{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T14:31:59Z","timestamp":1787495519485,"version":"build-2736575974"},"reference-count":52,"publisher":"Association for Computing Machinery (ACM)","issue":"ISSTA","license":[{"start":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T00:00:00Z","timestamp":1750550400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/100017052","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["Grant No. 62372114 and 62332005"],"award-info":[{"award-number":["Grant No. 62372114 and 62332005"]}],"id":[{"id":"10.13039\/100017052","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2025,6,22]]},"abstract":"<jats:p>With the rapid development of open-source software, code reuse has become a common practice to accelerate development. However, it leads to inheritance from the original vulnerability, which recurs at the reusing projects, known as recurring vulnerabilities (RVs). Traditional general-purpose vulnerability detection approaches struggle with scalability and adaptability, while learning-based approaches are often constrained by limited training datasets and are less effective against unseen vulnerabilities. Though specific recurring vulnerability detection (RVD) approaches have been proposed, their effectiveness across various RV characteristics remains unclear.<\/jats:p>\n                  <jats:p>\n                    In this paper, we conduct a large-scale empirical study using a newly constructed RV dataset containing 4,569 RVs, achieving a 953% expansion over prior RV datasets. Our study analyzes the characteristics of RVs, evaluates the effectiveness of the state-of-the-art RVD approaches, and investigates the root causes of false positives and false negatives, yielding key insights. Inspired by these insights, we design A\n                    <jats:sc>nt<\/jats:sc>\n                    M\n                    <jats:sc>an<\/jats:sc>\n                    , a novel RVD approach that identifies both explicit and implicit call relations with modified functions, then employs inter-procedural taint analysis and intra-procedural dependency slicing within those functions to generate comprehensive signatures, and finally incorporates a flexible matching to detect RVs. Our evaluation has shown the effectiveness, generality and practical usefulness in RVD. A\n                    <jats:sc>nt<\/jats:sc>\n                    M\n                    <jats:sc>an<\/jats:sc>\n                    has detected 4,593 RVs, with 307 confirmed by developers, and identified 73 new 0-day vulnerabilities across 15 projects, receiving 5 CVE identifiers.\n                  <\/jats:p>","DOI":"10.1145\/3728901","type":"journal-article","created":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T10:53:21Z","timestamp":1750589601000},"page":"573-595","source":"Crossref","is-referenced-by-count":3,"title":["Recurring Vulnerability Detection: How Far Are We?"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-6101-8270","authenticated-orcid":false,"given":"Yiheng","family":"Cao","sequence":"first","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2169-7032","authenticated-orcid":false,"given":"Susheng","family":"Wu","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-8404-4794","authenticated-orcid":false,"given":"Ruisi","family":"Wang","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7238-7492","authenticated-orcid":false,"given":"Bihuan","family":"Chen","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4722-3658","authenticated-orcid":false,"given":"Yiheng","family":"Huang","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-3377-9807","authenticated-orcid":false,"given":"Chenhao","family":"Lu","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7819-9656","authenticated-orcid":false,"given":"Zhuotong","family":"Zhou","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science