4 papers · 1 filter
The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs
Siqi Zhang, Fabio Massacci, Mengyuan Zhang
For decades, the National Vulnerability Database (NVD), the "Cathedral", has been the reference source for vulnerability information for downstream research and industry tasks, e.g…
Helpful or Harmful? Evaluating LLM-Assisted Vulnerability Patching via a Human Study
Giulian Biolo, Michael Tezza, Yuanjun Gong +1
Software vulnerability remediation is a cognitively demanding task that requires specialized security expertise often lacking in general developers. In the meantime, Large Language…
LLMs for Qualitative Data Analysis Fail on Security-specificComments in Human Experiments
Maria Camporese, Fabio Massacci, Yuanjun Gong
[Background:] Thematic analysis of free-text justifications in human experiments provides significant qualitative insights. Yet, it is costly because reliable annotations require m…
Risks of ignoring uncertainty propagation in AI-augmented security pipelines
Emanuele Mezzi, Aurora Papotti, Fabio Massacci +1
The use of AI technologies is being integrated into the secure development of software-based systems, with an increasing trend of composing AI-based subsystems (with uncertain leve…