collaborators

8 papers

cs.SE2026

ATLAS: Agentic Taxonomy of Large-Scale Software Ecosystems

Junyi Lu, Mengyao Lyu, Jiahui Wu +6

The open-source ecosystem on GitHub lacks a systematic hierarchical taxonomy of software repositories. GitHub Topics, the dominant organizational mechanism, is flat, inconsistent,…

cs.CR2026

Cutting the Gordian Knot: Detecting Malicious PyPI Packages via a Knowledge-Mining Framework

Wenbo Guo, Chengwei Liu, Ming Kang +5

The Python Package Index (PyPI) has become a target for malicious actors, yet existing detection tools generate false positive rates of 15-30%, incorrectly flagging one-third of le…

cs.SE2025

IntelliRadar: A Comprehensive Platform to Pinpoint Malicious Package Information from Cyber Intelligence

Wenbo Guo, Chengwei Liu, Limin Wang +4

Malicious packages in public registries pose serious threats to software supply chain security. While current software component analysis (SCA) tools rely on databases like OSV and…

cs.SE2025

JC-Finder: Detecting Java Clone-based Third-Party Library by Class-level Tree Analysis

Lida Zhao, Chaofan Li, Yueming Wu +10

While reusing third-party libraries (TPL) facilitates software development, its chaotic management has brought great threats to software maintenance and the unauthorized use of sou…

cs.SE2025

VFArchē: A Dual-Mode Framework for Locating Vulnerable Functions in Open-Source Software

Lyuye Zhang, Jian Zhang, Kaixuan Li +6

Software Composition Analysis (SCA) has become pivotal in addressing vulnerabilities inherent in software project dependencies. In particular, reachability analysis is increasingly…

cs.SE2025

Fixing Outside the Box: Uncovering Tactics for Open-Source Security Issue Management

Lyuye Zhang, Jiahui Wu, Chengwei Liu +5

In the rapidly evolving landscape of software development, addressing security vulnerabilities in open-source software (OSS) has become critically important. However, existing rese…