5 papers
Empirical Computation: Prompting versus Programming
Eric Tang, Jing Liu, Marcel Böhme
Large Language Models (LLM) can solve *any* computational problem *without* an algorithm in a runtime *independent* of the computational complexity of that problem. Instead of spec…
How and Why Agents Can Identify Bug-Introducing Commits
Niklas Risse, Marcel Böhme
Åliwerski, Zimmermann, and Zeller (SZZ) just won the 2026 ACM SIGSOFT Impact Award for asking: When do changes induce fixes? Their paper from 2005 served as the foundation for a w…
Top Score on the Wrong Exam: On Benchmarking in Machine Learning for Vulnerability Detection
Niklas Risse, Jing Liu, Marcel Böhme
According to our survey of machine learning for vulnerability detection (ML4VD), 9 in every 10 papers published in the past five years define ML4VD as a function-level binary class…
Fundamental Challenges in Cybersecurity and a Philosophy of Vulnerability-Guided Hardening
Marcel Böhme
Research in cybersecurity may seem reactive, specific, ephemeral, and indeed ineffective. Despite decades of innovation in defense, even the most critical software systems turn out…
Uncovering the Limits of Machine Learning for Automatic Vulnerability Detection
Niklas Risse, Marcel Böhme
Recent results of machine learning for automatic vulnerability detection (ML4VD) have been very promising. Given only the source code of a function , ML4VD techniques can decide…