详细信息
VFProber: A Vulnerability-Fixing Identification Framework Based on Code Changes and Semantic Adjustment ( EI收录)
文献类型:期刊文献
英文题名:VFProber: A Vulnerability-Fixing Identification Framework Based on Code Changes and Semantic Adjustment
作者:Dong, Jianan[1]; Fan, Guisheng[1,2]; Yu, Yueming[3]; Liang, Yuguo[1]; Ye, Yujie[1]; Yu, Huiqun[1,2]; Chen, Wentao[1]
机构:[1] East China University of Science and Technology, Department of Computer Science and Engineering, Shanghai, 200237, China; [2] Shanghai Engineering Research Center of Smart Energy, Shanghai, 201103, China; [3] Shanghai Data Exchange Corporation, Shanghai, 201203, China
年份:2025
起止页码:1174
外文期刊名:Proceedings - 2025 IEEE 49th Annual Computers, Software, and Applications Conference, COMPSAC 2025
收录:EI(收录号:20253819196521)
语种:英文
外文关键词:Codes (symbols) - Computer programming languages - Computer software - Learning systems - Natural language processing systems - Semantics
摘要:With the accelerated development of software, developers face the continuous challenge of fixing vulnerabilities but vulnerability-fixing commits often disassociated from the vulnerabilities, and the structural and semantic differences between code changes and natural language present significant challenges in identifying these commits. Existing approaches utilize machine learning and deep learning techniques to address this problem, but they often do not fully leverage the information about code changes. In this paper, we propose VFProber, a method based on a code change pretrained model, aiming to provide a comprehensive and unified framework for identifying vulnerability-fixing commits. VFProber uses semantic adjustment to distinguish between context-sensitive and context-insensitive code units in code changes, thereby enhancing the model's understanding of code changes during the training process. Secondly, VFProber employs a novel code change pretrained model as a feature extractor. Compared with ordinary code pretrained models, it can better meet the requirements of the vulnerability-fixing identification task. Moreover, we constructed a vulnerability-fixing dataset containing two common programming languages, Java and JavaScript, from industrial projects. In the experimental section, we designed three tasks to evaluate the method. The results show that, compared with the best baseline, VFProber performs better in the vulnerability-fixing identification task and can effectively reduce false positives and false negatives. ? 2025 IEEE.
参考文献:
正在载入数据...
