{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T00:59:46Z","timestamp":1784595586196,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":75,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T00:00:00Z","timestamp":1718755200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,19]]},"DOI":"10.1145\/3714393.3726509","type":"proceedings-article","created":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T18:38:47Z","timestamp":1749062327000},"page":"401-412","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["VulPatrol: Interprocedural Vulnerability Detection and Localization through Semantic Graph Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-3989-8320","authenticated-orcid":false,"given":"Asmaa","family":"Hailane","sequence":"first","affiliation":[{"name":"University of Ottawa, Ottawa, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5592-1518","authenticated-orcid":false,"given":"Paria","family":"Shirani","sequence":"additional","affiliation":[{"name":"University of Ottawa, Ottawa, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6067-6545","authenticated-orcid":false,"given":"Guy-Vincent","family":"Jourdan","sequence":"additional","affiliation":[{"name":"University of Ottawa, Ottawa, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"https:\/\/fbinfer.com\/","year":"2024","unstructured":"2013. Infer. https:\/\/fbinfer.com\/. Accessed: January 2024."},{"key":"e_1_3_2_1_2_1","volume-title":"https:\/\/joern.io\/","year":"2024","unstructured":"2013. Joern. https:\/\/joern.io\/. Accessed: January 2024."},{"key":"e_1_3_2_1_3_1","unstructured":"2014. Cppcheck. http:\/\/cppcheck.sourceforge.net\/."},{"key":"e_1_3_2_1_4_1","unstructured":"2014. Synopsys. Coverity. https:\/\/en.wikipedia.org\/wiki\/Coverity."},{"key":"e_1_3_2_1_5_1","unstructured":"2017. Juliet. https:\/\/samate.nist.gov\/SARD\/test-suites\/112."},{"key":"e_1_3_2_1_6_1","unstructured":"2018. Checkmarx. https:\/\/checkmarx.com\/."},{"key":"e_1_3_2_1_7_1","volume-title":"https:\/\/www.openai.com\/. Accessed","year":"2024","unstructured":"2021. GPT-3.5. https:\/\/www.openai.com\/. Accessed: 2024."},{"key":"e_1_3_2_1_8_1","unstructured":"2023. GPT-3 API Documentation. https:\/\/beta.openai.com\/docs\/."},{"key":"e_1_3_2_1_9_1","unstructured":"2023. Howto respond to curl& libcurl vulnerabilities. https:\/\/shorturl.at\/qoOMw."},{"key":"e_1_3_2_1_10_1","unstructured":"2023. Software assurance reference dataset. https:\/\/samate.nist.gov\/SARD\/ ."},{"key":"e_1_3_2_1_11_1","unstructured":"2024. ESBMC. https:\/\/github.com\/esbmc\/esbmc."},{"key":"e_1_3_2_1_12_1","unstructured":"2024. Microsoft CodexGLUE Leaderboard. https:\/\/microsoft.github.io\/CodeXGLUE\/. Accessed on: 2024--11--10."},{"key":"e_1_3_2_1_13_1","volume-title":"Graph neural networks in program analysis. Graph neural networks: foundations, frontiers, and applications","author":"Allamanis Miltiadis","year":"2022","unstructured":"Miltiadis Allamanis. 2022. Graph neural networks in program analysis. Graph neural networks: foundations, frontiers, and applications (2022), 483--497."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Uri Alon Meital Zilberstein Omer Levy and Eran Yahav. 2018. code2vec: Learning Distributed Representations of Code. arXiv:1803.09473 [cs.LG]","DOI":"10.1145\/3290353"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678706"},{"key":"e_1_3_2_1_16_1","unstructured":"Daniel Arp Erwin Quiring Feargus Pendlebury Alexander Warnecke Fabio Pierazzi ChristianWressnegger Lorenzo Cavallaro and Konrad Rieck. 2022. Dos and don'ts of machine learning in computer security. In USENIX Security 22."},{"key":"e_1_3_2_1_17_1","volume-title":"Diffusion-convolutional neural networks. Advances in neural information processing systems 29","author":"Atwood James","year":"2016","unstructured":"James Atwood and Don Towsley. 2016. Diffusion-convolutional neural networks. Advances in neural information processing systems 29 (2016)."},{"key":"e_1_3_2_1_18_1","volume-title":"Alice Shoshana Jakobovits, and Torsten Hoefler","author":"Ben-Nun Tal","year":"2018","unstructured":"Tal Ben-Nun, Alice Shoshana Jakobovits, and Torsten Hoefler. 