and Shanghai Key Laboratory of Data Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3376-2581","authenticated-orcid":false,"given":"Xin","family":"Peng","sequence":"additional","affiliation":[{"name":"Fudan University, School of Computer Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,22]]},"reference":[{"key":"e_1_3_1_2_2","first-page":"1","article-title":"Coca: Improving and Explaining Graph Neural Network-Based Vulnerability Detection Systems","author":"Cao Sicong","year":"2024","unstructured":"Sicong Cao, Xiaobing Sun, Xiaoxue Wu, David Lo, Lili Bo, Bin Li, and Wei Liu. 2024. Coca: Improving and Explaining Graph Neural Network-Based Vulnerability Detection Systems. In Proceedings of the 46th International Conference on Software Engineering. 1\u201313.","journal-title":"Proceedings of the 46th International Conference on Software Engineering"},{"key":"e_1_3_1_3_2","unstructured":"Checkmarx. 2024. Checkmarx. Retrieved October 25 2024 from https:\/\/checkmarx.com\/"},{"key":"e_1_3_1_4_2","first-page":"2095","article-title":"Hawkeye: Towards a desired directed grey-box fuzzer","author":"Chen Hongxu","year":"2018","unstructured":"Hongxu Chen, Yinxing Xue, Yuekang Li, Bihuan Chen, Xiaofei Xie, Xiuheng Wu, and Yang Liu. 2018. Hawkeye: Towards a desired directed grey-box fuzzer. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security. 2095\u20132108.","journal-title":"Proceedings of the 2018 ACM SIGSAC conference on computer and communications security"},{"key":"e_1_3_1_5_2","article-title":"Structure-Aware, Diagnosis-Guided ECU Firmware Fuzzing","author":"Chen Qicai","year":"2025","unstructured":"Qicai Chen, Kun Hu, Sichen Gong, Bihuan Chen, kevin kong, Haowen Jiang, Bingkun Sun, You Lu, and Xin Peng. 2025. Structure-Aware, Diagnosis-Guided ECU Firmware Fuzzing. In Proceedings of the 34th ACM SIGSOFT International Symposium on Software Testing and Analysis.","journal-title":"Proceedings of the 34th ACM SIGSOFT International Symposium on Software Testing and Analysis"},{"issue":"2020","key":"e_1_3_1_6_2","first-page":"2004","article-title":"Vuldetector: Detecting vulnerabilities using weighted feature graph comparison","volume":"16","author":"Cui Lei","year":"2020","unstructured":"Lei Cui, Zhiyu Hao, Yang Jiao, Haiqiang Fei, and Xiaochun Yun. 2020. Vuldetector: Detecting vulnerabilities using weighted feature graph comparison. IEEE Transactions on Information Forensics and Security 16 (2020), 2004\u20132017.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_1_7_2","first-page":"463","article-title":"{FIE} on firmware: Finding vulnerabilities in embedded systems using symbolic execution","author":"Davidson Drew","year":"2013","unstructured":"Drew Davidson, Benjamin Moench, Thomas Ristenpart, and Somesh Jha. 2013. {FIE} on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In Proceedings of the 22 USENIX Security Symposium. 463\u2013478.","journal-title":"Proceedings of the 22 USENIX Security Symposium"},{"key":"e_1_3_1_8_2","first-page":"60","article-title":"Leopard: Identifying vulnerable code for vulnerability assessment through program metrics","author":"Du Xiaoning","year":"2019","unstructured":"Xiaoning Du, Bihuan Chen, Yuekang Li, Jianmin Guo, Yaqin Zhou, Yang Liu, and Yu Jiang. 2019. Leopard: Identifying vulnerable code for vulnerability assessment through program metrics. In Proceedings of the 41st International Conference on Software Engineering. 60\u201371.","journal-title":"Proceedings of the 41st International Conference on Software Engineering"},{"key":"e_1_3_1_9_2","first-page":"158","article-title":"Tracking code clones in evolving software","author":"Duala-Ekoko Ekwa","year":"2007","unstructured":"Ekwa Duala-Ekoko and Martin P Robillard. 