4 papers · 1 filter
Understanding the Supply Chain and Risks of Large Language Model Applications
Yujie Ma, Lili Quan, Xiaofei Xie +4
The rise of Large Language Models (LLMs) has led to the widespread deployment of LLM-based systems across diverse domains. As these systems proliferate, understanding the risks ass…
Open Source, Hidden Costs: A Systematic Literature Review on OSS License Management
Boyuan Li, Chengwei Liu, Lingling Fan +3
Integrating third-party software components is a common practice in modern software development, offering significant advantages in terms of efficiency and innovation. However, thi…
A Comprehensive Study on Static Application Security Testing (SAST) Tools for Android
Jingyun Zhu, Kaixuan Li, Sen Chen +3
To identify security vulnerabilities in Android applications, numerous static application security testing (SAST) tools have been proposed. However, it poses significant challenges…
Does the Vulnerability Threaten Our Projects? Automated Vulnerable API Detection for Third-Party Libraries
Fangyuan Zhang, Lingling Fan, Sen Chen +3
Developers usually use TPLs to facilitate the development of the projects to avoid reinventing the wheels, however, the vulnerable TPLs indeed cause severe security threats. The ma…