An Empirical Study of Fine-Grained Entity Relationships for Tracing Natural Language and Code Vulnerability Artifacts
Simin Wang, LiGuo Huang, Shiyi Wei, Amiao Gao, Ruiqi Hu, Vincent Ng
Abstract
Understanding software vulnerabilities requires analyzing fine-grained entities and their complex relationships across natural language (NL) artifacts and source code. Vulnerability descriptions often interweave vulnerability triggers (VT), crash phenomena (CP), and after-fix (AF) actions within the same sentence, making it challenging to distinguish root causes, failure symptoms, and remediation strategies. Additionally, missing key NL entities further hinders traceability, limiting an analyst’s ability to determine why and how a vulnerability was introduced and resolved. To address these challenges, we conduct an empirical study on fine-grained entity relationships using a manually curated dataset of 1,000 vulnerabilities. We extract phrase-level VT, CP, and AF entities, categorize them into structured taxonomies, and analyze cross-entity relationships within NL artifacts and source code, uncovering recurring patterns in vulnerability evolution and remediation strategies. Furthermore, we investigate the automation of vulnerability entity extraction using different approaches, showing that ELECTRA [7], a state-of-the-art pre-trained language model, along with other LLM-based approaches, outperforms other methods.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3eb9e7f8-61b2-4945-ad85-7ff5547188e4Related papers
- Teaching AI the 'Why' and 'How' of Software Vulnerability FixesAmiao Gao, Zenong Zhang, Simin Wang, Liguo Huang et al.FSE 2025
- Unsupervised Labeling and Extraction of Phrase-based Concepts in Vulnerability DescriptionsSofonias Yitagesu, Zhenchang Xing, Xiaowang Zhang, Zhiyong Feng et al.ASE 2021 · 18 citations
- How Effective Are Neural Networks for Fixing Security VulnerabilitiesYi Wu, Nan Jiang, Hung Viet Pham, Thibaud Lutellier et al.ISSTA 2023 · 86 citations
- Code Change Intention, Development Artifact, and History Vulnerability: Putting Them Together for Vulnerability Fix Detection by LLMXu Yang, Wenhan Zhu, Michael Pacheco, Jiayuan Zhou et al.FSE 2025 · 5 citations
- Vul-R2: A Reasoning LLM for Automated Vulnerability RepairXin-Cheng Wen, Zirui Lin, Yijun Yang, Cuiyun Gao et al.ASE 2025 · 1 citation
