yuhao Wu, Ning Zhang, Chenguang Wang, Yevgeniy Vorobeychik, and Chaowei Xiao. 2023. CODEIPPROMPT: Intellectual property infringement assessment of code language models. In Proceedings of the International Conference on Machine Learning. PMLR, 40373\u201340389."},{"key":"e_1_3_2_202_2","doi-asserted-by":"crossref","first-page":"331","DOI":"10.1145\/3510457.3513044","volume-title":"Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice","author":"Zahan Nusrat","year":"2022","unstructured":"Nusrat Zahan, Thomas Zimmermann, Patrice Godefroid, Brendan Murphy, Chandra Maddila, and Laurie Williams. 2022. What are weak links in the npm supply chain? In Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice, 331\u2013340."},{"key":"e_1_3_2_203_2","unstructured":"Michal Zalewski. [n.d.]. Technical \u201cwhitepaper\u201d for AFL-fuzz. Retrieved from http:\/\/lcamtuf.coredump.cx\/afl\/technical_details.txt"},{"key":"e_1_3_2_204_2","first-page":"1695","volume-title":"Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE \u201921).","author":"Zhan Xian","year":"2021","unstructured":"Xian Zhan, Lingling Fan, Sen Chen, Feng Wu, Tianming Liu, Xiapu Luo, and Yang Liu. 2021. Atvhunter: Reliable version detection of third-party libraries for vulnerability identification in Android applications. In Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE \u201921). IEEE, 1695\u20131707."},{"key":"e_1_3_2_205_2","first-page":"191","volume-title":"Proceedings of the 2023 38th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201923)","author":"Zhang Lyuye","year":"2023","unstructured":"Lyuye Zhang, Chengwei Liu, Sen Chen, Zhengzi Xu, Lingling Fan, Lida Zhao, Yiran Zhang, and Yang Liu. 2023. Mitigating persistence of open-source vulnerabilities in Maven ecosystem. In Proceedings of the 2023 38th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201923). IEEE, 191\u2013203."},{"key":"e_1_3_2_206_2","first-page":"12","volume-title":"Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201922)","author":"Zhang Lyuye","year":"2023","unstructured":"Lyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen, Lingling Fan, Bihuan Chen, and Yang Liu. 2023. Has my release disobeyed semantic versioning? Static detection based on semantic differencing. In Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering (ASE \u201922). ACM, New York, NY, Article 51, 12 pages. DOI: 10.1145\/3551349.3556956"},{"key":"e_1_3_2_207_2","first-page":"2540","volume-title":"Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE \u201923).","author":"Zhang Lyuye","year":"2023","unstructured":"Lyuye Zhang, Chengwei Liu, Zhengzi Xu, Sen Chen, Lingling Fan, Lida Zhao, Jiahui Wu, and Yang Liu. 2023. Compatible remediation on vulnerabilities from third-party libraries for Java projects. In Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE \u201923). IEEE, 2540\u20132552."},{"key":"e_1_3_2_208_2","article-title":"Empirical study for open source libraries in automotive software systems","author":"Zhang Yanan","year":"2023","unstructured":"Yanan Zhang, Yuqiao Ning, Chao Ma, Longhai Yu, and Zhen Guo. 2023. Empirical study for open source libraries in automotive software systems. IEEE Access (2023).","journal-title":"IEEE Access"},{"key":"e_1_3_2_209_2","doi-asserted-by":"crossref","unstructured":"Yuntong Zhang Haifeng Ruan Zhiyu Fan and Abhik Roychoudhury. 2024. AutoCodeRover: Autonomous program improvement. arXiv:2404.05427. Retrieved from https:\/\/arxiv.org\/abs\/2404.05427","DOI":"10.1145\/3650212.3680384"},{"issue":"2","key":"e_1_3_2_210_2","doi-asserted-by":"crossref","first-page":"180","DOI":"10.1007\/s11633-022-1377-5","article-title":"Red alarm for pre-trained models: Universal vulnerability to neuron-level backdoor attacks","volume":"20","author":"Zhang Zhengyan","year":"2023","unstructured":"Zhengyan Zhang, Guangxuan Xiao, Yongwei Li, Tian Lv, Fanchao Qi, Zhiyuan Liu, Yasheng Wang, Xin Jiang, and Maosong Sun. 2023. Red alarm for pre-trained models: Universal vulnerability to neuron-level backdoor attacks. Machine Intelligence Research 20, 2 (2023), 180\u2013193.","journal-title":"Machine Intelligence Research"},{"key":"e_1_3_2_211_2","doi-asserted-by":"crossref","unstructured":"Jian Zhao Shenao Wang Yanjie Zhao Xinyi Hou Kailong Wang Peiming Gao Yuanchao Zhang Chen Wei and Haoyu Wang. 2024. Models are codes: Towards measuring malicious code poisoning attacks on pre-trained model hubs. arXiv:2409.09368. Retrieved from https:\/\/arxiv.org\/abs\/2409.09368","DOI":"10.1145\/3691620.3695271"},{"key":"e_1_3_2_212_2","article-title":"Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks","volume":"32","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jingkai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In Advances in Neural Information Processing Systems, Vol. 32.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_213_2","first-page":"995","volume-title":"Proceedings of the 28th USENIX Security Symposium (USENIX Security \u201919)","author":"Zimmermann Markus","year":"2019","unstructured":"Markus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, and Michael Pradel. 2019. Small world with high risks: A study of security threats in the npm ecosystem. In Proceedings of the 28th USENIX Security Symposium (USENIX Security \u201919), 995\u20131010."}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708533","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708533","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:46Z","timestamp":1750295866000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708533"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,26]]},"references-count":212,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,6,30]]}},"alternative-id":["10.1145\/3708533"],"URL":"https:\/\/doi.org\/10.1145\/3708533","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,26]]},"assertion":[{"value":"2024-05-27","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-04","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}