{"id":"https://openalex.org/W4224323202","doi":"https://doi.org/10.1145/3485447.3512235","title":"HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property Graphs","display_name":"HiddenCPG: Large-Scale Vulnerable Clone Detection Using Subgraph Isomorphism of Code Property Graphs","publication_year":2022,"publication_date":"2022-04-25","ids":{"openalex":"https://openalex.org/W4224323202","doi":"https://doi.org/10.1145/3485447.3512235"},"language":"en","primary_location":{"id":"doi:10.1145/3485447.3512235","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3485447.3512235","pdf_url":null,"source":{"id":"https://openalex.org/S4363608783","display_name":"Proceedings of the ACM Web Conference 2022","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2022","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5084848487","display_name":"Seongil Wi","orcid":"https://orcid.org/0000-0001-8081-4386"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":true,"raw_author_name":"Seongil Wi","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019840647","display_name":"Sijae Woo","orcid":null},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Sijae Woo","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090741314","display_name":"Joyce Jiyoung Whang","orcid":"https://orcid.org/0000-0002-4773-3194"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Joyce Jiyoung Whang","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5082893706","display_name":"Sooel Son","orcid":"https://orcid.org/0000-0003-0904-2875"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Sooel Son","raw_affiliation_strings":["School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea"],"affiliations":[{"raw_affiliation_string":"School of Computing, Korea Advanced Institute of Science and Technology, Republic of Korea","institution_ids":["https://openalex.org/I157485424"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5084848487"],"corresponding_institution_ids":["https://openalex.org/I157485424"],"apc_list":null,"apc_paid":null,"fwci":2.0428,"has_fulltext":false,"cited_by_count":17,"citation_normalized_percentile":{"value":0.8880789,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"755","last_page":"766"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/subgraph-isomorphism-problem","display_name":"Subgraph isomorphism problem","score":0.807579517364502},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7834844589233398},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.7062978744506836},{"id":"https://openalex.org/keywords/graph-isomorphism","display_name":"Graph isomorphism","score":0.584862470626831},{"id":"https://openalex.org/keywords/induced-subgraph-isomorphism-problem","display_name":"Induced subgraph isomorphism problem","score":0.5439895987510681},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.5139991641044617},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.4535757303237915},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.45036694407463074},{"id":"https://openalex.org/keywords/property","display_name":"Property (philosophy)","score":0.41273656487464905},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.34945791959762573},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.26096126437187195},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.18687763810157776}],"concepts":[{"id":"https://openalex.org/C131992880","wikidata":"https://www.wikidata.org/wiki/Q2528185","display_name":"Subgraph isomorphism problem","level":3,"score":0.807579517364502},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7834844589233398},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.7062978744506836},{"id":"https://openalex.org/C61665672","wikidata":"https://www.wikidata.org/wiki/Q303100","display_name":"Graph isomorphism","level":4,"score":0.584862470626831},{"id":"https://openalex.org/C191241153","wikidata":"https://www.wikidata.org/wiki/Q6027240","display_name":"Induced subgraph isomorphism problem","level":5,"score":0.5439895987510681},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.5139991641044617},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.4535757303237915},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.45036694407463074},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.41273656487464905},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.34945791959762573},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.26096126437187195},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.18687763810157776},{"id":"https://openalex.org/C203776342","wikidata":"https://www.wikidata.org/wiki/Q1378376","display_name":"Line graph","level":3,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C22149727","wikidata":"https://www.wikidata.org/wiki/Q7940747","display_name":"Voltage graph","level":4,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3485447.3512235","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3485447.3512235","pdf_url":null,"source":{"id":"https://openalex.org/S4363608783","display_name":"Proceedings of the