An Empirical Study of Fine-Grained Entity Relationships for Tracing Natural Language and Code Vulnerability Artifacts
Simin Wang, LiGuo Huang, Shiyi Wei, Amiao Gao, Ruiqi Hu, Vincent Ng
摘要
Understanding software vulnerabilities requires analyzing fine-grained entities and their complex relationships across natural language (NL) artifacts and source code. Vulnerability descriptions often interweave vulnerability triggers (VT), crash phenomena (CP), and after-fix (AF) actions within the same sentence, making it challenging to distinguish root causes, failure symptoms, and remediation strategies. Additionally, missing key NL entities further hinders traceability, limiting an analyst’s ability to determine why and how a vulnerability was introduced and resolved. To address these challenges, we conduct an empirical study on fine-grained entity relationships using a manually curated dataset of 1,000 vulnerabilities. We extract phrase-level VT, CP, and AF entities, categorize them into structured taxonomies, and analyze cross-entity relationships within NL artifacts and source code, uncovering recurring patterns in vulnerability evolution and remediation strategies. Furthermore, we investigate the automation of vulnerability entity extraction using different approaches, showing that ELECTRA [7], a state-of-the-art pre-trained language model, along with other LLM-based approaches, outperforms other methods.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Teaching AI the 'Why' and 'How' of Software Vulnerability FixesAmiao Gao, Zenong Zhang, Simin Wang, Liguo Huang 等FSE 2025
- Unsupervised Labeling and Extraction of Phrase-based Concepts in Vulnerability DescriptionsSofonias Yitagesu, Zhenchang Xing, Xiaowang Zhang, Zhiyong Feng 等ASE 2021 · 被引用 18 次
- How Effective Are Neural Networks for Fixing Security VulnerabilitiesYi Wu, Nan Jiang, Hung Viet Pham, Thibaud Lutellier 等ISSTA 2023 · 被引用 86 次
- Code Change Intention, Development Artifact, and History Vulnerability: Putting Them Together for Vulnerability Fix Detection by LLMXu Yang, Wenhan Zhu, Michael Pacheco, Jiayuan Zhou 等FSE 2025 · 被引用 5 次
- Vul-R2: A Reasoning LLM for Automated Vulnerability RepairXin-Cheng Wen, Zirui Lin, Yijun Yang, Cuiyun Gao 等ASE 2025 · 被引用 1 次
