{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T18:17:44Z","timestamp":1782325064143,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":85,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785375","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1507-1523","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Trace Gadgets: Minimizing Code Context for Machine Learning-Based Vulnerability Prediction"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-2431-0322","authenticated-orcid":false,"given":"Felix","family":"M\u00e4chtle","sequence":"first","affiliation":[{"name":"University of Luebeck, L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-6243-1623","authenticated-orcid":false,"given":"Nils","family":"Loose","sequence":"additional","affiliation":[{"name":"University of Luebeck, L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8409-7999","authenticated-orcid":false,"given":"Tim","family":"Schulz","sequence":"additional","affiliation":[{"name":"University of Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1501-0936","authenticated-orcid":false,"given":"Florian","family":"Sieck","sequence":"additional","affiliation":[{"name":"University of Luebeck, L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-4624-8592","authenticated-orcid":false,"given":"Jan-Niclas","family":"Serr","sequence":"additional","affiliation":[{"name":"University of Luebeck, L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1174-3323","authenticated-orcid":false,"given":"Ralf","family":"Moeller","sequence":"additional","affiliation":[{"name":"University of Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1116-6973","authenticated-orcid":false,"given":"Thomas","family":"Eisenbarth","sequence":"additional","affiliation":[{"name":"University of Luebeck, L\u00fcbeck, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Dockerhub. https:\/\/hub.docker.com\/. Accessed: 11\/2023."},{"key":"e_1_3_2_1_2_1","unstructured":"Findsecbugs. https:\/\/find-sec-bugs.github.io\/. Accessed: 11\/2023."},{"key":"e_1_3_2_1_3_1","unstructured":"Juliet java 1.3. https:\/\/samate.nist.gov\/SARD\/test-suites. Accessed: 11\/2024."},{"key":"e_1_3_2_1_4_1","unstructured":"An nsa-derived ransomware worm is shutting down computers worldwide. https:\/\/arstechnica.com\/information-technology\/2017\/05\/an-nsa-derived-ransomware-worm-is-shutting-down-computersworldwide\/. Accessed: 10\/2023."},{"key":"e_1_3_2_1_5_1","unstructured":"Owasp java benchmark. https:\/\/owasp.org\/www-project-benchmark\/. Accessed: 11\/2023."},{"key":"e_1_3_2_1_6_1","unstructured":"Tiobe index. https:\/\/www.tiobe.com\/tiobe-index\/. Accessed: 11\/2023."},{"key":"e_1_3_2_1_7_1","unstructured":"Anthropic. Claude 3.7 sonnet. https:\/\/www.anthropic.com\/claude\/sonnet Accessed: 04\/2025."},{"key":"e_1_3_2_1_8_1","first-page":"3988","volume-title":"31st USENIX Security Symposium, USENIX Security 2022","author":"Arp Daniel","year":"2022","unstructured":"Daniel Arp, Erwin Quiring, Feargus Pendlebury, Alexander Warnecke, Fabio Pierazzi, Christian Wressnegger, Lorenzo Cavallaro, and Konrad Rieck. Dos and don'ts of machine learning in computer security. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022, pages 3971\u20133988. USENIX Association, 2022."},{"key":"e_1_3_2_1_9_1","first-page":"269","volume-title":"ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI '14","author":"Arzt Steven","year":"2014","unstructured":"Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, and Patrick D. McDaniel. Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI '14, Edinburgh, United Kingdom - June 09 - 11, 2014, pages 259\u2013269. ACM, 2014."},{"key":"e_1_3_2_1_10_1","unstructured":"Bugcrowd. Xss: Unescaped output of directory name. https:\/\/bugcrowd.com\/disclosures\/29e6d45a-8829-42c9-a3b4-683d71318e37\/xssunescaped-output-of-directory-name Accessed: 09\/2024."