7 papers
Domain-constrained Synthesis of Inconsistent Key Aspects in Textual Vulnerability Descriptions
Linyi Han, Shidong Pan, Zhenchang Xing +5
Textual Vulnerability Descriptions (TVDs) are crucial for security analysts to understand and address software vulnerabilities. However, the key aspect inconsistencies in TVDs from…
The "4W+1H" of Software Supply Chain Security Checklist for Critical Infrastructure
Liming Dong, Sung Une Lee, Zhenchang Xing +2
The increasing frequency and sophistication of software supply chain attacks pose severe risks to critical infrastructure sectors, threatening national security, economic stability…
Think Like an Engineer: A Neuro-Symbolic Collaboration Agent for Generative Software Requirements Elicitation and Self-Review
Sai Zhang, Zhenchang Xing, Jieshan Chen +5
The vision of End-User Software Engineering (EUSE) is to empower non-professional users with full control over the software development lifecycle. It aims to enable users to drive…
Rethinking Broken Object Level Authorization Attacks Under Zero Trust Principle
Anbin Wu, Zhiyong Feng, Ruitao Feng +2
RESTful APIs facilitate data exchange between applications, but they also expose sensitive resources to potential exploitation. Broken Object Level Authorization (BOLA) is the top…
Human-Like Code Quality Evaluation through LLM-based Recursive Semantic Comprehension
Fangzhou Xu, Sai Zhang, Zhenchang Xing +3
Code quality evaluation involves scoring generated code quality based on a reference code for a specific problem statement. Currently, there are two main forms of evaluating code q…
Empowering Agile-Based Generative Software Development through Human-AI Teamwork
Sai Zhang, Zhenchang Xing, Ronghui Guo +6
In software development, the raw requirements proposed by users are frequently incomplete, which impedes the complete implementation of application functionalities. With the emerge…