详细信息

VFProber: A Vulnerability-Fixing Identification Framework Based on Code Changes and Semantic Adjustment  ( EI收录)  

文献类型:期刊文献

英文题名:VFProber: A Vulnerability-Fixing Identification Framework Based on Code Changes and Semantic Adjustment

作者:Dong, Jianan[1]; Fan, Guisheng[1,2]; Yu, Yueming[3]; Liang, Yuguo[1]; Ye, Yujie[1]; Yu, Huiqun[1,2]; Chen, Wentao[1]

机构:[1] East China University of Science and Technology, Department of Computer Science and Engineering, Shanghai, 200237, China; [2] Shanghai Engineering Research Center of Smart Energy, Shanghai, 201103, China; [3] Shanghai Data Exchange Corporation, Shanghai, 201203, China

年份:2025

起止页码:1174

外文期刊名:Proceedings - 2025 IEEE 49th Annual Computers, Software, and Applications Conference, COMPSAC 2025

收录:EI(收录号:20253819196521)

语种:英文

外文关键词:Codes (symbols) - Computer programming languages - Computer software - Learning systems - Natural language processing systems - Semantics

摘要:With the accelerated development of software, developers face the continuous challenge of fixing vulnerabilities but vulnerability-fixing commits often disassociated from the vulnerabilities, and the structural and semantic differences between code changes and natural language present significant challenges in identifying these commits. Existing approaches utilize machine learning and deep learning techniques to address this problem, but they often do not fully leverage the information about code changes. In this paper, we propose VFProber, a method based on a code change pretrained model, aiming to provide a comprehensive and unified framework for identifying vulnerability-fixing commits. VFProber uses semantic adjustment to distinguish between context-sensitive and context-insensitive code units in code changes, thereby enhancing the model's understanding of code changes during the training process. Secondly, VFProber employs a novel code change pretrained model as a feature extractor. Compared with ordinary code pretrained models, it can better meet the requirements of the vulnerability-fixing identification task. Moreover, we constructed a vulnerability-fixing dataset containing two common programming languages, Java and JavaScript, from industrial projects. In the experimental section, we designed three tasks to evaluate the method. The results show that, compared with the best baseline, VFProber performs better in the vulnerability-fixing identification task and can effectively reduce false positives and false negatives. ? 2025 IEEE.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心