{"id":"https://openalex.org/W4285490485","doi":"https://doi.org/10.1145/3533767.3534387","title":"Program vulnerability repair via inductive inference","display_name":"Program vulnerability repair via inductive inference","publication_year":2022,"publication_date":"2022-07-15","ids":{"openalex":"https://openalex.org/W4285490485","doi":"https://doi.org/10.1145/3533767.3534387"},"language":"en","primary_location":{"id":"doi:10.1145/3533767.3534387","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3533767.3534387","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102920981","display_name":"Yuntong Zhang","orcid":"https://orcid.org/0009-0005-1664-7110"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":true,"raw_author_name":"Yuntong Zhang","raw_affiliation_strings":["National University of Singapore, Singapore"],"affiliations":[{"raw_affiliation_string":"National University of Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101516064","display_name":"Xiang Gao","orcid":"https://orcid.org/0009-0005-1494-9676"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiang Gao","raw_affiliation_strings":["Beihang University, China"],"affiliations":[{"raw_affiliation_string":"Beihang University, China","institution_ids":["https://openalex.org/I82880672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069809962","display_name":"Gregory J. Duck","orcid":"https://orcid.org/0000-0002-0837-9671"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Gregory J. Duck","raw_affiliation_strings":["National University of Singapore, Singapore"],"affiliations":[{"raw_affiliation_string":"National University of Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060115298","display_name":"Abhik Roychoudhury","orcid":"https://orcid.org/0000-0002-7127-1137"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Abhik Roychoudhury","raw_affiliation_strings":["National University of Singapore, Singapore"],"affiliations":[{"raw_affiliation_string":"National University of Singapore, Singapore","institution_ids":["https://openalex.org/I165932596"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5102920981"],"corresponding_institution_ids":["https://openalex.org/I165932596"],"apc_list":null,"apc_paid":null,"fwci":7.4142,"has_fulltext":false,"cited_by_count":28,"citation_normalized_percentile":{"value":0.97738446,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"691","last_page":"702"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12423","display_name":"Software Reliability and Analysis Research","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/fuzz-testing","display_name":"Fuzz testing","score":0.8947809338569641},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7467119097709656},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6045626401901245},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.5820468068122864},{"id":"https://openalex.org/keywords/concolic-testing","display_name":"Concolic testing","score":0.4974985420703888},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.4907701909542084},{"id":"https://openalex.org/keywords/symbolic-execution","display_name":"Symbolic execution","score":0.48243674635887146},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.42390698194503784},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3884202539920807},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.33742374181747437},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.3283228874206543},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2929805815219879},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.22577330470085144}],"concepts":[{"id":"https://openalex.org/C111065885","wikidata":"https://www.wikidata.org/wiki/Q1189053","display_name":"Fuzz testing","level":3,"score":0.8947809338569641},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7467119097709656},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6045626401901245},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.5820468068122864},{"id":"https://openalex.org/C11219265","wikidata":"https://www.wikidata.org/wiki/Q5158734","display_name":"Concolic testing","level":4,"score":0.4974985420703888},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.4907701909542084},{"id":"https://openalex.org/C2779639559","wikidata":"https://www.wikidata.org/wiki/Q7661178","display_name":"Symbolic