{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:34:38Z","timestamp":1783611278577,"version":"3.55.0"},"reference-count":60,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T00:00:00Z","timestamp":1778630400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"NATURAL project, which has received funding from the European Research Council (ERC) under the European Union\u2019s Horizon 2020 research and innovation programme","award":["grant no. 949014"],"award-info":[{"award-number":["grant no. 949014"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>\n                    Open source code is pervasive. In this setting, embedded vulnerabilities are spreading to downstream software at an alarming rate. Although such vulnerabilities are generally identified and addressed rapidly, inconsistent maintenance policies can cause security patches to go unnoticed. Indeed, security patches can be\n                    <jats:italic toggle=\"yes\">silent<\/jats:italic>\n                    , i.e., they do not always come with comprehensive advisories such as CVEs. This lack of transparency leaves users oblivious to available security updates, providing ample opportunity for attackers to exploit unpatched vulnerabilities. Consequently, identifying silent security patches just in time when they are released is essential for preventing n-day attacks and for ensuring robust and secure maintenance practices. With\n                    <jats:sc>llmda<\/jats:sc>\n                    we propose to (1) leverage large language models (LLMs) to augment patch information with generated code change explanations, (2) design a representation learning approach that explores code-text alignment methodologies for feature combination, (3) implement a label-wise training with labeled instructions for guiding the embedding based on security relevance, and (4) rely on a probabilistic batch contrastive learning mechanism for building a high-precision identifier of security patches. We evaluate\n                    <jats:sc>llmda<\/jats:sc>\n                    on the PatchDB and SPI-DB literature datasets and show that our approach substantially improves over the state of the art, notably GraphSPD by 20% in terms of F-Measure on the SPI-DB benchmark.\n                  <\/jats:p>","DOI":"10.1145\/3749370","type":"journal-article","created":{"date-parts":[[2025,7,29]],"date-time":"2025-07-29T12:10:37Z","timestamp":1753791037000},"page":"1-34","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Just-in-Time Detection of Silent Security Patches"],"prefix":"10.1145","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6377-0884","authenticated-orcid":false,"given":"Xunzhu","family":"Tang","sequence":"first","affiliation":[{"name":"University of Luxembourg, Esch-sur-Alzette, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4462-6916","authenticated-orcid":false,"given":"Kisub","family":"Kim","sequence":"additional","affiliation":[{"name":"DGIST, Daegu, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7657-4738","authenticated-orcid":false,"given":"Saad","family":"Ezzini","sequence":"additional","affiliation":[{"name":"King Fahd University of Petroleum and Minerals, Dhahran, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6314-7515","authenticated-orcid":false,"given":"Yewei","family":"Song","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Esch-sur-Alzette, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8049-3997","authenticated-orcid":false,"given":"Haoye","family":"Tian","sequence":"additional","affiliation":[{"name":"University of Melbourne, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4052-475X","authenticated-orcid":false,"given":"Jacques","family":"Klein","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Esch-sur-Alzette, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7270-9869","authenticated-orcid":false,"given":"Tegawend\u00e9","family":"Bissyand\u00e9","sequence":"additional","affiliation":[{"name":"University of Luxembourg, Esch-sur-Alzette, Luxembourg"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Wasi Uddin Ahmad Saikat Chakraborty Baishakhi Ray and Kai-Wei Chang. 