TraceVIC: Causal Reasoning over Code Evolution for Identifying Vulnerability-Inducing Commits
Software vulnerabilities are often discovered long after they are introduced, making it difficult to identify the vulnerability-inducing commit (VIC) responsible for introducing the underlying vulnerable condition. Existing VIC identification techniques largely rely on git blame to trace vulnerable code through revision history and use positional heuristics, such as selecting its earliest or most…
We haven't written up this one. arXiv cs.AI has the full story — the link below goes straight to it.