2018. Neural Code Comprehension: A Learnable Representation of Code Semantics. arXiv:1806.07336 [cs.LG]"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3475960.3475985"},{"key":"e_1_3_2_1_20_1","unstructured":"Sicong Cao Xiaobing Sun Lili Bo Rongxin Wu Bin Li and Chuanqi Tao. 2022. MVD: memory-related vulnerability detection based on flow-sensitive graph neural networks (ICSE '22). ACM."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3087402"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607242"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3436877"},{"key":"e_1_3_2_1_24_1","unstructured":"Christian Collberg Clark Thomborson and Douglas Low. 1997. A taxonomy of obfuscating transformations. Technical Report. Department of Computer Science The University of Auckland New Zealand."},{"key":"e_1_3_2_1_25_1","volume-title":"International Conference on Machine Learning. PMLR, 2244--2253","author":"Cummins Chris","year":"2021","unstructured":"Chris Cummins, Zacharias V Fisches, Tal Ben-Nun, Torsten Hoefler, Michael FP O'Boyle, and Hugh Leather. 2021. Programl: A graph-based program representation for data flow analysis and compiler optimizations. In International Conference on Machine Learning. PMLR, 2244--2253."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCES.2010.5674830"},{"key":"e_1_3_2_1_27_1","volume-title":"SATE V Report: Ten Years of Static Analysis Tool Expositions. Special Publication (NIST SP).","author":"Delaitre Aurelien","year":"2018","unstructured":"Aurelien Delaitre, Bertrand Stivalet, Paul Black, Vadim Okun, Terry Cohen, and Athos Ribeiro. 2018. SATE V Report: Ten Years of Static Analysis Tool Expositions. Special Publication (NIST SP)."},{"key":"e_1_3_2_1_28_1","unstructured":"Ninon Eyrolles. 2017. Obfuscation with Mixed Boolean-Arithmetic Expressions: reconstruction analysis and simplification tools. Ph.D. Dissertation. Universit\u00e9 Paris Saclay (COmUE)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528452"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1093\/ietfec\/e91-a.1.316"},{"key":"e_1_3_2_1_32_1","volume-title":"Measurements of the Most Significant Software Security Weaknesses. In ACSAC '20","author":"Galhardo Carlos Cardoso","year":"2020","unstructured":"Carlos Cardoso Galhardo, Peter Mell, Irena Bojanova, and Assane Gueye. 2020. Measurements of the Most Significant Software Security Weaknesses. In ACSAC '20. Association for Computing Machinery, 154--164."},{"key":"e_1_3_2_1_33_1","volume-title":"PAVUDI: Patch-based Vulnerability Discovery using Machine Learning (ACSAC '23).","author":"Ganz Tom","year":"2023","unstructured":"Tom Ganz, Erik Imgrund, Martin H\u00e4rterich, and Konrad Rieck. 2023. PAVUDI: Patch-based Vulnerability Discovery using Machine Learning (ACSAC '23)."},{"key":"e_1_3_2_1_34_1","volume-title":"Graph U-Nets. In international conference on machine learning. PMLR","author":"Gao Hongyang","year":"2019","unstructured":"Hongyang Gao and Shuiwang Ji. 2019. Graph U-Nets. In international conference on machine learning. PMLR, 2083--2092."},{"key":"e_1_3_2_1_35_1","volume-title":"Software vulnerability analysis and discovery using machine-learning and data-mining techniques: A survey. ACM computing surveys (CSUR) 50, 4","author":"Ghaffarian Seyed Mohammad","year":"2017","unstructured":"Seyed Mohammad Ghaffarian and Hamid Reza Shahriari. 2017. Software vulnerability analysis and discovery using machine-learning and data-mining techniques: A survey. ACM computing surveys (CSUR) 50, 4 (2017)."},{"key":"e_1_3_2_1_36_1","volume-title":"International conference on machine learning. PMLR.","author":"Gilmer Justin","year":"2017","unstructured":"Justin Gilmer, Samuel S Schoenholz, Patrick F Riley, Oriol Vinyals, and George E Dahl. 2017. Neural message passing for quantum chemistry. In International conference on machine learning. PMLR."},{"key":"e_1_3_2_1_37_1","volume-title":"International conference on machine learning. PMLR, 1263--1272","author":"Gilmer Justin","year":"2017","unstructured":"Justin Gilmer, Samuel S Schoenholz, Patrick F Riley, Oriol Vinyals, and George E Dahl. 2017. Neural message passing for quantum chemistry. In International conference on machine learning. PMLR, 1263--1272."