},{"key":"e_1_3_2_1_11_1","first-page":"468","volume-title":"19th IEEE\/ACM International Conference on Mining Software Repositories, MSR 2022","author":"Bui Quang-Cuong","year":"2022","unstructured":"Quang-Cuong Bui, Riccardo Scandariato, and Nicol\u00e1s E. D\u00edaz Ferreyra. Vul4j: A dataset of reproducible java vulnerabilities geared towards the study of program repair techniques. In 19th IEEE\/ACM International Conference on Mining Software Repositories, MSR 2022, Pittsburgh, PA, USA, May 23-24, 2022, pages 464\u2013468. ACM, 2022."},{"key":"e_1_3_2_1_12_1","first-page":"618","volume-title":"Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering, ASE 2024","author":"Cao Sicong","year":"2024","unstructured":"Sicong Cao, Xiaobing Sun, Xiaoxue Wu, David Lo, Lili Bo, Bin Li, Xiaolei Liu, Xingwei Lin, and Wei Liu. Snopy: Bridging sample denoising with causal graph learning for effective vulnerability detection. In Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering, ASE 2024, Sacramento, CA, USA, October 27 - November 1, 2024, pages 606\u2013618. ACM, 2024."},{"key":"e_1_3_2_1_13_1","volume-title":"A survey of source code representations for machine learning-based cybersecurity tasks. CoRR, abs\/2403.10646","author":"Casey Beatrice","year":"2024","unstructured":"Beatrice Casey, Joanna C. S. Santos, and George Perry. A survey of source code representations for machine learning-based cybersecurity tasks. CoRR, abs\/2403.10646, 2024."},{"key":"e_1_3_2_1_14_1","first-page":"144","volume-title":"SecDev 2019","author":"Chen Chien-An","year":"2019","unstructured":"Chien-An Chen. With great abstraction comes great responsibility: Sealing the microservices attack surface. In 2019 IEEE Cybersecurity Development, SecDev 2019, Tysons Corner, VA, USA, September 23-25, 2019, page 144. IEEE, 2019."},{"issue":"3","key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3436877","article-title":"Statically detecting software vulnerabilities using deep graph neural network","volume":"30","author":"Cheng Xiao","year":"2021","unstructured":"Xiao Cheng, Haoyu Wang, Jiayi Hua, Guoai Xu, and Yulei Sui. Deepwukong: Statically detecting software vulnerabilities using deep graph neural network. ACM Trans. Softw. Eng. Methodol., 30(3):38:1\u201338:33, 2021.","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"e_1_3_2_1_16_1","unstructured":"CISA. Ransomware activity targeting the healthcare and public health sector. https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa20-302a. Accessed: 11\/2023."},{"key":"e_1_3_2_1_17_1","first-page":"41","volume-title":"IEEE European Symposium on Security and Privacy, EuroS&P 2023 - Workshops","author":"de Kraker Wesley","year":"2023","unstructured":"Wesley de Kraker, Harald Vranken, and Arjen Hommersom. GLICE: combining graph neural networks and program slicing to improve software vulnerability detection. In IEEE European Symposium on Security and Privacy, EuroS&P 2023 - Workshops, Delft, Netherlands, July 3-7, 2023, pages 34\u201341. IEEE, 2023."},{"key":"e_1_3_2_1_18_1","volume-title":"ECOOP'95 - Object-Oriented Programming, 9th European Conference, \u00c5rhus, Denmark","volume":"952","author":"Dean Jeffrey","year":"1995","unstructured":"Jeffrey Dean, David Grove, and Craig Chambers. Optimization of object-oriented programs using static class hierarchy analysis. In Walter G. Olthoff, editor, ECOOP'95 - Object-Oriented Programming, 9th European Conference, \u00c5rhus, Denmark, August 7-11, 1995, Proceedings, volume 952 of Lecture Notes in Computer Science, pages 77\u2013101. Springer, 1995."},{"key":"e_1_3_2_1_19_1","volume-title":"Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024","author":"Ding Yangruibo","year":"2024","unstructured":"Yangruibo Ding, Jinjun Peng, Marcus J. Min, Gail E. Kaiser, Junfeng Yang, and Baishakhi Ray. Semcoder: Training code language models with comprehensive semantics reasoning. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024, Vancouver, BC, Canada, December 10 - 15, 2024, 2024."