1
Return

Automated Localization of Affected Libraries and Versions from Vulnerability Reports

delete2026-04-29
delete0
PRE
AI
J
Ji-Shao Xu
H
He Zhang
X
Xin Zhou
Y
Yanjing Yang
J
Jinghao Hu
李小康 (Xiaokang Li)
L
Lanxin Yang
B
Bohan Liu
DOI:10.1109/tse.2026.3688559delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Security experts investigate vulnerability reports to analyze the impact scope of a vulnerability, specifically the affected libraries and versions. As large language models (LLMs) exhibit powerful capabilities in understanding vulnerability reports, many LLM-based approaches have been proposed to address this problem. However, existing approaches primarily focus on locating affected libraries without considering the corresponding affected versions, which results in an overestimation of vulnerability impact and leads to unnecessary protection efforts. Leveraging LLMs to locate affected libraries and versions has two challenges: inaccurate and incomplete information in the vulnerability report, which arises from the input side; LLM’s hallucinations, which arise from the output side. To do so, we propose <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> in this article. For the first challenge, <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> first performs knowledge augmentation on vulnerability reports by retrieving additional information from security vendors (<italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">e</i>.<italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">g</i>., Snyk) and ecosystem advisories (<italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">e</i>.<italic xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">g</i>., Jenkins). Then, <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> locally fine-tunes an LLM to locate affected libraries and versions based on the augmented vulnerability reports. For the second challenge, <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> integrates a local search algorithm to verify the validity of LLM outputs and a fixing commit detection algorithm to improve the accuracy. We evaluate <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> using 3,200 NVD vulnerability reports. The experimental results show that for locating affected libraries, <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> improves the F1@3 from 76.44% to 95.54%, and for locating affected versions, <sc xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">VulLoc</small> improves the F1@3 from 39.26% to 77.35%.
Keywords:
Third-party library
affected library
affected version
large language model
software supply chain security

Journal

IEEE Transactions on Software Engineering cover
IEEE Transactions on Software Engineering
IF:
5.6
Papers:
2.8K
Citations:
1.1W

Organization

N
nanjing university
Scholars:
7.6W
Papers: 5.5W
Citations: 87
Cited Papers

Cited Papers

Citing Papers

Citing Papers