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3082757"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2023.3297387"},{"key":"e_1_3_2_1_40_1","volume-title":"VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection. In 2022 IJCNN","author":"Hanif Hazim","unstructured":"Hazim Hanif and Sergio Maffeis. 2022. VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection. In 2022 IJCNN. IEEE, 1--8."},{"key":"e_1_3_2_1_41_1","unstructured":"Jacob A Harer Louis Y Kim Rebecca L Russell Onur Ozdemir Leonard R Kosta Akshay Rangamani Lei H Hamilton Gabriel I Centeno Jonathan R Key Paul M Ellingwood et al. 2018. Automated software vulnerability detection with machine learning. arXiv preprint arXiv:1803.04497 (2018)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/2372225.2372230"},{"key":"e_1_3_2_1_43_1","volume-title":"Dylan Manuel, Elias Bou-Harb, and Peyman Najafirad.","author":"Islam Nafis Tanveer","year":"2023","unstructured":"Nafis Tanveer Islam, Gonzalo De La Torre Parra, Dylan Manuel, Elias Bou-Harb, and Peyman Najafirad. 2023. An unbiased transformer source code learning with semantic vulnerability graph. In 2023 IEEE 8th EuroS&P. IEEE."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPRO.2015.10"},{"key":"e_1_3_2_1_45_1","volume-title":"GLICE: Combining Graph Neural Networks and Program Slicing to Improve Software Vulnerability Detection. In 2023 IEEE EuroS&PW. 34--41.","author":"de Kraker Wesley","year":"2023","unstructured":"Wesley de Kraker, Harald Vranken, and Arjen Hommmersom. 2023. GLICE: Combining Graph Neural Networks and Program Slicing to Improve Software Vulnerability Detection. In 2023 IEEE EuroS&PW. 34--41."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-22390-7_21"},{"key":"e_1_3_2_1_47_1","first-page":"3","article-title":"Obfuscating C programs via control flow flattening. Annales Universitatis Scientarum Budapestinensis de Rolando E\u00f6tv\u00f6s Nominatae","volume":"30","author":"L\u00e1szl\u00f3 Timea","year":"2009","unstructured":"Timea L\u00e1szl\u00f3 and \u00c1kos Kiss. 2009. Obfuscating C programs via control flow flattening. Annales Universitatis Scientarum Budapestinensis de Rolando E\u00f6tv\u00f6s Nominatae, Sectio Computatorica 30, 1 (2009), 3--19.","journal-title":"Sectio Computatorica"},{"key":"e_1_3_2_1_48_1","unstructured":"Yujia Li Daniel Tarlow Marc Brockschmidt and Richard Zemel. 2017. Gated Graph Sequence Neural Networks. arXiv:1511.05493 [cs.LG]"},{"key":"e_1_3_2_1_49_1","volume-title":"ESEC\/FSE '21 (ESEC\/FSE '21)","author":"Li Yi","unstructured":"Yi Li, Shaohua Wang, and Tien N. Nguyen. 2021. Vulnerability detection with fine-grained interpretations. In ESEC\/FSE '21 (ESEC\/FSE '21). ACM."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3076142"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991102"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3051525"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23158"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1976.233837"},{"key":"e_1_3_2_1_55_1","volume-title":"Proceedings of the 32nd USENIX Security Symposium. 6557--6574","author":"Mirsky Yisroel","year":"2023","unstructured":"Yisroel Mirsky, George Macon, Michael Brown, Carter Yagemann, Matthew Pruett, Evan Downing, Sukarno Mertoguno, and Wenke Lee. 2023. VulChecker: Graph-based Vulnerability Localization in Source Code. In Proceedings of the 32nd USENIX Security Symposium. 6557--6574."},{"key":"e_1_3_2_1_56_1","volume-title":"TBCNN: A tree-based convolutional neural network for programming language processing. arXiv preprint arXiv:1409.5718","author":"Mou Lili","year":"2014","unstructured":"Lili Mou, Ge Li, Zhi Jin, Lu Zhang, and Tao Wang. 2014. TBCNN: A tree-based convolutional neural network for programming language processing. arXiv preprint arXiv:1409.5718 (2014)."