2007. Tracking code clones in evolving software. In Proceedings of the 29th International Conference on Software Engineering. 158\u2013167.","journal-title":"Proceedings of the 29th International Conference on Software Engineering"},{"key":"e_1_3_1_10_2","first-page":"2169","article-title":"Identifying open-source license violation and 1-day security risk at large scale","author":"Duan Ruian","year":"2017","unstructured":"Ruian Duan, Ashish Bijlani, Meng Xu, Taesoo Kim, and Wenke Lee. 2017. Identifying open-source license violation and 1-day security risk at large scale. In Proceedings of the 2017 ACM SIGSAC Conference on computer and communications security. 2169\u20132185.","journal-title":"Proceedings of the 2017 ACM SIGSAC Conference on computer and communications security"},{"key":"e_1_3_1_11_2","first-page":"1867","article-title":"{FIRE}: Combining {Multi-Stage} Filtering with Taint Analysis for Scalable Recurring Vulnerability Detection","author":"Feng Siyue","year":"2024","unstructured":"Siyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan, Deqing Zou, Yang Liu, and Hai Jin. 2024. {FIRE}: Combining {Multi-Stage} Filtering with Taint Analysis for Scalable Recurring Vulnerability Detection. In 33rd USENIX Security Symposium (USENIX Security 24). 1867\u20131884.","journal-title":"33rd USENIX Security Symposium (USENIX Security 24)"},{"key":"e_1_3_1_12_2","unstructured":"GitHub. 2024. CodeQL. Retrieved October 25 2024 from https:\/\/codeql.github.com\/"},{"key":"e_1_3_1_13_2","unstructured":"gpac. 2024. CVE-2022-46489. Retrieved October 25 2024 from https:\/\/github.com\/gpac\/gpac\/commit\/44e8616ec6d0c37498cdacb81375b09249fa9daa"},{"key":"e_1_3_1_14_2","article-title":"Unixcoder: Unified cross-modal pre-training for code representation","author":"Guo Daya","year":"2022","unstructured":"Daya Guo, Shuai Lu, Nan Duan, Yanlin Wang, Ming Zhou, and Jian Yin. 2022. Unixcoder: Unified cross-modal pre-training for code representation. arXiv preprint arXiv:2203.03850 (2022).","journal-title":"arXiv preprint arXiv:2203.03850"},{"key":"e_1_3_1_15_2","first-page":"3958","article-title":"VMUD: Detecting Recurring Vulnerabilities with Multiple Fixing Functions via Function Selection and Semantic Equivalent Statement Matching","author":"Huang Kaifeng","year":"2024","unstructured":"Kaifeng Huang, Chenhao Lu, Yiheng Cao, Bihuan Chen, and Xin Peng. 2024. VMUD: Detecting Recurring Vulnerabilities with Multiple Fixing Functions via Function Selection and Semantic Equivalent Statement Matching. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 3958\u20133972.","journal-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1109\/SP.2012.13","volume-title":"2012 IEEE Symposium on Security and Privacy","author":"Jang Jiyong","year":"2012","unstructured":"Jiyong Jang, Abeer Agrawal, and David Brumley. 2012. ReDeBug: finding unpatched code clones in entire os distributions. In 2012 IEEE Symposium on Security and Privacy. IEEE, 48\u201362."},{"key":"e_1_3_1_17_2","first-page":"258","article-title":"Pixy: A static analysis tool for detecting web application vulnerabilities","author":"Jovanovic Nenad","year":"2006","unstructured":"Nenad Jovanovic, Christopher Kruegel, and Engin Kirda. 2006. Pixy: A static analysis tool for detecting web application vulnerabilities. In Proceedings of the Symposium on Security and Privacy. 258\u2013263.","journal-title":"Proceedings of the Symposium on Security and Privacy"},{"key":"e_1_3_1_18_2","first-page":"1695","article-title":"Tracer: Signature-based static analysis for detecting recurring vulnerabilities","author":"Kang Wooseok","year":"2022","unstructured":"Wooseok Kang, Byoungho Son, and Kihong Heo. 2022. Tracer: Signature-based static analysis for detecting recurring vulnerabilities. