{"id":"W4402273641","doi":"10.1007/978-3-031-70896-1_9","title":"SerdeSniffer: Enhancing Java Deserialization Vulnerability Detection with Function Summaries","year":2024,"lang":"en","type":"book-chapter","venue":"Lecture notes in computer science","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":false,"ca_institutions":"University of Waterloo","funders":"","keywords":"Computer science; Java; Vulnerability (computing); Function (biology); Programming language; Computer security","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0005405186,0.001219099,0.0004073447,0.001186686,0.0002810425,0.001010244,0.001034165,0.0005393593,0.007210873],"category_scores_gemma":[0.002025132,0.0004201152,0.0004592442,0.0003944739,0.0002789948,0.001662486,0.0009823528,0.0007605616,0.003725791],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0003778785,"about_ca_system_score_gemma":0.0005341924,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.001221744,"about_ca_topic_score_gemma":0.002919713,"domain_scores_codex":[0.999387,0.00007362736,0.00003099897,0.0001091838,0.0003358288,0.00006333888],"domain_scores_gemma":[0.9991173,0.0002825094,0.00007551692,0.0002260429,0.000248278,0.00005022856],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.0006467109,0.0003597426,0.005153999,0.0003417913,0.00008246507,0.0003002567,0.0001947746,0.01135573,0.07402658,0.005832192,0.06923207,0.8324736],"study_design_scores_gemma":[0.0001244984,0.0006476893,0.005236244,0.0001409809,0.0001916787,0.001220406,0.00009414621,0.5251824,0.3316414,0.01185732,0.1235333,0.0001299893],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.1097306,0.001397124,0.5058285,0.0005449532,0.0005693593,0.0002494585,0.001252658,0.3344043,0.04602316],"genre_scores_gemma":[0.6339592,0.0006887309,0.2715574,0.0008190828,0.0001681705,0.0001283747,0.003298522,0.01391163,0.07546896],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.007210873,"threshold_uncertainty_score":0.02412277,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01012730779484923,"score_gpt":0.2367370278990524,"score_spread":0.2266097201042031,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}