},{"key":"e_1_3_2_1_20_1","volume-title":"TRACED: execution-aware pre-training for source code. CoRR, abs\/2306.07487","author":"Ding Yangruibo","year":"2023","unstructured":"Yangruibo Ding, Benjamin Steenhoek, Kexin Pei, Gail E. Kaiser, Wei Le, and Baishakhi Ray. TRACED: execution-aware pre-training for source code. CoRR, abs\/2306.07487, 2023."},{"key":"e_1_3_2_1_21_1","volume-title":"Forty-first International Conference on Machine Learning, ICML 2024","author":"Florian","year":"2024","unstructured":"Florian E. Dorner and Moritz Hardt. Don't label twice: Quantity beats quality when comparing binary classifiers on a budget. In Forty-first International Conference on Machine Learning, ICML 2024, Vienna, Austria, July 21-27, 2024. OpenReview.net, 2024."},{"key":"e_1_3_2_1_22_1","series-title":"Findings of ACL","first-page":"1547","volume-title":"Findings of the Association for Computational Linguistics: EMNLP","author":"Feng Zhangyin","year":"2020","unstructured":"Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, Daxin Jiang, and Ming Zhou. Codebert: A pre-trained model for programming and natural languages. In Findings of the Association for Computational Linguistics: EMNLP 2020, Online Event, 16\u201320 November 2020, volume EMNLP 2020 of Findings of ACL, pages 1536\u20131547. Association for Computational Linguistics, 2020."},{"key":"e_1_3_2_1_23_1","unstructured":"FindSecBugs. Injection sinks. https:\/\/github.com\/find-sec-bugs\/find-sec-bugs\/tree\/master\/findsecbugs-plugin\/src\/main\/resources\/injection-sinks Accessed: 11\/2023."},{"key":"e_1_3_2_1_24_1","first-page":"620","volume-title":"19th IEEE\/ACM International Conference on Mining Software Repositories, MSR 2022","author":"Fu Michael","year":"2022","unstructured":"Michael Fu and Chakkrit Tantithamthavorn. Linevul: A transformer-based linelevel vulnerability prediction. In 19th IEEE\/ACM International Conference on Mining Software Repositories, MSR 2022, Pittsburgh, PA, USA, May 23-24, 2022, pages 608\u2013620. ACM, 2022."},{"key":"e_1_3_2_1_25_1","unstructured":"Geoserver. [geos-11390] replace testwfspost with javascript demo page. https:\/\/github.com\/geoserver\/geoserver\/pull\/7672. Accessed: 11\/2024."},{"key":"e_1_3_2_1_26_1","unstructured":"Github. Codeql. https:\/\/codeql.github.com\/ Accessed: 11\/2023."},{"key":"e_1_3_2_1_27_1","volume-title":"Forty-first International Conference on Machine Learning, ICML 2024","author":"Gu Alex","year":"2024","unstructured":"Alex Gu, Baptiste Rozi\u00e8re, Hugh James Leather, Armando Solar-Lezama, Gabriel Synnaeve, and Sida Wang. Cruxeval: A benchmark for code reasoning, understanding and execution. In Forty-first International Conference on Machine Learning, ICML 2024, Vienna, Austria, July 21-27, 2024. OpenReview.net, 2024."},{"key":"e_1_3_2_1_28_1","unstructured":"Guardsquare. Proguard. https:\/\/github.com\/Guardsquare\/Proguard Accessed: 11\/2023."},{"key":"e_1_3_2_1_29_1","first-page":"7225","volume-title":"Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), ACL 2022","author":"Guo Daya","year":"2022","unstructured":"Daya Guo, Shuai Lu, Nan Duan, Yanlin Wang, Ming Zhou, and Jian Yin. Unixcoder: Unified cross-modal pre-training for code representation. In Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), ACL 2022, Dublin, Ireland, May 22-27, 2022, pages 7212\u20137225. Association for Computational Linguistics, 2022."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_3_2_1_31_1","unstructured":"JetBrains. Fernflower decompiler. https:\/\/github.com\/JetBrains\/intellij-community\/tree\/master\/plugins\/java-decompiler\/engine Accessed: 11\/2023."},{"key":"e_1_3_2_1_32_1","unstructured":"Johnb110. Vdpython. https:\/\/github.com\/johnb110\/VDPython Accessed: 04\/2025."},{"key":"e_1_3_2_1_33_1","volume-title":"Understanding the effectiveness of large language models in detecting security vulnerabilities. CoRR, abs\/2311.16169","author":"Khare Avishree","year":"2023","unstructured":"Avishree Khare, Saikat Dutta, Ziyang Li, Alaia Solko-Breslin, Rajeev Alur, and Mayur Naik. Understanding the effectiveness of large language models in detecting security vulnerabilities. CoRR, abs\/2311.16169, 2023."