activity
20242026
collaborators
Showing cs.SEShow all

5 papers · 1 filter

cs.SE2026

The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs

Siqi Zhang, Fabio Massacci, Mengyuan Zhang

For decades, the National Vulnerability Database (NVD), the "Cathedral", has been the reference source for vulnerability information for downstream research and industry tasks, e.g…

cs.SE2026

Helpful or Harmful? Evaluating LLM-Assisted Vulnerability Patching via a Human Study

Giulian Biolo, Michael Tezza, Yuanjun Gong +1

Software vulnerability remediation is a cognitively demanding task that requires specialized security expertise often lacking in general developers. In the meantime, Large Language…

cs.SE2026

LLMs for Qualitative Data Analysis Fail on Security-specificComments in Human Experiments

Maria Camporese, Fabio Massacci, Yuanjun Gong

[Background:] Thematic analysis of free-text justifications in human experiments provides significant qualitative insights. Yet, it is costly because reliable annotations require m…

cs.SE2024

Risks of ignoring uncertainty propagation in AI-augmented security pipelines

Emanuele Mezzi, Aurora Papotti, Fabio Massacci +1

The use of AI technologies is being integrated into the secure development of software-based systems, with an increasing trend of composing AI-based subsystems (with uncertain leve…

cs.SE20242 cited

Analyzing and Mitigating (with LLMs) the Security Misconfigurations of Helm Charts from Artifact Hub

Francesco Minna, Fabio Massacci, Katja Tuma

Background: Helm is a package manager that allows defining, installing, and upgrading applications with Kubernetes (K8s), a popular container orchestration platform. A Helm chart i…