2021. Unified pre-training for program understanding and generation. arXiv:2103.06333. Retrieved from https:\/\/arxiv.org\/abs\/2103.06333"},{"key":"e_1_3_2_3_2","unstructured":"Meta AI. 2023. Llama3 70B: Large Language Model for Multimodal Applications. Retrieved from https:\/\/ai.meta.com\/llama3-70b"},{"key":"e_1_3_2_4_2","unstructured":"Anthropic. 2023. Claude 3.5 Sonnet: High-Performance Language Model for Complex Tasks. Retrieved from https:\/\/www.anthropic.com\/claude-3-5-sonnet"},{"key":"e_1_3_2_5_2","unstructured":"Tom B. Brown Benjamin Mann Nick Ryder Melanie Subbiah Jared Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell et al. 2020. Language models are few-shot learners. arXiv:2005.14165. Retrieved from https:\/\/arxiv.org\/abs\/2005.14165"},{"key":"e_1_3_2_6_2","unstructured":"Hyung Won Chung Le Hou Shayne Longpre Barret Zoph Yi Tay William Fedus Eric Li Xuezhi Wang Mostafa Dehghani Siddhartha Brahma et al. 2022. Scaling instruction-finetuned language models. arXiv:2210.11416. Retrieved from https:\/\/arxiv.org\/abs\/2210.11416"},{"issue":"70","key":"e_1_3_2_7_2","first-page":"1","article-title":"Scaling instruction-finetuned language models","volume":"25","author":"Won Chung Hyung","year":"2024","unstructured":"Hyung Won Chung, Le Hou, Shayne Longpre, Barret Zoph, Yi Tay, William Fedus, Yunxuan Li, Xuezhi Wang, Mostafa Dehghani, Siddhartha Brahma, et al. 2024. Scaling instruction-finetuned language models. Journal of Machine Learning Research 25, 70 (2024), 1\u201353.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_8_2","unstructured":"Wenliang Dai Junnan Li Dongxu Li Anthony Meng Huat Tiong Junqi Zhao Weisheng Wang Boyang Li Pascale Fung and Steven Hoi. 2023. InstructBLIP: Towards general-purpose vision-language models with instruction tuning. arXiv:2305.06500. Retrieved from https:\/\/arxiv.org\/abs\/2305.06500"},{"key":"e_1_3_2_9_2","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv:1810.04805. Retrieved from https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"e_1_3_2_10_2","first-page":"1","volume-title":"Proceedings of the ACM on Human-Computer Interaction","volume":"6","author":"Dissanayake Nesara","year":"2022","unstructured":"Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, and Muhammad Ali Babar. 2022. Why, how and where of delays in software security patch management: An empirical investigation in the healthcare sector. Proceedings of the ACM on Human-Computer Interaction 6, CSCW2 (2022), 1\u201329."},{"key":"e_1_3_2_11_2","unstructured":"Hugging Face. 2023. Mixtral 8x7B: Multi-Domain Pre-Trained Model for Code and Text. Retrieved from https:\/\/huggingface.co\/mixtral-8x7b"},{"key":"e_1_3_2_12_2","doi-asserted-by":"crossref","unstructured":"Zhangyin Feng Daya Guo Duyu Tang Nan Duan Xiaocheng Feng Ming Gong Linjun Shou Bing Qin Ting Liu Daxin Jiang et al. 2020. Codebert: A pre-trained model for programming and natural languages. arXiv:2002.08155. Retrieved from https:\/\/arxiv.org\/abs\/2002.08155","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"issue":"10","key":"e_1_3_2_13_2","article-title":"VulExplainer: A transformer-based hierarchical distillation for explaining vulnerability types","volume":"49","author":"Fu Michael","year":"2023","unstructured":"Michael Fu, Van Nguyen, Chakkrit Kla Tantithamthavorn, Trung Le, and Dinh Phung. 2023. VulExplainer: A transformer-based hierarchical distillation for explaining vulnerability types. IEEE Transactions on Software Engineering 49, 10 (2023).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-023-10346-3"},{"key":"e_1_3_2_15_2","unstructured":"Daya Guo Shuo Ren Shuai Lu Zhangyin Feng Duyu Tang Shujie Liu Long Zhou Nan Duan Alexey Svyatkovskiy Shengyu Fu et al. 2020. Graphcodebert: Pre-training code representations with data flow. arXiv:2009.08366. Retrieved from https:\/\/arxiv.org\/abs\/2009.08366"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.5121\/ijdkp.2015.5201"},{"key":"e_1_3_2_17_2","doi-asserted-by":"crossref","first-page":"539","DOI":"10.1109\/SP.2019.00071","volume-title":"Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP)","author":"Huang Zhen","year":"2019","unstructured":"Zhen Huang, David Lie, Gang Tan, and Trent Jaeger. 