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 1695\u20131708.","journal-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security"},{"key":"e_1_3_1_19_2","first-page":"595","article-title":"Vuddy: A scalable approach for vulnerable code clone discovery","author":"Kim Seulbae","year":"2017","unstructured":"Seulbae Kim, Seunghoon Woo, Heejo Lee, and Hakjoo Oh. 2017. Vuddy: A scalable approach for vulnerable code clone discovery. In Proceedings of the Symposium on Security and Privacy. 595\u2013614.","journal-title":"Proceedings of the Symposium on Security and Privacy"},{"key":"e_1_3_1_20_2","first-page":"272","article-title":"SAGA: efficient and large-scale detection of near-miss clones with GPU acceleration","author":"Li Guanhua","year":"2020","unstructured":"Guanhua Li, Yijian Wu, Chanchal K Roy, Jun Sun, Xin Peng, Nanjie Zhan, Bin Hu, and Jingyi Ma. 2020. SAGA: efficient and large-scale detection of near-miss clones with GPU acceleration. In Proceedings of the 2020 IEEE 27th International Conference on Software Analysis, Evolution and Reengineering. 272\u2013283.","journal-title":"Proceedings of the 2020 IEEE 27th International Conference on Software Analysis, Evolution and Reengineering"},{"key":"e_1_3_1_21_2","first-page":"627","article-title":"Steelix: program-state based binary fuzzing","author":"Li Yuekang","year":"2017","unstructured":"Yuekang Li, Bihuan Chen, Mahinthan Chandramohan, Shang-Wei Lin, Yang Liu, and Alwen Tiu. 2017. Steelix: program-state based binary fuzzing. In Proceedings of the 2017 11th joint meeting on foundations of software engineering. 627\u2013637.","journal-title":"Proceedings of the 2017 11th joint meeting on foundations of software engineering"},{"key":"e_1_3_1_22_2","first-page":"1","article-title":"On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities","author":"Li Zhen","year":"2024","unstructured":"Zhen Li, Ning Wang, Deqing Zou, Yating Li, Ruqian Zhang, Shouhuai Xu, Chao Zhang, and Hai Jin. 2024. On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering. 1\u201312.","journal-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3051525"},{"key":"e_1_3_1_24_2","article-title":"Vuldeepecker: A deep learning-based system for vulnerability detection","author":"Li Zhen","year":"2018","unstructured":"Zhen Li, Deqing Zou, Shouhuai Xu, Xinyu Ou, Hai Jin, Sujuan Wang, Zhijun Deng, and Yuyi Zhong. 2018. Vuldeepecker: A deep learning-based system for vulnerability detection. arXiv preprint arXiv:1801.01681 (2018).","journal-title":"arXiv preprint arXiv:1801.01681"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.48"},{"key":"e_1_3_1_26_2","unstructured":"NVD. 2024. CVE-2022-46489. Retrieved October 25 2024 from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-46489"},{"key":"e_1_3_1_27_2","unstructured":"NVD. 2024. NVD Data Feeds. Retrieved October 25 2024 from https:\/\/nvd.nist.gov\/vuln\/data-feeds"},{"key":"e_1_3_1_28_2","first-page":"780","article-title":"MACKE: Compositional analysis of low-level vulnerabilities with symbolic execution","author":"Ognawala Saahil","year":"2016","unstructured":"Saahil Ognawala, Mart\u00edn Ochoa, Alexander Pretschner, and Tobias Limmer. 2016. MACKE: Compositional analysis of low-level vulnerabilities with symbolic execution. In Proceedings of the 31st IEEE\/ACM International Conference on Automated Software Engineering. 780\u2013785.","journal-title":"Proceedings of the 31st IEEE\/ACM International Conference on Automated Software Engineering"},{"key":"e_1_3_1_29_2","unstructured":"Openstd. 2024. Open Std. Retrieved April 20 2024 from https:\/\/www.open-std.org\/jtc1\/sc22\/wg14\/www\/docs\/n1548.pdf"},{"key":"e_1_3_1_30_2","first-page":"757","article-title":"Automated vulnerability detection in source code using deep representation learning","author":"Russell Rebecca","year":"2018","unstructured":"Rebecca Russell, Louis Kim, Lei Hamilton, Tomo Lazovich, Jacob Harer, Onur Ozdemir, Paul Ellingwood, and Marc McConley. 