Today's Cat Is Tomorrow's Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection Approaches
Ranindya Paramitha, Yuan Feng, Fabio Massacci
Abstract
Assurance and certification in secure Multiparty Open Software and Services (Assure-MOSS). No single company masters its own national, in-house software. Software is mostly assembled from "the internet" and more than half comes from Open Source Software repositories (some in Europe, most elsewhere). Security & privacy assurance, verification, and certification techniques designed for large, slow, and controlled updates, must now cope with small, continuous changes in weeks, happening in sub-components and decided by third-party developers one did not even know existed. AssureMOSS proposes to switch from process-based to artifact-based security evaluation by supporting all phases of the continuous software lifecycle (Design, Develop, Deploy, Evaluate, and back) and their artifacts (Models, Source code, Container images, Services). The key idea is to support mechanisms for lightweight and scalable screenings applicable automatically to the entire population of software components by Machine intelligent identification of security issues, Sound analysis and verification of changes, and Business insight by risk analysis and security evaluation. This approach supports the fast-paced development of better software with a new notion: continuous (re)certification. The project will generate also benchmark datasets with thousands of vulnerabilities. AssureMOSS: Open Source Software: Designed Everywhere, Secured in Europe. More information at https://assuremoss.eu.
Cybersecurity for AI-Augmented Systems (Sec4AI4Sec) . As artificial intelligence (AI) becomes omnipresent, even integrated within secure software development, the safety of digital infrastructures requires new technologies and new methodologies, as highlighted in the EU Strategic Plan 2021-2024. To achieve this goal, the EU-funded Sec4AI4Sec project will develop advanced security-by-design testing and assurance techniques tailored for AI-augmented systems. These systems can democratize security expertise, enabling intelligent, automated secure coding and testing while simultaneously lowering development costs and improving software quality. However, they also introduce unique security challenges, particularly concerning fairness and explainability. Sec4AI4Sec is at the forefront of the move to tackle these challenges with a comprehensive approach, embodying the vision of better security for AI and better AI for security. More information at https://sec4ai4sec.eu. Ranindya Paramitha (PhD 2025) is a research fellow at the University of Trento, Italy. She received her PhD from the University of Trento, Italy, in April 2025. Her main research interest is in software security, focusing on empirical analysis of secure software ecosystems, mining software repositories, and how developers can apply security. She is involved in a Horizon Europe Sec4AI4Sec project and has also started to actively serve the research community in several IEEE/ACM International Conferences/Workshops, such as by being a junior PC member (Distinguished Junior PC Award MSR'25) and regular PC member (ICSME'25
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 59460df0-5edc-465e-94a9-cac686153ce0Builds on12
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan et al.NDSS 2018 · 1,102 citations
- Data Quality for Software Vulnerability DatasetsRoland Croft, Muhammad Ali Babar, M. Mehdi KholoosiICSE 2023 · 138 citations
- An Empirical Study of Deep Learning Models for Vulnerability DetectionBenjamin Steenhoek, Md Mahbubur Rahman, Richard Jiles, Wei LeICSE 2023 · 107 citations
- Uncovering the Limits of Machine Learning for Automatic Vulnerability DetectionNiklas Risse, Marcel BöhmeUSENIX Security 2024 · 63 citations
- DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task LearningTriet Huynh Minh Le, David Hin, Roland Croft, Muhammad Ali BabarASE 2021 · 62 citations
Related papers
- LastPyMile: identifying the discrepancy between sources and packagesDuc-Ly Vu, Fabio Massacci, Ivan Pashchenko, Henrik Plate et al.FSE 2021 · 53 citations
- Using AI Assistants in Software Development: A Qualitative Study on Security Practices and ConcernsJan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik, Cordelia Ludden et al.CCS 2024 · 14 citations
- Intrusion Models for Security Assessment: Methodology and Case Study on XenCharles Gonçalves, Marco VieiraISSTA 2026
- FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability DetectionSiyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan et al.USENIX Security 2024 · 13 citations
- Software security during modern code review: the developer's perspectiveLarissa Braz, Alberto BacchelliFSE 2022 · 28 citations
