{"id":"https://openalex.org/W7135420219","doi":"https://doi.org/10.1016/j.jss.2026.112855","title":"ReVul-CoT: Towards effective software vulnerability assessment with retrieval-augmented generation and chain-of-thought prompting","display_name":"ReVul-CoT: Towards effective software vulnerability assessment with retrieval-augmented generation and chain-of-thought prompting","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7135420219","doi":"https://doi.org/10.1016/j.jss.2026.112855"},"language":"en","primary_location":{"id":"doi:10.1016/j.jss.2026.112855","is_oa":false,"landing_page_url":"https://doi.org/10.1016/j.jss.2026.112855","pdf_url":null,"source":{"id":"https://openalex.org/S37879656","display_name":"Journal of Systems and Software","issn_l":"0164-1212","issn":["0164-1212","1873-1228"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Systems and Software","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5027407618","display_name":"Zhijie Chen","orcid":"https://orcid.org/0000-0002-6546-7352"},"institutions":[{"id":"https://openalex.org/I199305430","display_name":"Nantong University","ror":"https://ror.org/02afcvw97","country_code":"CN","type":"education","lineage":["https://openalex.org/I199305430"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhijie Chen","raw_affiliation_strings":["School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China","institution_ids":["https://openalex.org/I199305430"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129243533","display_name":"Xiang Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I199305430","display_name":"Nantong University","ror":"https://ror.org/02afcvw97","country_code":"CN","type":"education","lineage":["https://openalex.org/I199305430"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xiang Chen","raw_affiliation_strings":["School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China","institution_ids":["https://openalex.org/I199305430"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065198327","display_name":"Z.B. Li","orcid":"https://orcid.org/0009-0008-6924-8510"},"institutions":[{"id":"https://openalex.org/I199305430","display_name":"Nantong University","ror":"https://ror.org/02afcvw97","country_code":"CN","type":"education","lineage":["https://openalex.org/I199305430"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ziming Li","raw_affiliation_strings":["School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China","institution_ids":["https://openalex.org/I199305430"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074162313","display_name":"Jiamei Xue","orcid":null},"institutions":[{"id":"https://openalex.org/I199305430","display_name":"Nantong University","ror":"https://ror.org/02afcvw97","country_code":"CN","type":"education","lineage":["https://openalex.org/I199305430"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiacheng Xue","raw_affiliation_strings":["School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China","institution_ids":["https://openalex.org/I199305430"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5010878830","display_name":"Chaoyang Gao","orcid":null},"institutions":[{"id":"https://openalex.org/I199305430","display_name":"Nantong University","ror":"https://ror.org/02afcvw97","country_code":"CN","type":"education","lineage":["https://openalex.org/I199305430"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chaoyang Gao","raw_affiliation_strings":["School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China","institution_ids":["https://openalex.org/I199305430"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5129243533"],"corresponding_institution_ids":["https://openalex.org/I199305430"],"apc_list":{"value":3560,"currency":"USD","value_usd":3560},"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.77260445,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"237","issue":null,"first_page":"112855","last_page":"112855"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.4494999945163727,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.4494999945163727,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.3222000002861023,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.04820000007748604,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.6396999955177307},{"id":"https://openalex.org/keywords/ranking","display_name":"Ranking (information retrieval)","score":0.534500002861023},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.4950999915599823},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.48159998655319214},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4530999958515167},{"id":"https://openalex.org/keywords/matching","display_name":"Matching (statistics)","score":0.44369998574256897},{"id":"https://openalex.org/keywords/point","display_name":"Point (geometry)","score":0.44190001487731934},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.43880000710487366}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7577999830245972},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.6396999955177307},{"id":"https://openalex.org/C189430467","wikidata":"https://www.wikidata.org/wiki/Q7293293","display_name":"Ranking (information retrieval)","level":2,"score":0.534500002861023},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.4950999915599823},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.48159998655319214},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4530999958515167},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.44369998574256897},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.44190001487731934},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.43880000710487366},{"id":"https://openalex.org/C4554734","wikidata":"https://www.wikidata.org/wiki/Q593744","display_name":"Knowledge base","level":2,"score":0.4372999966144562},{"id":"https://openalex.org/C172776598","wikidata":"https://www.wikidata.org/wiki/Q7943570","display_name":"Vulnerability management","level":4,"score":0.41670000553131104},{"id":"https://openalex.org/C12725497","wikidata":"https://www.wikidata.org/wiki/Q810247","display_name":"Baseline (sea)","level":2,"score":0.41600000858306885},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.382999986410141},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.37630000710487366},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.37560001015663147},{"id":"https://openalex.org/C167063184","wikidata":"https://www.wikidata.org/wiki/Q1400839","display_name":"Vulnerability assessment","level":3,"score":0.3564000129699707},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3305000066757202},{"id":"https://openalex.org/C2777267654","wikidata":"https://www.wikidata.org/wiki/Q3519023","display_name":"Test (biology)","level":2,"score":0.32659998536109924},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.32339999079704285},{"id":"https://openalex.org/C168167062","wikidata":"https://www.wikidata.org/wiki/Q1117970","display_name":"Component (thermodynamics)","level":2,"score":0.313400000333786},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.30309998989105225},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.29010000824928284},{"id":"https://openalex.org/C184356942","wikidata":"https://www.wikidata.org/wiki/Q830382","display_name":"Best practice","level":2,"score":0.28780001401901245},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.27709999680519104},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.27459999918937683},{"id":"https://openalex.org/C1009929","wikidata":"https://www.wikidata.org/wiki/Q179550","display_name":"Software bug","level":3,"score":0.2551000118255615}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1016/j.jss.2026.112855","is_oa":false,"landing_page_url":"https://doi.org/10.1016/j.jss.2026.112855","pdf_url":null,"source":{"id":"https://openalex.org/S37879656","display_name":"Journal of Systems and Software","issn_l":"0164-1212","issn":["0164-1212","1873-1228"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Systems and Software","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.6141116619110107,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W2059185913","https://openalex.org/W2060758175","https://openalex.org/W2119821739","https://openalex.org/W2620760558","https://openalex.org/W2890264517","https://openalex.org/W3098605233","https://openalex.org/W3184339106","https://openalex.org/W3198685994","https://openalex.org/W4206664668","https://openalex.org/W4319319488","https://openalex.org/W4368373697","https://openalex.org/W4385757764","https://openalex.org/W4388778348","https://openalex.org/W4390813110","https://openalex.org/W4392996195","https://openalex.org/W4393029443","https://openalex.org/W4393166720","https://openalex.org/W4393237100","https://openalex.org/W4396982340","https://openalex.org/W4404728511","https://openalex.org/W4409376547","https://openalex.org/W4410308078","https://openalex.org/W4411219919","https://openalex.org/W4412695867","https://openalex.org/W4414437166","https://openalex.org/W7133198585"],"related_works":[],"abstract_inverted_index":null,"counts_by_year":[],"updated_date":"2026-03-21T06:30:42.041108","created_date":"2026-03-15T00:00:00"}