2018. Automated vulnerability detection in source code using deep representation learning. In Proceedings of the 17th IEEE international conference on machine learning and applications. 757\u2013762.","journal-title":"Proceedings of the 17th IEEE international conference on machine learning and applications"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","unstructured":"Carolyn B. Seaman. 1999. Qualitative methods in empirical studies of software engineering. IEEE Transactions on software engineering 25 4 (1999) 557\u2013572. https:\/\/doi.org\/10.1109\/32.799955 10.1109\/32.799955","DOI":"10.1109\/32.799955"},{"key":"e_1_3_1_32_2","unstructured":"ShiftLeftSecurity. 2024. Joern. Retrieved October 25 2024 from https:\/\/github.com\/ShiftLeftSecurity\/joern"},{"key":"e_1_3_1_33_2","first-page":"1","article-title":"Dataflow analysis-inspired deep learning for efficient vulnerability detection","author":"Steenhoek Benjamin","year":"2024","unstructured":"Benjamin Steenhoek, Hongyang Gao, and Wei Le. 2024. Dataflow analysis-inspired deep learning for efficient vulnerability detection. In Proceedings of the 46th International Conference on Software Engineering. 1\u201313.","journal-title":"Proceedings of the 46th International Conference on Software Engineering"},{"key":"e_1_3_1_34_2","first-page":"1","article-title":"Driller: Augmenting fuzzing through selective symbolic execution","author":"Stephens Nick","year":"2016","unstructured":"Nick Stephens, John Grosen, Christopher Salls, Andrew Dutcher, Ruoyu Wang, Jacopo Corbetta, Yan Shoshitaishvili, Christopher Kruegel, and Giovanni Vigna. 2016. Driller: Augmenting fuzzing through selective symbolic execution. In Proceedings of the Symposium on Network and Distributed System Security. 1\u201316.","journal-title":"Proceedings of the Symposium on Network and Distributed System Security"},{"key":"e_1_3_1_35_2","unstructured":"AntMan. 2024. AntMan. Retrieved October 25 2024 from https:\/\/antman-opensource.github.io\/"},{"key":"e_1_3_1_36_2","unstructured":"tree sitter. 2023. Tree-sitter: An incremental parsing system for programming tools. Retrieved September 1 2024 from https:\/\/tree-sitter.github.io\/tree-sitter\/"},{"key":"e_1_3_1_37_2","first-page":"218","volume-title":"2023 IEEE\/ACM 45th International Conference on Software Engineering: Companion Proceedings (ICSE-Companion)","author":"Tu Haoxin","year":"2023","unstructured":"Haoxin Tu. 2023. Boosting symbolic execution for heap-based vulnerability detection and exploit generation. In 2023 IEEE\/ACM 45th International Conference on Software Engineering: Companion Proceedings (ICSE-Companion). IEEE, 218\u2013220."},{"key":"e_1_3_1_38_2","first-page":"33","article-title":"Towards practical reactive security audit using extended static checkers","author":"Vanegue Julien","year":"2013","unstructured":"Julien Vanegue and Shuvendu K Lahiri. 2013. Towards practical reactive security audit using extended static checkers. In Proceedings of the Symposium on Security and Privacy. 33\u201347.","journal-title":"Proceedings of the Symposium on Security and Privacy"},{"key":"e_1_3_1_39_2","doi-asserted-by":"crossref","first-page":"579","DOI":"10.1109\/SP.2017.23","article-title":"Skyfire: Data-driven seed generation for fuzzing","author":"Wang Junjie","year":"2017","unstructured":"Junjie Wang, Bihuan Chen, Lei Wei, and Yang Liu. 2017. Skyfire: Data-driven seed generation for fuzzing. In Proceedings of the 2017 IEEE Symposium on Security and Privacy. 579\u2013594.","journal-title":"Proceedings of the 2017 IEEE Symposium on Security and Privacy"},{"key":"e_1_3_1_40_2","first-page":"724","article-title":"Superion: Grammar-aware greybox fuzzing","author":"Wang Junjie","year":"2019","unstructured":"Junjie Wang, Bihuan Chen, Lei Wei, and Yang Liu. 2019. Superion: Grammar-aware greybox fuzzing. In Proceedings of the 2019 IEEE\/ACM 41st International Conference on Software Engineering. 