Lune

ISSTA2026顶会

ProgSCA: Software Composition Analysis via Program-Level Modeling

Peihong Li, Cheng Li, Yuchen Gu, Yanzhe Hu, Liheng Chen, Zeyu Gao, Hao Wang, Chao Zhang

2026年份

摘要

Software composition analysis (SCA) aims to identify third-party dependencies in programs, which plays a critical role in ensuring software supply chain security. Existing approaches largely follow a rule-based paradigm: they first compute function-level similarities, then aggregate these results using handcrafted heuristics to determine which third-party libraries (TPLs) the target program depends on. However, such rules require substantial manual effort and expert knowledge to design, tune, and maintain. To address this, we present ProgSCA, an SCA framework based on a two-stage strategy and program-level rather than function-level modeling. ProgSCA formulates SCA as a retrieval problem, first employing lightweight methods to quickly filter out irrelevant libraries from numerous candidate TPLs, then using a model trained at the program level to directly predict dependency between programs. Comprehensive evaluations show that ProgSCA achieves state-of-the-art performance in SCA tasks, improving F1 scores over existing methods by 174% and 100% in two mainstream scenarios, respectively. Moreover, ProgSCA maintains a consistent advantage across different datasets and different candidate pool scales, and also proves effective in the downstream task of function similarity matching, further demonstrating the practical value of our approach.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get 4501b68a-d133-4b6c-bb01-e4168f1797be

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