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Nachiappan Nagappan and Thomas Ball. 2005. Use of relative code churn measures to predict system defect density. In ICSE.","DOI":"10.1145\/1062455.1062514"},{"key":"e_1_3_2_1_58_1","unstructured":"National Vulnerability Database (NVD). 2024. CVE-2024--4741 Detail Page. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024--4741"},{"key":"e_1_3_2_1_59_1","volume-title":"Predicting vulnerable software components through n-gram analysis and statistical feature selection. In 2015 IEEE 14th ICMLA","author":"Pang Yulei","unstructured":"Yulei Pang, Xiaozhen Xue, and Akbar Siami Namin. 2015. Predicting vulnerable software components through n-gram analysis and statistical feature selection. In 2015 IEEE 14th ICMLA. IEEE, 543--548."},{"key":"e_1_3_2_1_60_1","volume-title":"International Conference on Machine Learning. PMLR, 8476--8486","author":"Peng Dinglan","year":"2021","unstructured":"Dinglan Peng, Shuxin Zheng, Yatao Li, Guolin Ke, Di He, and Tie-Yan Liu. 2021. How could neural networks understand programs?. In International Conference on Machine Learning. PMLR, 8476--8486."},{"key":"e_1_3_2_1_61_1","unstructured":"Dinglan Peng Shuxin Zheng Yatao Li Guolin Ke Di He and Tie-Yan Liu. 2021. How could Neural Networks understand Programs?"},{"key":"e_1_3_2_1_62_1","volume-title":"Limits of Machine Learning for Automatic Vulnerability Detection. arXiv preprint arXiv:2306.17193 (06","author":"Risse Niklas","year":"2023","unstructured":"Niklas Risse and Marcel B\u00f6hme. 2023. Limits of Machine Learning for Automatic Vulnerability Detection. arXiv preprint arXiv:2306.17193 (06 2023)."},{"key":"e_1_3_2_1_63_1","unstructured":"Xin Rong. 2016. word2vec Parameter Learning Explained. arXiv:1411.2738 [cs.CL]"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2340398"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.11"},{"key":"e_1_3_2_1_67_1","volume-title":"Causal Attention for Interpretable and Generalizable Graph Classification. In KDD'22 (KDD '22)","author":"Sui Yongduo","year":"2022","unstructured":"Yongduo Sui, XiangWang, JiancanWu, Min Lin, Xiangnan He, and Tat-Seng Chua. 2022. Causal Attention for Interpretable and Generalizable Graph Classification. In KDD'22 (KDD '22). ACM, 1696--1705."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/2892208.2892235"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567985"},{"key":"e_1_3_2_1_70_1","unstructured":"Frank Tip. 1994. A survey of program slicing techniques. Centrum voor Wiskunde en Informatica Amsterdam."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00210"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884804"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"crossref","unstructured":"W. Xiong J. Droppo X. Huang F. Seide M. Seltzer A. Stolcke D. Yu and G. Zweig. 2017. Achieving Human Parity in Conversational Speech Recognition. arXiv:1610.05256 [cs.CL]","DOI":"10.1109\/TASLP.2017.2756440"},{"key":"e_1_3_2_1_74_1","unstructured":"N. Zhang. 2017. Hikari -- an improvement over Obfuscator-LLVM. https:\/\/github.com\/HikariObfuscator\/."},{"key":"e_1_3_2_1_75_1","volume-title":"Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks. arXiv:1909.03496 [cs.SE]","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jingkai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks. arXiv:1909.03496 [cs.SE]"}],"event":{"name":"CODASPY '25: Fifteenth ACM Conference on Data and Application Security and Privacy","location":"Pittsburgh PA USA","acronym":"CODASPY '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Fifteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3714393.3726509","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3714393.3726509","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T16:26:19Z","timestamp":1780417579000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3714393.3726509"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,19]]},"references-count":75,"alternative-id":["10.1145\/3714393.3726509","10.1145\/3714393"],"URL":"https:\/\/doi.org\/10.1145\/3714393.3726509","relation":{},"subject":[],"published":{"date-parts":[[2024,6,19]]},"assertion":[{"value":"2025-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}