},{"key":"e_1_3_2_1_34_1","volume-title":"Symbolic execution and program testing","author":"King James C.","year":"1976","unstructured":"James C. King. Symbolic execution and program testing. 1976."},{"key":"e_1_3_2_1_35_1","volume-title":"LONGCODEU: benchmarking long-context language models on long code understanding. CoRR, abs\/2503.04359","author":"Li Jia","year":"2025","unstructured":"Jia Li, Xuyuan Guo, Lei Li, Kechi Zhang, Ge Li, Jia Li, Zhengwei Tao, Fang Liu, Chongyang Tao, Yuqi Zhu, and Zhi Jin. LONGCODEU: benchmarking long-context language models on long code understanding. CoRR, abs\/2503.04359, 2025."},{"key":"e_1_3_2_1_36_1","first-page":"303","volume-title":"ESEC\/FSE '21: 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering","author":"Li Yi","year":"2021","unstructured":"Yi Li, Shaohua Wang, and Tien N. Nguyen. Vulnerability detection with finegrained interpretations. In ESEC\/FSE '21: 29th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Athens, Greece, August 23-28, 2021, pages 292\u2013303. ACM, 2021."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.21227\/fhg0-1b35"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23158"},{"key":"e_1_3_2_1_39_1","volume-title":"The Thirteenth International Conference on Learning Representations, ICLR 2025","author":"Li Ziyang","year":"2025","unstructured":"Ziyang Li, Saikat Dutta, and Mayur Naik. IRIS: llm-assisted static analysis for detecting security vulnerabilities. In The Thirteenth International Conference on Learning Representations, ICLR 2025, Singapore, April 24-28, 2025. OpenReview.net, 2025."},{"key":"e_1_3_2_1_40_1","volume-title":"Lost in the middle: How language models use long contexts. CoRR, abs\/2307.03172","author":"Liu Nelson F.","year":"2023","unstructured":"Nelson F. Liu, Kevin Lin, John Hewitt, Ashwin Paranjape, Michele Bevilacqua, Fabio Petroni, and Percy Liang. Lost in the middle: How language models use long contexts. CoRR, abs\/2307.03172, 2023."},{"key":"e_1_3_2_1_41_1","volume-title":"DIMVA 2023, Hamburg, Germany, July 12-14, 2023, Proceedings","volume":"13959","author":"Loose Nils","year":"2023","unstructured":"Nils Loose, Felix M\u00e4chtle, Claudius Pott, Volodymyr Bezsmertnyi, and Thomas Eisenbarth. Madvex: Instrumentation-based adversarial attacks on machine learning malware detection. In Detection of Intrusions and Malware, and Vulnerability Assessment - 20th International Conference, DIMVA 2023, Hamburg, Germany, July 12-14, 2023, Proceedings, volume 13959 of Lecture Notes in Computer Science, pages 69\u201388. Springer, 2023."},{"key":"e_1_3_2_1_42_1","series-title":"Lecture Notes in Computer Science","first-page":"405","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems - 30th International Conference, TACAS","author":"Loose Nils","year":"2024","unstructured":"Nils Loose, Felix M\u00e4chtle, Florian Sieck, and Thomas Eisenbarth. SWAT: modular dynamic symbolic execution for java applications using dynamic instrumentation (competition contribution). In Tools and Algorithms for the Construction and Analysis of Systems - 30th International Conference, TACAS 2024, Held as Part of the European Joint Conferences on Theory and Practice of Software, ETAPS 2024, Luxembourg City, Luxembourg, April 6-11, 2024, Proceedings, Part III, volume 14572 of Lecture Notes in Computer Science, pages 399\u2013405. Springer, 2024."},{"key":"e_1_3_2_1_43_1","volume-title":"The Twelfth International Conference on Learning Representations, ICLR 2024","author":"Luo Ziyang","year":"2024","unstructured":"Ziyang Luo, Can Xu, Pu Zhao, Qingfeng Sun, Xiubo Geng, Wenxiang Hu, Chongyang Tao, Jing Ma, Qingwei Lin, and Daxin Jiang. Wizardcoder: Empowering code large language models with evol-instruct. In The Twelfth International Conference on Learning Representations, ICLR 2024, Vienna, Austria, May 7-11, 2024. OpenReview.net, 2024."