{"id":"W4394769336","doi":"10.1145/3597503.3639212","title":"Combining Structured Static Code Information and Dynamic Symbolic Traces for Software Vulnerability Prediction","year":2024,"lang":"en","type":"article","venue":"","topic":"Software Engineering Research","field":"Computer Science","cited_by":15,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University","funders":"Engineering and Physical Sciences Research Council; Mitacs; National Natural Science Foundation of China","keywords":"Computer science; Symbolic execution; Scalability; Fuzz testing; Overhead (engineering); Code (set theory); Source code; Programming language; Vulnerability (computing); Static analysis; Semantics (computer science); Software; Static program analysis; Benchmark (surveying); Artificial intelligence; Machine learning; Database; Software development; Computer security; Set (abstract data type)","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0004051035,0.00009505906,0.00009698152,0.0001647167,0.0000921966,0.0004785965,0.000212549,0.00005074614,0.000005805237],"category_scores_gemma":[0.0006193044,0.00008258666,0.00002514072,0.0002681281,0.00002877276,0.00139211,0.00007611555,0.0001402297,0.000005073377],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.00007695135,"about_ca_system_score_gemma":0.00007341542,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.00001214806,"about_ca_topic_score_gemma":0.000009450629,"domain_scores_codex":[0.9991495,0.00002237261,0.0002010498,0.0002098863,0.0002194988,0.0001976641],"domain_scores_gemma":[0.9986486,0.0009735857,0.00001785582,0.0002188984,0.00007397381,0.00006702812],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.00002508653,0.00003604041,0.01294146,0.003010292,0.0001425273,0.000004271105,0.01084379,0.0160143,0.0006866418,0.02974837,0.002060293,0.9244869],"study_design_scores_gemma":[0.0001957506,0.00008800018,0.03365042,0.00003981801,0.000005664897,0.00001251431,0.00004039714,0.9583408,0.0002203929,0.006580135,0.0007310112,0.00009512372],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.1851998,0.0001521569,0.8127707,0.0002321069,0.0003546512,0.0002990369,0.00004200941,0.0009414394,0.000008177235],"genre_scores_gemma":[0.9259568,0.000009061991,0.07384909,0.00002732672,0.00001255587,0.00006775955,0.0000270833,0.000007281215,0.00004306814],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.9423265,"threshold_uncertainty_score":0.4615116,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01112050374642408,"score_gpt":0.2772554784275464,"score_spread":0.2661349746811223,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}