724\u2013735.","journal-title":"Proceedings of the 2019 IEEE\/ACM 41st International Conference on Software Engineering"},{"key":"e_1_3_1_41_2","first-page":"1","article-title":"IntScope: Automatically detecting integer overflow vulnerability in X86 binary using symbolic execution","author":"Wang Tielei","year":"2009","unstructured":"Tielei Wang, Tao Wei, Zhiqiang Lin, and Wei Zou. 2009. IntScope: Automatically detecting integer overflow vulnerability in X86 binary using symbolic execution. In Proceedings of the Symposium on Network and Distributed System Security. 1\u201314.","journal-title":"Proceedings of the Symposium on Network and Distributed System Security"},{"key":"e_1_3_1_42_2","first-page":"332","article-title":"Comparison and evaluation of clone detection techniques with different code representations","author":"Wang Yuekun","year":"2023","unstructured":"Yuekun Wang, Yuhang Ye, Yueming Wu, Weiwei Zhang, Yinxing Xue, and Yang Liu. 2023. Comparison and evaluation of clone detection techniques with different code representations. In Proceedings of the IEEE\/ACM 45th International Conference on Software Engineering. IEEE, 332\u2013344.","journal-title":"Proceedings of the IEEE\/ACM 45th International Conference on Software Engineering"},{"key":"e_1_3_1_43_2","first-page":"2710","article-title":"Symgx: Detecting cross-boundary pointer vulnerabilities of sgx applications via static symbolic execution","author":"Wang Yuanpeng","year":"2023","unstructured":"Yuanpeng Wang, Ziqi Zhang, Ningyu He, Zhineng Zhong, Shengjian Guo, Qinkun Bao, Ding Li, Yao Guo, and Xiangqun Chen. 2023. Symgx: Detecting cross-boundary pointer vulnerabilities of sgx applications via static symbolic execution. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. 2710\u20132724.","journal-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"},{"key":"e_1_3_1_44_2","first-page":"345","volume-title":"2023 38th IEEE\/ACM International Conference on Automated Software Engineering (ASE)","author":"Wen Xin-Cheng","year":"2023","unstructured":"Xin-Cheng Wen, Xinchen Wang, Cuiyun Gao, Shaohua Wang, Yang Liu, and Zhaoquan Gu. 2023. When less is enough: Positive and unlabeled learning model for vulnerability detection. In 2023 38th IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 345\u2013357."},{"key":"e_1_3_1_45_2","first-page":"6541","article-title":"V1SCAN: Discovering 1-day Vulnerabilities in Reused C\/C++ Open-source Software Components Using Code Classification Techniques","author":"Woo Seunghoon","year":"2023","unstructured":"Seunghoon Woo, Eunjin Choi, Heejo Lee, and Hakjoo Oh. 2023. V1SCAN: Discovering 1-day Vulnerabilities in Reused C\/C++ Open-source Software Components Using Code Classification Techniques. In Proceedings of the 32nd USENIX Security Symposium. 6541\u20136556.","journal-title":"Proceedings of the 32nd USENIX Security Symposium"},{"key":"e_1_3_1_46_2","first-page":"3037","article-title":"MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software Components","author":"Woo Seunghoon","year":"2022","unstructured":"Seunghoon Woo, Hyunji Hong, Eunjin Choi, and Heejo Lee. 2022. MOVERY: A Precise Approach for Modified Vulnerable Code Clone Discovery from Modified Open-Source Software Components. In Proceedings of the 31st USENIX Security Symposium. 3037\u20133053.","journal-title":"Proceedings of the 31st USENIX Security Symposium"},{"key":"e_1_3_1_47_2","first-page":"1","article-title":"Identifying Affected Libraries and Their Ecosystems for Open Source Software Vulnerabilities","author":"Wu Susheng","year":"2024","unstructured":"Susheng Wu, Wenyan Song, Kaifeng Huang, Bihuan Chen, and Xin Peng. 2024. Identifying Affected Libraries and Their Ecosystems for Open Source Software Vulnerabilities. In Proceedings of the 46th International Conference on Software Engineering. 