},{"key":"e_1_3_2_1_44_1","first-page":"52","volume-title":"22nd IEEE International Conference on Software Quality, Reliability and Security, QRS 2022","author":"Mamede Cl\u00e1udia","year":"2022","unstructured":"Cl\u00e1udia Mamede, Eduard Pinconschi, Rui Abreu, and Jos\u00e9 Campos. Exploring transformers for multi-label classification of java vulnerabilities. In 22nd IEEE International Conference on Software Quality, Reliability and Security, QRS 2022, Guangzhou, China, December 5-9, 2022, pages 43\u201352. IEEE, 2022."},{"key":"e_1_3_2_1_45_1","first-page":"5","volume-title":"Proceedings of the 15th International Conference on Mining Software Repositories, MSR 2018","author":"Martins Pedro","year":"2018","unstructured":"Pedro Martins, Rohan Achar, and Cristina V. Lopes. 50k-c: a dataset of compilable, and compiled, java projects. In Proceedings of the 15th International Conference on Mining Software Repositories, MSR 2018, Gothenburg, Sweden, May 28-29, 2018, pages 1\u20135. ACM, 2018."},{"key":"e_1_3_2_1_46_1","first-page":"6574","volume-title":"32nd USENIX Security Symposium, USENIX Security 2023","author":"Mirsky Yisroel","year":"2023","unstructured":"Yisroel Mirsky, George Macon, Michael D. Brown, Carter Yagemann, Matthew Pruett, Evan Downing, J. Sukarno Mertoguno, and Wenke Lee. Vulchecker: Graph-based vulnerability localization in source code. In 32nd USENIX Security Symposium, USENIX Security 2023, Anaheim, CA, USA, August 9-11, 2023, pages 6557\u20136574. USENIX Association, 2023."},{"key":"e_1_3_2_1_47_1","volume-title":"Ocean: Open-world contrastive authorship identification. CoRR, abs\/2412.05049","author":"M\u00e4chtle Felix","year":"2024","unstructured":"Felix M\u00e4chtle, Jan-Niclas Serr, Nils Loose, Jonas Sander, and Thomas Eisenbarth. Ocean: Open-world contrastive authorship identification. CoRR, abs\/2412.05049, 2024."},{"key":"e_1_3_2_1_48_1","volume-title":"Van Nguyen, Trung Le, Quan Hung Tran, and Dinh Q. Phung. Regvd: Revisiting graph neural networks for vulnerability detection. CoRR, abs\/2110.07317","author":"Nguyen Van-Anh","year":"2021","unstructured":"Van-Anh Nguyen, Dai Quoc Nguyen, Van Nguyen, Trung Le, Quan Hung Tran, and Dinh Q. Phung. Regvd: Revisiting graph neural networks for vulnerability detection. CoRR, abs\/2110.07317, 2021."},{"key":"e_1_3_2_1_49_1","unstructured":"OpenAI. Hello gpt-4o. https:\/\/openai.com\/index\/hello-gpt-4o\/. Accessed: 09\/2024."},{"key":"e_1_3_2_1_50_1","unstructured":"OWASP. Owasp top ten. https:\/\/owasp.org\/www-project-top-ten\/. Accessed: 11\/2023."},{"key":"e_1_3_2_1_51_1","series-title":"Lecture Notes in Business Information Processing","first-page":"103","volume-title":"Agile Processes in Software Engineering and Extreme Programming - 19th International Conference, XP","author":"Oyetoyan Tosin Daniel","year":"2018","unstructured":"Tosin Daniel Oyetoyan, Bisera Milosheska, Mari Grini, and Daniela Soares Cruzes. Myths and facts about static application security testing tools: An action research at telenor digital. In Agile Processes in Software Engineering and Extreme Programming - 19th International Conference, XP 2018, Porto, Portugal, May 21-25, 2018, Proceedings, volume 314 of Lecture Notes in Business Information Processing, pages 86\u2013103. Springer, 2018."},{"key":"e_1_3_2_1_52_1","first-page":"1482","volume-title":"COMPSAC 2021","author":"Partenza Garrett","year":"2021","unstructured":"Garrett Partenza, Trevor Amburgey, Lin Deng, Josh Dehlinger, and Suranjan Chakraborty. Automatic identification of vulnerable code: Investigations with an ast-based neural network. In IEEE 45th Annual Computers, Software, and Applications Conference, COMPSAC 2021, Madrid, Spain, July 12-16, 2021, pages 1475\u20131482. IEEE, 2021."