2019. Using safety properties to generate vulnerability patches. In Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP). IEEE, 539\u2013554."},{"key":"e_1_3_2_18_2","first-page":"2052","volume-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","author":"Hyun Jeeho","year":"2024","unstructured":"Jeeho Hyun, Sangyun Kim, Giyoung Jeon, Seung Hwan Kim, Kyunghoon Bae, and Byung Jun Kang. 2024. ReConPatch: Contrastive patch representation learning for industrial anomaly detection. In Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, 2052\u20132061."},{"key":"e_1_3_2_19_2","unstructured":"Gemma AI Labs. 2023. Gemma 7B: Lightweight Model for Language and Code Tasks. Retrieved from https:\/\/gemmalabs.ai\/models\/7b"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"e_1_3_2_21_2","first-page":"19730","volume-title":"International Conference on Machine Learning","author":"Li Junnan","year":"2023","unstructured":"Junnan Li, Dongxu Li, Silvio Savarese, and Steven Hoi. 2023. Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models. In International Conference on Machine Learning. PMLR, 19730\u201319742."},{"key":"e_1_3_2_22_2","unstructured":"Raymond Li Loubna Ben Allal Yangtian Zi Niklas Muennighoff Denis Kocetkov Chenghao Mou Marc Marone Christopher Akiki Jia Li Jenny Chim et al. 2023. StarCoder: May the source be with you!. arXiv:2305.06161. Retrieved from https:\/\/arxiv.org\/abs\/2305.06161"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3051525"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00014"},{"key":"e_1_3_2_25_2","unstructured":"Ilya Loshchilov and Frank Hutter. 2019. Decoupled weight decay degularization. In International Conference on Learning Representations (ICLR 2019) Paper 939 1\u201319."},{"key":"e_1_3_2_26_2","unstructured":"Wenqiang Luo Jacky Wai Keung Boyang Yang He Ye Claire Le Goues Tegawende F. Bissyande Haoye Tian and Bach Le. 2024. When fine-tuning LLMs meets data privacy: An empirical study of federated learning in LLM-based program repair. arXiv:2412.01072. Retrieved from https:\/\/arxiv.org\/abs\/2412.01072"},{"key":"e_1_3_2_27_2","unstructured":"Van Nguyen Trung Le Chakkrit Tantithamthavorn John Grundy Hung Nguyen Seyit Camtepe Paul Quirk and Dinh Phung. 2022. An information-theoretic and contrastive learning-based approach for identifying code statements causing software vulnerability. arXiv:2209.10414. Retrieved from https:\/\/arxiv.org\/abs\/2209.10414"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3510454.3516865"},{"key":"e_1_3_2_29_2","unstructured":"OpenAI. 2023. Gemini 2.0 Flash: Advanced Language Model for Code and Text Understanding. Retrieved from https:\/\/www.openai.com\/gemini-2-flash"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813604"},{"key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3712187","article-title":"You don\u2019t have to say where to edit! jLED\u2013joint learning to localize and edit source code","author":"Pian Weiguo","year":"2025","unstructured":"Weiguo Pian, Yinghua Li, Haoye Tian, Tiezhu Sun, Yewei Song, Xunzhu Tang, Andrew Habib, Jacques Klein, and Tegawend\u00e9 F. Bissyand\u00e9. 2025. You don\u2019t have to say where to edit! jLED\u2013joint learning to localize and edit source code. ACM Transactions on Software Engineering and Methodology Article 164 (2025), 1\u20132.","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25654"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_3_2_34_2","unstructured":"Lindsay I. Smith. 2002. A Tutorial on Principal Components Analysis. Computer Science Technical Report OUCS-2002-12 Department of Computer Science University of Otago Otago New Zealand."},{"key":"e_1_3_2_35_2","unstructured":"Chia Yi Su and Collin McMillan. 