Today's Cat Is Tomorrow's Dog: Accounting for Time-Based Changes in the Labels of ML Vulnerability Detection Approaches
Ranindya Paramitha, Yuan Feng, Fabio Massacci
摘要
Assurance and certification in secure Multiparty Open Software and Services (Assure-MOSS). No single company masters its own national, in-house software. Software is mostly assembled from "the internet" and more than half comes from Open Source Software repositories (some in Europe, most elsewhere). Security & privacy assurance, verification, and certification techniques designed for large, slow, and controlled updates, must now cope with small, continuous changes in weeks, happening in sub-components and decided by third-party developers one did not even know existed. AssureMOSS proposes to switch from process-based to artifact-based security evaluation by supporting all phases of the continuous software lifecycle (Design, Develop, Deploy, Evaluate, and back) and their artifacts (Models, Source code, Container images, Services). The key idea is to support mechanisms for lightweight and scalable screenings applicable automatically to the entire population of software components by Machine intelligent identification of security issues, Sound analysis and verification of changes, and Business insight by risk analysis and security evaluation. This approach supports the fast-paced development of better software with a new notion: continuous (re)certification. The project will generate also benchmark datasets with thousands of vulnerabilities. AssureMOSS: Open Source Software: Designed Everywhere, Secured in Europe. More information at https://assuremoss.eu.
Cybersecurity for AI-Augmented Systems (Sec4AI4Sec) . As artificial intelligence (AI) becomes omnipresent, even integrated within secure software development, the safety of digital infrastructures requires new technologies and new methodologies, as highlighted in the EU Strategic Plan 2021-2024. To achieve this goal, the EU-funded Sec4AI4Sec project will develop advanced security-by-design testing and assurance techniques tailored for AI-augmented systems. These systems can democratize security expertise, enabling intelligent, automated secure coding and testing while simultaneously lowering development costs and improving software quality. However, they also introduce unique security challenges, particularly concerning fairness and explainability. Sec4AI4Sec is at the forefront of the move to tackle these challenges with a comprehensive approach, embodying the vision of better security for AI and better AI for security. More information at https://sec4ai4sec.eu. Ranindya Paramitha (PhD 2025) is a research fellow at the University of Trento, Italy. She received her PhD from the University of Trento, Italy, in April 2025. Her main research interest is in software security, focusing on empirical analysis of secure software ecosystems, mining software repositories, and how developers can apply security. She is involved in a Horizon Europe Sec4AI4Sec project and has also started to actively serve the research community in several IEEE/ACM International Conferences/Workshops, such as by being a junior PC member (Distinguished Junior PC Award MSR'25) and regular PC member (ICSME'25
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan 等NDSS 2018 · 被引用 1,102 次
- Data Quality for Software Vulnerability DatasetsRoland Croft, Muhammad Ali Babar, M. Mehdi KholoosiICSE 2023 · 被引用 138 次
- An Empirical Study of Deep Learning Models for Vulnerability DetectionBenjamin Steenhoek, Md Mahbubur Rahman, Richard Jiles, Wei LeICSE 2023 · 被引用 107 次
- Uncovering the Limits of Machine Learning for Automatic Vulnerability DetectionNiklas Risse, Marcel BöhmeUSENIX Security 2024 · 被引用 63 次
- DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task LearningTriet Huynh Minh Le, David Hin, Roland Croft, Muhammad Ali BabarASE 2021 · 被引用 62 次
相关 Paper
- LastPyMile: identifying the discrepancy between sources and packagesDuc-Ly Vu, Fabio Massacci, Ivan Pashchenko, Henrik Plate 等FSE 2021 · 被引用 53 次
- Using AI Assistants in Software Development: A Qualitative Study on Security Practices and ConcernsJan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik, Cordelia Ludden 等CCS 2024 · 被引用 14 次
- Intrusion Models for Security Assessment: Methodology and Case Study on XenCharles Gonçalves, Marco VieiraISSTA 2026
- FIRE: Combining Multi-Stage Filtering with Taint Analysis for Scalable Recurring Vulnerability DetectionSiyue Feng, Yueming Wu, Wenjie Xue, Sikui Pan 等USENIX Security 2024 · 被引用 13 次
- Software security during modern code review: the developer's perspectiveLarissa Braz, Alberto BacchelliFSE 2022 · 被引用 28 次
