Evaluating SZZ Implementations Through a Developer-informed Oracle
Giovanni Rosa, Luca Pascarella, Simone Scalabrino, Rosalia Tufano, Gabriele Bavota, Michele Lanza, Rocco Oliveto
Abstract
The SZZ algorithm for identifying bug-inducing changes has been widely used to evaluate defect prediction techniques and to empirically investigate when, how, and by whom bugs are introduced. Over the years, researchers have proposed several heuristics to improve the SZZ accuracy, providing various implementations of SZZ. However, fairly evaluating those implementations on a reliable oracle is an open problem: SZZ evaluations usually rely on (i) the manual analysis of the SZZ output to classify the identified bug-inducing commits as true or false positives; or (ii) a golden set linking bug-fixing and bug-inducing commits. In both cases, these manual evaluations are performed by researchers with limited knowledge of the studied subject systems. Ideally, there should be a golden set created by the original developers of the studied systems. We propose a methodology to build a "developer-informed" oracle for the evaluation of SZZ variants. We use Natural Language Processing (NLP) to identify bug-fixing commits in which developers explicitly reference the commit(s) that introduced a fixed bug. This was followed by a manual filtering step aimed at ensuring the quality and accuracy of the oracle. Once built, we used the oracle to evaluate several variants of the SZZ algorithm in terms of their accuracy. Our evaluation helped us to distill a set of lessons learned to further improve the SZZ algorithm.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e4bd0d31-a2b8-4925-8caa-e0d4c58cb89dCited by top-tier papers11
- The best of both worlds: integrating semantic features with expert features for defect prediction and localizationChao Ni, Wei Wang, Kaiwen Yang, Xin Xia et al.FSE 2022 · 76 citations
- Fast Changeset-based Bug Localization with BERTAgnieszka Ciborowska, Kostadin DamevskiICSE 2022 · 53 citations
- V-SZZ: Automatic Identification of Version Ranges Affected by CVE VulnerabilitiesLingfeng Bao, Xin Xia, Ahmed E. Hassan, Xiaohu YangICSE 2022 · 45 citations
- Commit Message Matters: Investigating Impact and Evolution of Commit Message QualityJiawei Li, Iftekhar AhmedICSE 2023 · 26 citations
- An Empirical Study of Static Analysis Tools for Secure Code ReviewWachiraphan Charoenwet, Patanamon Thongtanunam, Van-Thuan Pham, Christoph TreudeISSTA 2024 · 19 citations
Related papers
- LLM4SZZ: Enhancing SZZ Algorithm with Context-Enhanced Assessment on Large Language ModelsLingxiao Tang, Jiakun Liu, Zhongxin Liu, Xiaohu Yang et al.ISSTA 2025 · 3 citations
- Neural SZZ AlgorithmLingxiao Tang, Lingfeng Bao, Xin Xia, Zhongdong HuangASE 2023 · 9 citations
- SemBIC: Semantic-Aware Identification of Bug-Inducing CommitsXiao Chen, Hengcheng Zhu, Jialun Cao, Ming Wen et al.FSE 2025 · 1 citation
- Do bugs lead to unnaturalness of source code?Yanjie Jiang, Hui Liu, Yuxia Zhang, Weixing Ji et al.FSE 2022 · 8 citations
- Fonte: Finding Bug Inducing Commits from FailuresGabin An, Jingun Hong, Naryeong Kim, Shin YooICSE 2023 · 10 citations