2023. Semantic similarity loss for neural source code summarization. arXiv:2308.07429. Retrieved from https:\/\/arxiv.org\/abs\/2308.07429"},{"key":"e_1_3_2_36_2","unstructured":"Weisong Sun Chunrong Fang Yudu You Yun Miao Yi Liu Yuekang Li Gelei Deng Shenghan Huang Yuchen Chen Quanjun Zhang et al. 2023. Automatic code summarization via ChatGPT: How far are we? arXiv:2305.12865. Retrieved from https:\/\/arxiv.org\/abs\/2305.12865"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484593"},{"key":"e_1_3_2_38_2","doi-asserted-by":"crossref","first-page":"11279","DOI":"10.18653\/v1\/2024.emnlp-main.632","volume-title":"Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing","author":"Tang Xunzhu","year":"2024","unstructured":"Xunzhu Tang, Kisub Kim, Yewei Song, Cedric Lothritz, Bei Li, Saad Ezzini, Haoye Tian, Jacques Klein, and Tegawend\u00e9 Bissyand\u00e9. 2024. CodeAgent: Autonomous communicative agents for code review. In Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing, 11279\u201311313."},{"key":"e_1_3_2_39_2","first-page":"396","volume-title":"Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering: Companion Proceedings","author":"Tang Xunzhu","year":"2024","unstructured":"Xunzhu Tang, Haoye Tian, Zhenghan Chen, Weiguo Pian, Saad Ezzini, Abdoul Kader Kabor\u00e9, Andrew Habib, Jacques Klein, and Tegawende F. Bissyande. 2024. Learning to represent patches. In Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering: Companion Proceedings, 396\u2013397."},{"issue":"5","key":"e_1_3_2_40_2","doi-asserted-by":"crossref","first-page":"124","DOI":"10.1007\/s10664-024-10489-x","article-title":"App review driven collaborative bug finding","volume":"29","author":"Tang Xunzhu","year":"2024","unstructured":"Xunzhu Tang, Haoye Tian, Pingfan Kong, Saad Ezzini, Kui Liu, Xin Xia, Jacques Klein, and Tegawend\u00e9 F. Bissyand\u00e9. 2024. App review driven collaborative bug finding. Empirical Software Engineering 29, 5 (2024), 124.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416532"},{"key":"e_1_3_2_42_2","unstructured":"Haoye Tian Weiqi Lu Tsz On Li Xunzhu Tang Shing-Chi Cheung Jacques Klein and Tegawend\u00e9 F. Bissyand\u00e9. 2023. Is ChatGPT the ultimate programming assistant\u2013How far is it? arXiv:2304.11938. Retrieved from https:\/\/arxiv.org\/abs\/2304.11938"},{"key":"e_1_3_2_43_2","doi-asserted-by":"crossref","unstructured":"Haoye Tian Xunzhu Tang Andrew Habib Shangwen Wang Kui Liu Xin Xia Jacques Klein and Tegawend\u00e9 F. Bissyand\u00e9. 2022. Is this change the answer to that problem? Correlating descriptions of bug and code changes for evaluating patch correctness. arXiv:2208.04125. Retrieved from https:\/\/arxiv.org\/abs\/2208.04125","DOI":"10.1145\/3551349.3556914"},{"key":"e_1_3_2_44_2","doi-asserted-by":"crossref","first-page":"386","DOI":"10.1109\/ICSE.2012.6227176","volume-title":"Proceedings of the 2012 34th International Conference on Software Engineering (ICSE)","author":"Tian Yuan","year":"2012","unstructured":"Yuan Tian, Julia Lawall, and David Lo. 2012. Identifying linux bug fixing patches. In Proceedings of the 2012 34th International Conference on Software Engineering (ICSE). IEEE, 386\u2013396."},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179479"},{"key":"e_1_3_2_46_2","first-page":"485","volume-title":"Proceedings of the 2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","author":"Wang Xinda","year":"2019","unstructured":"Xinda Wang, Kun Sun, Archer Batcheller, and Sushil Jajodia. 2019. Detecting \u201c0-day\u201d vulnerability: An empirical study of secret security patch in OSS. In Proceedings of the 2019 49th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 485\u2013492."},{"key":"e_1_3_2_47_2","first-page":"149","volume-title":"Proceedings of the 2021 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","author":"Wang Xinda","year":"2021","unstructured":"Xinda Wang, Shu Wang, Pengbin Feng, Kun Sun, and Sushil Jajodia. 2021. Patchdb: A large-scale security patch dataset. In Proceedings of the 2021 51st Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN). IEEE, 149\u2013160."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM52596.2021.9652940"},{"key":"e_1_3_2_49_2","first-page":"1","volume-title":"Proceedings of the 2020 IEEE Conference on Communications and Network Security (CNS)","author":"Wang Xinda","year":"2020","unstructured":"Xinda Wang, Shu Wang, Kun Sun, Archer Batcheller, and Sushil Jajodia. 