{"id":"https://openalex.org/W4391979639","doi":"https://doi.org/10.1145/3641399.3641405","title":"A Codebert Based Empirical Framework for Evaluating Classification-Enabled Vulnerability Prediction Models","display_name":"A Codebert Based Empirical Framework for Evaluating Classification-Enabled Vulnerability Prediction Models","publication_year":2024,"publication_date":"2024-02-20","ids":{"openalex":"https://openalex.org/W4391979639","doi":"https://doi.org/10.1145/3641399.3641405"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1145/3641399.3641405","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3641399.3641405","source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3641399.3641405","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5093057081","display_name":"Tumu Akshar","orcid":"https://orcid.org/0009-0003-4883-8734"},"institutions":[{"id":"https://openalex.org/I4210101034","display_name":"Birla Institute of Technology and Science - Hyderabad Campus","ror":"https://ror.org/014ctt859","country_code":"IN","type":"education","lineage":["https://openalex.org/I4210101034","https://openalex.org/I74796645"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Tumu Akshar","raw_affiliation_strings":["BITS Pilani Hyderabad, India, India"],"affiliations":[{"raw_affiliation_string":"BITS Pilani Hyderabad, India, India","institution_ids":["https://openalex.org/I4210101034"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027196381","display_name":"Vikram Singh","orcid":"https://orcid.org/0000-0001-6315-0872"},"institutions":[{"id":"https://openalex.org/I105094715","display_name":"National Institute of Technology Kurukshetra","ror":"https://ror.org/04909p852","country_code":"IN","type":"education","lineage":["https://openalex.org/I105094715"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Vikram Singh","raw_affiliation_strings":["National Institute of Technology, Kurukshetra, India"],"affiliations":[{"raw_affiliation_string":"National Institute of Technology, Kurukshetra, India","institution_ids":["https://openalex.org/I105094715"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113885636","display_name":"N. L. Bhanu Murthy","orcid":null},"institutions":[{"id":"https://openalex.org/I4210101034","display_name":"Birla Institute of Technology and Science - Hyderabad Campus","ror":"https://ror.org/014ctt859","country_code":"IN","type":"education","lineage":["https://openalex.org/I4210101034","https://openalex.org/I74796645"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"N L Bhanu Murthy","raw_affiliation_strings":["BITS Pilani Hyderabad, India, India"],"affiliations":[{"raw_affiliation_string":"BITS Pilani Hyderabad, India, India","institution_ids":["https://openalex.org/I4210101034"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053327787","display_name":"Aneesh Krishna","orcid":"https://orcid.org/0000-0001-8637-5732"},"institutions":[{"id":"https://openalex.org/I205640436","display_name":"Curtin University","ror":"https://ror.org/02n415q13","country_code":"AU","type":"education","lineage":["https://openalex.org/I205640436"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Aneesh Krishna","raw_affiliation_strings":["Curtin University, Australia, Australia"],"affiliations":[{"raw_affiliation_string":"Curtin University, Australia, Australia","institution_ids":["https://openalex.org/I205640436"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009512977","display_name":"Lov Kumar","orcid":"https://orcid.org/0000-0002-0123-7822"},"institutions":[{"id":"https://openalex.org/I105094715","display_name":"National Institute of Technology Kurukshetra","ror":"https://ror.org/04909p852","country_code":"IN","type":"education","lineage":["https://openalex.org/I105094715"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Lov Kumar","raw_affiliation_strings":["National Institute of Technology, Kurukshetra, India"],"affiliations":[{"raw_affiliation_string":"National Institute of Technology, Kurukshetra, India","institution_ids":["https://openalex.org/I105094715"]}]}],"institution_assertions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":86},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10260","display_name":"Empirical Studies in Software Engineering","score":0.9996,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10260","display_name":"Empirical Studies in Software Engineering","score":0.9996,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability Assessment and Prediction","score":0.9987,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Characterization and Detection of Android Malware","score":0.9979,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.7237711},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.60372037},{"id":"https://openalex.org/keywords/software-defect-prediction","display_name":"Software Defect Prediction","score":0.583287},{"id":"https://openalex.org/keywords/software-reliability-modeling","display_name":"Software Reliability Modeling","score":0.577638},{"id":"https://openalex.org/keywords/code-clone-detection","display_name":"Code Clone Detection","score":0.568331},{"id":"https://openalex.org/keywords/source-code-analysis","display_name":"Source Code Analysis","score":0.553874},{"id":"https://openalex.org/keywords/secure-coding","display_name":"Secure coding","score":0.53800225},{"id":"https://openalex.org/keywords/intrusion-detection","display_name":"Intrusion