execution","level":3,"score":0.48243674635887146},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.42390698194503784},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3884202539920807},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.33742374181747437},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.3283228874206543},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2929805815219879},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.22577330470085144}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3533767.3534387","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3533767.3534387","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.6899999976158142,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":27,"referenced_works":["https://openalex.org/W1480909796","https://openalex.org/W2072000086","https://openalex.org/W2097556400","https://openalex.org/W2110908283","https://openalex.org/W2145373440","https://openalex.org/W2274071363","https://openalex.org/W2343875716","https://openalex.org/W2344973853","https://openalex.org/W2400994325","https://openalex.org/W2548997977","https://openalex.org/W2735571786","https://openalex.org/W2741361950","https://openalex.org/W2766540688","https://openalex.org/W2794832431","https://openalex.org/W2898024328","https://openalex.org/W2898887472","https://openalex.org/W2960756002","https://openalex.org/W2974889942","https://openalex.org/W2998011150","https://openalex.org/W3004024657","https://openalex.org/W3033117380","https://openalex.org/W3101845936","https://openalex.org/W3129269689","https://openalex.org/W3167325648","https://openalex.org/W3176859472","https://openalex.org/W4244452926","https://openalex.org/W4253196470"],"related_works":["https://openalex.org/W3172606155","https://openalex.org/W3019261932","https://openalex.org/W2276185690","https://openalex.org/W2801797726","https://openalex.org/W157156687","https://openalex.org/W2186070848","https://openalex.org/W2785720764","https://openalex.org/W2375338395","https://openalex.org/W3104446232","https://openalex.org/W2984839971"],"abstract_inverted_index":{"Program":[0],"vulnerabilities,":[1,137],"even":[2],"when":[3],"detected":[4],"and":[5,17,173],"reported,":[6],"are":[7,59,99,169],"not":[8],"fixed":[9],"immediately.":[10],"The":[11,56],"time":[12],"lag":[13],"between":[14],"the":[15,66,83,121,127,132,149,186],"reporting":[16],"fixing":[18],"of":[19,135,151,204],"a":[20,39,205],"vulnerability":[21,146,161],"causes":[22],"open-source":[23],"software":[24],"systems":[25],"to":[26,31,48,72,82,105,125,157,197],"suffer":[27],"from":[28],"significant":[29],"exposure":[30],"possible":[32,53],"attacks.":[33],"In":[34],"this":[35],"paper,":[36],"we":[37,95,101,177],"propose":[38],"counter-example":[40],"guided":[41],"inductive":[42,77,192],"inference":[43],"procedure":[44],"over":[45,63,87],"program":[46,88,189],"states":[47,64],"define":[49],"likely":[50,57,92],"invariants":[51,58],"at":[52,65],"fix":[54,67],"locations.":[55],"constructed":[60],"via":[61,108,191,201],"mutation":[62],"location,":[68],"which":[69,94,138,168],"turns":[70],"out":[71],"be":[73],"more":[74,181],"effective":[75],"for":[76,160,188],"property":[78],"inference,":[79,194],"as":[80,164,195],"compared":[81,156],"usual":[84],"greybox":[85],"fuzzing":[86],"inputs.":[89],"Once":[90],"such":[91,163],"invariants,":[93,98],"call":[96],"patch":[97,110],"identified,":[100],"can":[102,178],"use":[103],"them":[104],"construct":[106],"patches":[107],"simple":[109],"templates.":[111],"Our":[112,183],"work":[113],"assumes":[114],"that":[115],"only":[116],"one":[117],"failing":[118],"input":[119],"(representing":[120],"exploit)":[122],"is":[123],"available":[124],"start":[126],"repair":[128,153,162,179,190,199],"process.":[129],"Experiments":[130],"on":[131,145,171],"VulnLoc":[133],"data-set":[134],"39":[136],"has":[139],"been":[140],"curated":[141],"in":[142],"previous":[143],"works":[144],"repair,":[147],"show":[148,185],"effectiveness":[150],"our":[152],"procedure.":[154],"As":[155],"proposed":[158],"approaches":[159],"CPR":[165],"or":[166],"SenX":[167],"based":[170],"concolic":[172],"symbolic":[174],"execution":[175],"respectively,":[176],"significantly":[180],"vulnerabilities.":[182],"results":[184],"potential":[187],"constraint":[193],"opposed":[196],"generating":[198],"constraints":[200],"deductive/symbolic":[202],"analysis":[203],"given":[206],"test-suite.":[207]},"counts_by_year":[{"year":2025,"cited_by_count":9},{"year":2024,"cited_by_count":11},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