},{"key":"e_1_3_2_1_53_1","series-title":"Proceedings of Machine Learning Research","first-page":"8486","volume-title":"ICML","author":"Peng Dinglan","year":"2021","unstructured":"Dinglan Peng, Shuxin Zheng, Yatao Li, Guolin Ke, Di He, and Tie-Yan Liu. How could neural networks understand programs? In Proceedings of the 38th International Conference on Machine Learning, ICML 2021, 18\u201324 July 2021, Virtual Event, volume 139 of Proceedings of Machine Learning Research, pages 8476\u20138486. PMLR, 2021."},{"key":"e_1_3_2_1_54_1","unstructured":"r2c. Semgrep. https:\/\/semgrep.dev\/. Accessed: 11\/2023."},{"key":"e_1_3_2_1_55_1","volume-title":"Longcodebench: Evaluating coding llms at 1m context windows. CoRR, abs\/2505.07897","author":"Rando Stefano","year":"2025","unstructured":"Stefano Rando, Luca Romani, Alessio Sampieri, Yuta Kyuragi, Luca Franco, Fabio Galasso, Tatsunori Hashimoto, and John Yang. Longcodebench: Evaluating coding llms at 1m context windows. CoRR, abs\/2505.07897, 2025."},{"key":"e_1_3_2_1_56_1","volume-title":"33rd USENIX Security Symposium, USENIX Security 2024","author":"Risse Niklas","year":"2024","unstructured":"Niklas Risse and Marcel B\u00f6hme. Uncovering the limits of machine learning for automatic vulnerability detection. In 33rd USENIX Security Symposium, USENIX Security 2024, Philadelphia, PA, USA, August 14-16, 2024. USENIX Association, 2024."},{"key":"e_1_3_2_1_57_1","first-page":"121","volume-title":"34th IEEE\/ACM International Conference on Automated Software Engineering Workshops, ASE Workshops 2019","author":"Saccente Nicholas","year":"2019","unstructured":"Nicholas Saccente, Josh Dehlinger, Lin Deng, Suranjan Chakraborty, and Yin Xiong. Project achilles: A prototype tool for static method-level vulnerability detection of java source code using a recurrent neural network. In 34th IEEE\/ACM International Conference on Automated Software Engineering Workshops, ASE Workshops 2019, San Diego, CA, USA, November 11-15, 2019, pages 114\u2013121. IEEE, 2019."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2025.3546700"},{"key":"e_1_3_2_1_59_1","unstructured":"ShiftLeft. Joern - the bug hunter's workbench. https:\/\/joern.io\/. Accessed: 2022-08-7."},{"key":"e_1_3_2_1_60_1","unstructured":"ShiftLeftSecurity. Shiftleft scan. https:\/\/github.com\/ShiftLeftSecurity\/sast-scan. Accessed: 12\/2024."},{"key":"e_1_3_2_1_61_1","first-page":"174","volume-title":"Proceedings of the ACM SIGPLAN'88 Conference on Programming Language Design and Implementation (PLDI)","author":"Shivers Olin","year":"1988","unstructured":"Olin Shivers. Control-flow analysis in scheme. In Richard L. Wexelblat, editor, Proceedings of the ACM SIGPLAN'88 Conference on Programming Language Design and Implementation (PLDI), Atlanta, Georgia, USA, June 22-24, 1988, pages 164\u2013174. ACM, 1988."},{"key":"e_1_3_2_1_62_1","first-page":"6","volume-title":"11th International Conference on Computing, Communication and Networking Technologies, ICCCNT 2020","author":"Singh Navneet","year":"2020","unstructured":"Navneet Singh, Vishtasp Meherhomji, and B. R. Chandavarkar. Automated versus manual approach of web application penetration testing. In 11th International Conference on Computing, Communication and Networking Technologies, ICCCNT 2020, Kharagpur, India, July 1-3, 2020, pages 1\u20136. IEEE, 2020."},{"key":"e_1_3_2_1_63_1","volume-title":"Most used programming languages among developers worldwide as of","year":"2024","unstructured":"Statista. Most used programming languages among developers worldwide as of 2024. https:\/\/www.statista.com\/statistics\/793628\/worldwide-developer-survey-most-used-languages\/, 2024."},{"key":"e_1_3_2_1_64_1","first-page":"13","volume-title":"Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, ICSE 2024","author":"Steenhoek Benjamin","year":"2024","unstructured":"Benjamin Steenhoek, Hongyang Gao, and Wei Le. Dataflow analysis-inspired deep learning for efficient vulnerability detection. In Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, ICSE 2024, Lisbon, Portugal, April 14-20, 2024, pages 16:1\u201316:13. ACM, 2024."