ACM Web Conference 2022","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2022","raw_type":"proceedings-article"},{"id":"pmh:oai:scholarworks.unist.ac.kr:201301/65875","is_oa":false,"landing_page_url":"https://scholarworks.unist.ac.kr/handle/201301/65875","pdf_url":null,"source":{"id":"https://openalex.org/S4306401118","display_name":"Scholarworks@UNIST (Ulsan National Institute of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I48566637","host_organization_name":"Ulsan National Institute of Science and Technology","host_organization_lineage":["https://openalex.org/I48566637"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"CONFERENCE"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W1593203335","https://openalex.org/W1698439592","https://openalex.org/W1872325575","https://openalex.org/W1990762361","https://openalex.org/W1991074244","https://openalex.org/W1992114977","https://openalex.org/W2008158744","https://openalex.org/W2014590767","https://openalex.org/W2041190309","https://openalex.org/W2068932268","https://openalex.org/W2074529754","https://openalex.org/W2077204203","https://openalex.org/W2085925880","https://openalex.org/W2104301886","https://openalex.org/W2111487235","https://openalex.org/W2113709047","https://openalex.org/W2126359798","https://openalex.org/W2128782367","https://openalex.org/W2128888088","https://openalex.org/W2130107753","https://openalex.org/W2138110817","https://openalex.org/W2138756793","https://openalex.org/W2140840007","https://openalex.org/W2147405597","https://openalex.org/W2157532207","https://openalex.org/W2165739648","https://openalex.org/W2168103835","https://openalex.org/W2532962075","https://openalex.org/W2534610146","https://openalex.org/W2547625248","https://openalex.org/W2559935471","https://openalex.org/W2577142429","https://openalex.org/W2634106992","https://openalex.org/W2732351623","https://openalex.org/W2749008552","https://openalex.org/W2767683547","https://openalex.org/W2781491433","https://openalex.org/W2789627069","https://openalex.org/W2794744252","https://openalex.org/W2811327923","https://openalex.org/W2969658140","https://openalex.org/W3018238337","https://openalex.org/W3101228802","https://openalex.org/W3105926539","https://openalex.org/W3137884047","https://openalex.org/W3147107715","https://openalex.org/W3155061837","https://openalex.org/W3156952258","https://openalex.org/W3183794086","https://openalex.org/W3187895569","https://openalex.org/W4246774680","https://openalex.org/W4254829975"],"related_works":["https://openalex.org/W1482551403","https://openalex.org/W2954463587","https://openalex.org/W2393701947","https://openalex.org/W2915540008","https://openalex.org/W2018568077","https://openalex.org/W1965191464","https://openalex.org/W2128390795","https://openalex.org/W84561889","https://openalex.org/W167435155","https://openalex.org/W2540418660"],"abstract_inverted_index":{"A":[0],"code":[1,64],"property":[2],"graph":[3,51,59],"(CPG)":[4],"is":[5,121],"a":[6,17,41,46,50,84,104,107,112,117,167],"joint":[7],"representation":[8],"of":[9,16,27,33,39,139,150,170],"syntax,":[10],"control":[11],"flows,":[12],"and":[13,174],"data":[14],"flows":[15],"target":[18,47,108],"application.":[19],"Recent":[20],"studies":[21],"have":[22],"demonstrated":[23],"the":[24,31,37,124,130,136,148],"promising":[25],"efficacy":[26],"leveraging":[28],"CPGs":[29,165],"for":[30,45],"identification":[32],"vulnerabilities.":[34],"It":[35,55],"recasts":[36],"problem":[38],"implementing":[40],"specific":[42],"static":[43],"analysis":[44],"vulnerability":[48],"as":[49,123],"query":[52,115],"composition":[53],"problem.":[54,127],"requires":[56],"devising":[57],"coarse-grained":[58,68],"queries":[60,69],"that":[61,95,110,133],"model":[62],"vulnerable":[63,152],"patterns.":[65],"Unfortunately,":[66],"such":[67],"often":[70],"leave":[71],"vulnerabilities":[72,156,162],"due":[73],"to":[74,88,102,146],"faulty":[75],"input":[76],"sanitization":[77],"undetected.":[78],"In":[79],"this":[80,140],"paper,":[81],"we":[82],"propose,":[83],"scalable":[85],"system":[86],"designed":[87,101,145],"identify":[89],"various":[90],"web":[91],"vulnerabilities,":[92],"including":[93,157],"bugs":[94],"stem":[96],"from":[97,135],"incorrect":[98],"sanitization.":[99],"We":[100],"find":[103],"subgraph":[105,125],"in":[106,163],"CPG":[109,114],"matches":[111],"given":[113],"having":[116,166],"known":[118,122],"vulnerability,":[119],"which":[120],"isomorphism":[126],"To":[128],"address":[129],"scalability":[131],"challenge":[132],"stems":[134],"NP-complete":[137],"nature":[138],"problem,":[141],"leverages":[142],"optimization":[143],"techniques":[144],"boost":[147],"efficiency":[149],"matching":[151],"subgraphs.":[153],"found":[154],"confirmed":[155],"CVEs":[158],"among":[159],"2,464":[160],"potential":[161],"real-world":[164],"combined":[168],"total":[169],"1":[171],"billion":[172,176],"nodes":[173],"1.2":[175],"edges.":[177]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":2}],"updated_date":"2026-04-12T07:58:50.170612","created_date":"2025-10-10T00:00:00"}
