{"id":"W4394769336","doi":"10.1145/3597503.3639212","title":"Combining Structured Static Code Information and Dynamic Symbolic Traces for Software Vulnerability Prediction","year":2024,"lang":"en","type":"article","venue":"","topic":"Software Engineering Research","field":"Computer Science","cited_by":15,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University","funders":"Engineering and Physical Sciences Research Council; Mitacs; National Natural Science Foundation of China","keywords":"Computer science; Symbolic execution; Scalability; Fuzz testing; Overhead (engineering); Code (set theory); Source code; Programming language; Vulnerability (computing); Static analysis; Semantics (computer science); Software; Static program analysis; Benchmark (surveying); Artificial intelligence; Machine learning; Database; Software development; Computer security; Set (abstract data type)","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0008842477,0.001112884,0.0005060553,0.004091739,0.0003172428,0.0007492429,0.001144358,0.0007832338,0.001161517],"category_scores_gemma":[0.005653434,0.0004774414,0.0005874651,0.001895301,0.0007329091,0.002783198,0.001892187,0.001263656,0.0005600557],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009514426,"about_ca_system_score_gemma":0.001409448,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.006587381,"about_ca_topic_score_gemma":0.01304598,"domain_scores_codex":[0.9993675,0.000123126,0.00004595185,0.0001999498,0.0001855489,0.0000779745],"domain_scores_gemma":[0.9966793,0.001525171,0.0005025547,0.0006597332,0.0004821908,0.0001510541],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0003146841,0.0005242037,0.06029895,0.0003796939,0.0001498314,0.0002792705,0.0003437312,0.224204,0.01820325,0.004553714,0.005579132,0.6851694],"study_design_scores_gemma":[0.000009427948,0.00007767458,0.002527301,0.00002731282,0.00002285101,0.00006526636,0.00005420176,0.9805523,0.007408644,0.007938198,0.001300369,0.00001646286],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.2812875,0.0009883747,0.6885914,0.0006510495,0.00004414198,0.0001389227,0.001981086,0.02326128,0.003056203],"genre_scores_gemma":[0.8025061,0.0003628317,0.1907346,0.0002019486,0.00002507109,0.00009295854,0.00395365,0.0004177762,0.001705022],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.006587381,"threshold_uncertainty_score":0.01309806,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01112050374642408,"score_gpt":0.2772554784275464,"score_spread":0.2661349746811223,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}