1\u201312.","journal-title":"Proceedings of the 46th International Conference on Software Engineering"},{"key":"e_1_3_1_48_2","article-title":"Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLM","volume":"2","author":"Wu Susheng","year":"2025","unstructured":"Susheng Wu, Ruisi Wang, Yiheng Cao, Bihuan Chen, Zhuotong Zhou, Yiheng Huang, Zhao Junpeng, and Xin Peng. 2025. Mystique: Automated Vulnerability Patch Porting with Semantic and Syntactic-Enhanced LLM. Proceedings of the ACM on Software Engineering 2, FSE (2025).","journal-title":"Proceedings of the ACM on Software Engineering"},{"key":"e_1_3_1_49_2","first-page":"1447","article-title":"Vision: Identifying affected library versions for open source software vulnerabilities","author":"Wu Susheng","year":"2024","unstructured":"Susheng Wu, Ruisi Wang, Kaifeng Huang, Yiheng Cao, Wenyan Song, Zhuotong Zhou, Yiheng Huang, Bihuan Chen, and Xin Peng. 2024. Vision: Identifying affected library versions for open source software vulnerabilities. In Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering. 1447\u20131459.","journal-title":"Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering"},{"key":"e_1_3_1_50_2","first-page":"1165","article-title":"MVP: Detecting Vulnerabilities using Patch-Enhanced Vulnerability Signatures","author":"Xiao Yang","year":"2020","unstructured":"Yang Xiao, Bihuan Chen, Chendong Yu, Zhengzi Xu, Zimu Yuan, Feng Li, Binghong Liu, Yang Liu, Wei Huo, Wei Zou, . 2020. MVP: Detecting Vulnerabilities using Patch-Enhanced Vulnerability Signatures. In Proceedings of the 29th USENIX Security Symposium. 1165\u20131182.","journal-title":"Proceedings of the 29th USENIX Security Symposium"},{"key":"e_1_3_1_51_2","first-page":"499","article-title":"Chucky: Exposing missing checks in source code for vulnerability discovery","author":"Yamaguchi Fabian","year":"2013","unstructured":"Fabian Yamaguchi, Christian Wressnegger, Hugo Gascon, and Konrad Rieck. 2013. Chucky: Exposing missing checks in source code for vulnerability discovery. In Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security. 499\u2013510.","journal-title":"Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security"},{"key":"e_1_3_1_52_2","article-title":"Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jingkai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. In Proceedings of the 33rd Conference on Neural Information Processing Systems.","journal-title":"Proceedings of the 33rd Conference on Neural Information Processing Systems"},{"key":"e_1_3_1_53_2","first-page":"1633","article-title":"Magneto: A Step-Wise Approach to Exploit Vulnerabilities in Dependent Libraries via LLM-Empowered Directed Fuzzing","author":"Zhou Zhuotong","year":"2024","unstructured":"Zhuotong Zhou, Yongzhuo Yang, Susheng Wu, Yiheng Huang, Bihuan Chen, and Xin Peng. 2024. Magneto: A Step-Wise Approach to Exploit Vulnerabilities in Dependent Libraries via LLM-Empowered Directed Fuzzing. In Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering. 1633\u20131644.","journal-title":"Proceedings of the 39th IEEE\/ACM International Conference on Automated Software Engineering"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3728901","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T13:55:19Z","timestamp":1787493319000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3728901"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,22]]},"references-count":52,"journal-issue":{"issue":"ISSTA","published-print":{"date-parts":[[2025,6,22]]}},"alternative-id":["10.1145\/3728901"],"URL":"https:\/\/doi.org\/10.1145\/3728901","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,22]]}}}