PPT4J: Patch Presence Test for Java Binaries
Zhiyuan Pan, Xing Hu, Xin Xia, Xian Zhan, David Lo, Xiaohu Yang
Abstract
The number of vulnerabilities reported in open source software has increased substantially in recent years. Security patches provide the necessary measures to protect software from attacks and vulnerabilities. In practice, it is difficult to identify whether patches have been integrated into software, especially if we only have binary files. Therefore, the ability to test whether a patch is applied to the target binary, a.k.a. patch presence test, is crucial for practitioners. However, it is challenging to obtain accurate semantic information from patches, which could lead to incorrect results. In this paper, we propose a new patch presence test framework named Ppt4J (Patch Presence Test for Java Binaries). Ppt4J is designed for open-source Java libraries. It takes Java binaries (i.e. bytecode files) as input, extracts semantic information from patches, and uses feature-based techniques to identify patch lines in the binaries. To evaluate the effectiveness of our proposed approach Ppt4J, we construct a dataset with binaries that include 110 vulnerabilities. The results show that Ppt4J achieves an F1 score of 98.5% with reasonable efficiency, improving the baseline by 14.2%. Furthermore, we conduct an in-the-wild evaluation of Ppt4J on JetBrains IntelliJ IDEA. The results suggest that a third-party library included in the software is not patched for two CVEs, and we have reported this potential security problem to the vendor. CCS CONCEPTS • Software and its engineering → Software reliability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8c63ae89-c3f4-4f4a-bfc1-18303d87ce73Cited by top-tier papers3
- REACT: IR-Level Patch Presence Test for BinaryQi Zhan, Xing Hu, Xin Xia, Shanping LiASE 2024 · 2 citations
- Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java ProjectsStefan Schott, Serena Elisa Ponta, Wolfram Fischer, Jonas Klauke et al.ICSE 2026
- VulPA: Detecting Semantically Recurring Vulnerabilities with Multi-object Typestate AnalysisLiqing Cao, Haofeng Li, Chenghang Shi, Jie Lu et al.FSE 2025
Builds on6
- Neural Network-based Graph Embedding for Cross-Platform Binary Code Similarity DetectionXiaojun Xu, Chang Liu, Qian Feng, Heng Yin et al.CCS 2017 · 682 citations
- Scalable Graph-based Bug Search for Firmware ImagesQian Feng, Rundong Zhou, Chengcheng Xu, Yao Cheng et al.CCS 2016 · 456 citations
- discovRE: Efficient Cross-Architecture Identification of Bugs in Binary CodeSebastian Eschweiler, Khaled Yakdan, Elmar Gerhards-PadillaNDSS 2016 · 342 citations
- Precise and Accurate Patch Presence Test for BinariesHang Zhang, Zhiyun QianUSENIX Security 2018 · 91 citations
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen et al.CCS 2020 · 54 citations
Related papers
- Beyond Fuzzy Matching: Constraint-Guided Patch Presence Testing for Obfuscated Java BinariesLige Zhan, Jiang Ming, Chenke Luo, Letian Sha et al.ICSE 2026
- BScout: Direct Whole Patch Presence Test for Java ExecutablesJiarun Dai, Yuan Zhang, Zheyue Jiang, Yingtian Zhou et al.USENIX Security 2020
- PS3: Precise Patch Presence Test based on Semantic Symbolic SignatureQi Zhan, Xing Hu, Zhiyang Li, Xin Xia et al.ICSE 2024 · 4 citations
- A Comprehensive Empirical Analysis of Patch Presence Testing: Capabilities, Limitations, and Paths ForwardXiaobei Zhang, Yaowen Zheng, Wu Luo, Shijun Zhao et al.ISSTA 2026
- Lares: LLM-driven Code Slice Semantic Search for Patch Presence TestingSiyuan Li, Yaowen Zheng, Hong Li, Jingdong Guo et al.ASE 2025 · 1 citation
