3 papers
cs.SE2026
One Is Not Enough: The Untold Story of Multiple Security Patches for One Vulnerability
Fangyuan Zhang, Lyuye Zhang, Lingling Fan +6
Security patches (SPs) are the main mechanism for fixing software vulnerabilities, yet a single vulnerability is not always resolved by a single patch: fixes may be completed incre…
cs.SE2026
Benchmarking Automated Security Patch Backporting: How Far Are We?
Jincheng Yang, Yulong Fu, Chengwei Liu +5
Automated security patch backporting is critical for mitigating N-day vulnerabilities. Recent tools report success rates above 80% on their respective datasets. However, these eval…
cs.SE2026
Implicit, Yet Impactful: Understanding Hidden Dependencies in Java Projects
Lyuye Zhang, Chengwei Liu, Fangyuan Zhang +3
As software usage continues to expand, package managers automatically resolve dependencies to construct a dependency graph based on user-specified requirements. These explicitly de…