},{"key":"e_1_3_2_1_65_1","unstructured":"Tree-sitter. https:\/\/tree-sitter.github.io\/tree-sitter\/ Accessed: 2022-11-23."},{"key":"e_1_3_2_1_66_1","volume-title":"Can large language models identify and reason about security vulnerabilities? not yet. CoRR, abs\/2312.12575","author":"Ullah Saad","year":"2023","unstructured":"Saad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce, Ayse K. Coskun, and Gianluca Stringhini. Can large language models identify and reason about security vulnerabilities? not yet. CoRR, abs\/2312.12575, 2023."},{"key":"e_1_3_2_1_67_1","first-page":"880","volume-title":"IEEE Symposium on Security and Privacy, SP 2024","author":"Ullah Saad","year":"2024","unstructured":"Saad Ullah, Mingji Han, Saurabh Pujar, Hammond Pearce, Ayse K. Coskun, and Gianluca Stringhini. Llms cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks. In IEEE Symposium on Security and Privacy, SP 2024, San Francisco, CA, USA, May 19-23, 2024, pages 862\u2013880. IEEE, 2024."},{"key":"e_1_3_2_1_68_1","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N. Gomez, Lukasz Kaiser, and Illia Polosukhin. Attention is all you need. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, December 4-9, 2017, Long Beach, CA, USA, pages 5998\u20136008, 2017."},{"key":"e_1_3_2_1_69_1","volume-title":"softmax is not enough (for sharp out-of-distribution). CoRR, abs\/2410.01104","author":"Velickovic Petar","year":"2024","unstructured":"Petar Velickovic, Christos Perivolaropoulos, Federico Barbero, and Razvan Pascanu. softmax is not enough (for sharp out-of-distribution). CoRR, abs\/2410.01104, 2024."},{"key":"e_1_3_2_1_70_1","unstructured":"WALA. The t. j. watson libraries for analysis. https:\/\/wala.sourceforge.net\/. Accessed: 2022-11-29."},{"key":"e_1_3_2_1_71_1","volume-title":"Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024","author":"Wang Chengpeng","year":"2024","unstructured":"Chengpeng Wang, Wuqi Zhang, Zian Su, Xiangzhe Xu, Xiaoheng Xie, and Xiangyu Zhang. LLMDFA: analyzing dataflow in code with large language models. In Advances in Neural Information Processing Systems 38: Annual Conference on Neural Information Processing Systems 2024, NeurIPS 2024, Vancouver, BC, Canada, December 10 - 15, 2024, 2024."},{"key":"e_1_3_2_1_72_1","first-page":"13","volume-title":"Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, ICSE 2024","author":"Wang Huanting","year":"2024","unstructured":"Huanting Wang, Zhanyong Tang, Shin Hwei Tan, Jie Wang, Yuzhe Liu, Hejun Fang, Chunwei Xia, and Zheng Wang. Combining structured static code information and dynamic symbolic traces for software vulnerability prediction. In Proceedings of the 46th IEEE\/ACM International Conference on Software Engineering, ICSE 2024, Lisbon, Portugal, April 14-20, 2024, pages 169:1\u2013169:13. ACM, 2024."},{"key":"e_1_3_2_1_73_1","first-page":"134","volume-title":"Proceedings of the 41st ACM SIGPLAN International Conference on Programming Language Design and Implementation, PLDI 2020","author":"Wang Ke","year":"2020","unstructured":"Ke Wang and Zhendong Su. Blended, precise semantic program embeddings. In Proceedings of the 41st ACM SIGPLAN International Conference on Programming Language Design and Implementation, PLDI 2020, London, UK, June 15-20, 2020, pages 121\u2013134. ACM, 2020."},{"key":"e_1_3_2_1_74_1","volume-title":"Nghi D. Q. Bui, Junnan Li, and Steven C. H. Hoi. Codet5+: Open code large language models for code understanding and generation. CoRR, abs\/2305.07922","author":"Wang Yue","year":"2023","unstructured":"Yue Wang, Hung Le, Akhilesh Deepak Gotmare, Nghi D. Q. Bui, Junnan Li, and Steven C. H. Hoi. Codet5+: Open code large language models for code understanding and generation. CoRR, abs\/2305.07922, 2023."