Detection","score":0.533565},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.42051455}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.85964406},{"id":"https://openalex.org/C148483581","wikidata":"https://www.wikidata.org/wiki/Q446488","display_name":"Feature selection","level":2,"score":0.7327095},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.7237711},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6867433},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.61600053},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.60372037},{"id":"https://openalex.org/C22680326","wikidata":"https://www.wikidata.org/wiki/Q7444867","display_name":"Secure coding","level":5,"score":0.53800225},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.51409775},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.4346223},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.42051455},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.4126062},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.342017},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.1929954},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.18824485},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.0},{"id":"https://openalex.org/C202444582","wikidata":"https://www.wikidata.org/wiki/Q837863","display_name":"Pure mathematics","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1145/3641399.3641405","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3641399.3641405","source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1145/3641399.3641405","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3641399.3641405","source":null,"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":18,"referenced_works":["https://openalex.org/W1997646511","https://openalex.org/W2069268700","https://openalex.org/W2087016628","https://openalex.org/W2623796653","https://openalex.org/W2796200341","https://openalex.org/W2904738276","https://openalex.org/W2995824836","https://openalex.org/W3010818808","https://openalex.org/W3016970378","https://openalex.org/W3107289082","https://openalex.org/W3142439607","https://openalex.org/W3159944911","https://openalex.org/W3187025053","https://openalex.org/W4205733352","https://openalex.org/W4210320978","https://openalex.org/W4221036576","https://openalex.org/W4283835231","https://openalex.org/W4386214355"],"related_works":["https://openalex.org/W4225160120","https://openalex.org/W2999607548","https://openalex.org/W2956597637","https://openalex.org/W23486959","https://openalex.org/W2293245356","https://openalex.org/W2141388993","https://openalex.org/W2044639210","https://openalex.org/W1981466760","https://openalex.org/W1978034799","https://openalex.org/W1588942021"],"abstract_inverted_index":{"Software":[0],"vulnerabilities":[1,21],"are":[2,110,121],"discovered":[3],"quite":[4],"frequently":[5],"and":[6,10,30,55,64,99,114,130,141,161,184,197,218],"cause":[7],"substantial":[8],"damage":[9],"security":[11],"breaches.":[12],"In":[13,32],"the":[14,18,37,40,46,70,79,88,144,147,164,174,179,198,211],"realm":[15],"of":[16,20,39,82,146,157,176,181,203,213],"cybersecurity,":[17],"detection":[19,221],"plays":[22],"a":[23,57,95],"pivotal":[24],"role":[25],"in":[26,50,125,150,207],"safeguarding":[27],"critical":[28],"systems":[29],"data.":[31],"this":[33,204],"paper,":[34],"we":[35,77],"evaluate":[36],"efficacy":[38],"source":[41],"code":[42,53],"embeddings":[43,149],"obtained":[44],"from":[45],"pre-trained":[47],"CodeBERT":[48,89,148],"model":[49],"detecting":[51,126],"vulnerable":[52],"snippets":[54],"perform":[56,163],"comparative":[58],"analysis":[59],"with":[60,128],"different":[61,84],"data":[62,189],"pre-processing":[63,190],"ML":[65],"classification":[66,101],"algorithms":[67],"to":[68,112,173,210],"recommend":[69],"best":[71,165],"techniques":[72,187,191],"for":[73,166],"vulnerability":[74,167,220],"detection.":[75],"Precisely,":[76],"investigated":[78],"predictive":[80],"ability":[81],"540":[83],"models":[85,109,120,136],"developed":[86,135],"using":[87,194],"embeddings,":[90],"five":[91],"feature":[92,185],"selection":[93,186],"techniques,":[94],"class":[96,182],"balancing":[97,183],"technique,":[98],"fifteen":[100],"algorithms.":[102],"Unlike":[103],"regular":[104],"deep":[105],"learning-based":[106],"models,":[107],"these":[108],"quick":[111],"implement":[113],"require":[115],"minimal":[116],"computational":[117],"resources.":[118],"The":[119,134,201],"evaluated":[122,193],"on":[123],"robustness":[124],"codes":[127],"known":[129],"previously":[131],"unseen":[132],"vulnerabilities.":[133,152],"display":[137],"high":[138],"average":[139],"accuracy":[140],"AUC,":[142],"proving":[143],"efficiency":[145],"capturing":[151],"We":[153],"find":[154],"that":[155],"ensembles":[156],"decision":[158],"trees":[159],"(RF":[160],"EXTR)":[162],"detection,":[168],"which":[169],"can":[170],"be":[171],"attributed":[172],"advantages":[175],"ensembling.":[177],"Furthermore,":[178],"effectiveness":[180],"as":[188],"is":[192],"box":[195],"plots":[196],"Friedman":[199],"test.":[200],"significance":[202],"research":[205],"lies":[206],"its":[208],"contribution":[209],"field":[212],"cybersecurity":[214],"by":[215],"introducing":[216],"reliable":[217],"efficient":[219],"methods.":[222]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4391979639","counts_by_year":[],"updated_date":"2024-10-17T12:17:59.006510","created_date":"2024-02-21"}