2020. A machine learning approach to classify security patches into vulnerability types. In Proceedings of the 2020 IEEE Conference on Communications and Network Security (CNS). IEEE, 1\u20139."},{"key":"e_1_3_2_50_2","doi-asserted-by":"crossref","unstructured":"Yue Wang Hung Le Akhilesh Deepak Gotmare Nghi D. Q. Bui Junnan Li and Steven C. H. Hoi. 2023. Codet5+: Open code large language models for code understanding and generation. arXiv:2305.07922. Retrieved from https:\/\/arxiv.org\/abs\/2305.07922","DOI":"10.18653\/v1\/2023.emnlp-main.68"},{"key":"e_1_3_2_51_2","doi-asserted-by":"crossref","unstructured":"Yue Wang Weishi Wang Shafiq Joty and Steven C. H. Hoi. 2021. Codet5: Identifier-aware unified pre-trained encoder-decoder models for code understanding and generation. arXiv:2109.00859. Retrieved from https:\/\/arxiv.org\/abs\/2109.00859","DOI":"10.18653\/v1\/2021.emnlp-main.685"},{"key":"e_1_3_2_52_2","unstructured":"Jason Wei Maarten Bosma Vincent Y. Zhao Kelvin Guu Adams Wei Yu Brian Lester Nan Du Andrew M. Dai and Quoc V. Le. 2021. Finetuned language models are zero-shot learners. arXiv:2109.01652. Retrieved from https:\/\/arxiv.org\/abs\/2109.01652"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01095"},{"key":"e_1_3_2_54_2","volume-title":"Proceedings of the 2020 Annual Network and Distributed System Security Symposium (NDSS \u201920)","author":"Wu Qiushi","year":"2020","unstructured":"Qiushi Wu, Yang He, Stephen McCamant, and Kangjie Lu. 2020. Precisely characterizing security impact in a flood of patches via symbolic rule comparison. In Proceedings of the 2020 Annual Network and Distributed System Security Symposium (NDSS \u201920)."},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489347"},{"key":"e_1_3_2_56_2","article-title":"MORepair: Teaching LLMs to repair code via Multi-Objective Fine-Tuning","author":"Yang Boyang","year":"2025","unstructured":"Boyang Yang, Haoye Tian, Jiadong Ren, Hongyu Zhang, Jacques Klein, Tegawende Bissyande, Claire Le Goues, and Shunfu Jin. 2025. MORepair: Teaching LLMs to repair code via Multi-Objective Fine-Tuning. ACM Transactions on Software Engineering and Methodology (2025).","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"e_1_3_2_57_2","first-page":"2565","volume-title":"Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE)","author":"Zhou Jiayuan","year":"2023","unstructured":"Jiayuan Zhou, Michael Pacheco, Jinfu Chen, Xing Hu, Xin Xia, David Lo, and Ahmed E. Hassan. 2023. Colefunda: Explainable silent vulnerability fix identification. In Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2565\u20132577."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678720"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSME58846.2023.00028"},{"key":"e_1_3_2_60_2","article-title":"Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks","volume":"32","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jingkai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in Neural Information Processing Systems 32 (2019).","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"1","key":"e_1_3_2_61_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3468854","article-title":"SPI: Automated identification of security patches via commits","volume":"31","author":"Zhou Yaqin","year":"2021","unstructured":"Yaqin Zhou, Jing Kai Siow, Chenyu Wang, Shangqing Liu, and Yang Liu. 2021. SPI: Automated identification of security patches via commits. ACM Transactions on Software Engineering and Methodology (TOSEM) 31, 1, Article 915 (2021), 1\u201327.","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3749370","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T17:25:40Z","timestamp":1778693140000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3749370"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,13]]},"references-count":60,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3749370"],"URL":"https:\/\/doi.org\/10.1145\/3749370","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,13]]},"assertion":[{"value":"2024-07-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-25","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}