},{"key":"e_1_3_2_1_75_1","first-page":"449","volume-title":"Proceedings of the 5th International Conference on Software Engineering","author":"Weiser Mark D.","year":"1981","unstructured":"Mark D. Weiser. Program slicing. In Proceedings of the 5th International Conference on Software Engineering, San Diego, California, USA, March 9-12, 1981, pages 439\u2013449. IEEE Computer Society, 1981."},{"key":"e_1_3_2_1_76_1","first-page":"1383","volume-title":"Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/FSE 2023","author":"Wu Bozhi","year":"2023","unstructured":"Bozhi Wu, Shangqing Liu, Yang Xiao, Zhiming Li, Jun Sun, and Shang-Wei Lin. Learning program semantics for vulnerability detection via vulnerability-specific inter-procedural slicing. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/FSE 2023, San Francisco, CA, USA, December 3-9, 2023, pages 1371\u20131383. ACM, 2023."},{"key":"e_1_3_2_1_77_1","first-page":"389","volume-title":"32nd IEEE International Symposium on Software Reliability Engineering, ISSRE 2021","author":"Wu Hongjun","year":"2021","unstructured":"Hongjun Wu, Zhuo Zhang, Shangwen Wang, Yan Lei, Bo Lin, Yihao Qin, Haoyu Zhang, and Xiaoguang Mao. Peculiar: Smart contract vulnerability detection based on crucial data flow graph and pre-training techniques. In 32nd IEEE International Symposium on Software Reliability Engineering, ISSRE 2021, Wuhan, China, October 25-28, 2021, pages 378\u2013389. IEEE, 2021."},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.44"},{"key":"e_1_3_2_1_79_1","first-page":"812","volume-title":"2015 IEEE Symposium on Security and Privacy, SP 2015","author":"Yamaguchi Fabian","year":"2015","unstructured":"Fabian Yamaguchi, Alwin Maier, Hugo Gascon, and Konrad Rieck. Automatic inference of search patterns for taint-style vulnerabilities. In 2015 IEEE Symposium on Security and Privacy, SP 2015, San Jose, CA, USA, May 17-21, 2015, pages 797\u2013812. IEEE Computer Society, 2015."},{"key":"e_1_3_2_1_80_1","volume-title":"The Fuzzing Book","author":"Zeller Andreas","year":"2024","unstructured":"Andreas Zeller, Rahul Gopinath, Marcel B\u00f6hme, Gordon Fraser, and Christian Holler. The Fuzzing Book. CISPA Helmholtz Center for Information Security, 2024. Retrieved 2024-07-01 16:50:18+02:00."},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2021.3072154"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.3390\/s24051351"},{"key":"e_1_3_2_1_83_1","first-page":"184","volume-title":"Proceedings of the 14th Asia-Pacific Symposium on Internetware, Internetware 2023","author":"Zhang Yuting","year":"2023","unstructured":"Yuting Zhang, Jiahao Zhu, Yixin Yang, Ming Wen, and Hai Jin. Comparing the performance of different code representations for learning-based vulnerability detection. In Proceedings of the 14th Asia-Pacific Symposium on Internetware, Internetware 2023, Hangzhou, China, August 4-6, 2023, pages 174\u2013184. ACM, 2023."},{"key":"e_1_3_2_1_84_1","volume-title":"A comprehensive survey on pretrained foundation models: A history from BERT to chatgpt. CoRR, abs\/2302.09419","author":"Zhou Ce","year":"2023","unstructured":"Ce Zhou, Qian Li, Chen Li, Jun Yu, Yixin Liu, Guangjing Wang, Kai Zhang, Cheng Ji, Qiben Yan, Lifang He, Hao Peng, Jianxin Li, Jia Wu, Ziwei Liu, Pengtao Xie, Caiming Xiong, Jian Pei, Philip S. Yu, and Lichao Sun. A comprehensive survey on pretrained foundation models: A history from BERT to chatgpt. CoRR, abs\/2302.09419, 2023."},{"key":"e_1_3_2_1_85_1","first-page":"10207","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jing Kai Siow, Xiaoning Du, and Yang Liu. Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada, pages 10197\u201310207, 2019."}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785375","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:26:07Z","timestamp":1780586767000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785375"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":85,"alternative-id":["10.1145\/3779208.3785375","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785375","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}