collaborators

5 papers

cs.SE2026

The Data Problem in Software Vulnerability Analysis: Artifacts, Quality, and Consumption

Yu Nong, Yao Du, Tianxiang Xu +1

Learning- and LLM-based software vulnerability analysis is only as trustworthy as the data it is trained and evaluated on, yet that data is rarely examined as a first-class object.…

cs.CR2026

How Reliable Are NVD CWE Labels? A Large-Scale Semantic Audit with Seclometry

Yu Nong, Yao Du, Majid Behravan +1

CWE labels in the National Vulnerability Database (NVD) are widely treated as ground truth for vulnerability search, scanner evaluation, benchmark construction, learning-based secu…

cs.SE2026

Neuro-Symbolic Proof-of-Vulnerability Generation with Open-Weight Models

Yu Nong, Haipeng Cai

Software vulnerabilities are persistent, but validating them remains difficult: a Proof-of-Vulnerability (PoV) requires a concrete input that triggers the vulnerable behavior, yet…

cs.CR2024

APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching

Yu Nong, Haoran Yang, Long Cheng +2

Timely and effective vulnerability patching is essential for cybersecurity defense, for which various approaches have been proposed yet still struggle to generate valid and correct…

cs.SE2024

VulScribeR: Exploring RAG-based Vulnerability Augmentation with LLMs

Seyed Shayan Daneshvar, Yu Nong, Xu Yang +2

Detecting vulnerabilities is vital for software security, yet deep learning-based vulnerability detectors (DLVD) face a data shortage, which limits their effectiveness. Data augmen…