Why Not Fix It Once and for All? An Empirical Study of Multiple Patches for Vulnerability Fixes in Open-Source Software
Weiliang Qi, Youpeng Li, Xinda Wang
cs.CR, cs.SE
Submitted: 2026-07-14
Comments: Accepted at ESORICS 2026
Code: https://github.com/CVEProject/cvedocuments
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Vulnerability Detection with Code Language Models: How Far Are We?
- CodeBERT: A Pre-Trained Model for Programming and Natural Languages
- UniXcoder: Unified Cross-Modal Pre-training for Code Representation
- VulDeePecker: A Deep Learning-Based System for Vulnerability Detection
- CodeXGLUE: A Machine Learning Benchmark Dataset for Code Understanding and Generation
- LLMBisect: Breaking Barriers in Bug Bisection with A Comparative Analysis Pipeline
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs