Guilong Lu

dblp:332/4483 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0009-8336-9009ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 2 first-author · 5 since 2021
YearPublicationVenuePosition
2025 Semi-supervised software vulnerability assessment via code lexical and structural information fusion
Wenlong Pei, Xiang Chen 0005, Guilong Lu, Yong Liu 0030, Chao Ni 0001
Autom. Softw. Eng.4
2025 SIFT: enhance the performance of vulnerability detection by incorporating structural knowledge and multi-task learning
Guilong Lu, Xiaofeng Dai, Jianlin Qiu
Autom. Softw. Eng.2
2024 CSVD-TF: Cross-project software vulnerability detection with TrAdaBoost by fusing expert metrics and semantic metrics
Zhilong Cai, Yongwei Cai, Xiang Chen 0005, Guilong Lu, Wenlong Pei
J. Syst. Softw.4
2024 GRACE: Empowering LLM-based software vulnerability detection with graph structure and in-context learning
Guilong Lu, Xiaolin Ju, Xiang Chen 0005, Wenlong Pei, Zhilong Cai
J. Syst. Softw.1
2023 Assessing the Effectiveness of Vulnerability Detection via Prompt Tuning: An Empirical Study
abstract
In vulnerability detection approaches based on deep learning, fine-tuning with Pre-trained Language Models (PLMs) is a prevalent technique. Unfortunately, a natural gap exists between model pre-training tasks and vulnerability detection tasks due to different input formats, and the performance of fine-tuning relies on downstream dataset scales. Recently, prompt tuning has been used to alleviate these issues. However, it has not received enough attention in vulnerability detection. To assess the effectiveness of prompt tuning, we consider three classical vulnerability detection tasks: within-domain vulnerability detection, cross-domain vulnerability detection, and vulnerability type detection. Our empirical study considers three popular PLMs: CodeBERT, CodeT5, and CodeGPT. Then we use Devign, BigVul, and Reveal datasets as our experimental subjects. Our empirical results indicate that (1) compared to fine-tuning, prompt tuning can increase the accuracy of three tasks by an average of 42 %, 38%, and 41 %, respectively; (2) different prompt templates can have up to an 8 % impact on accuracy; (3) in data scarcity scenarios, the superiority of prompt tuning over fine-tuning is more obvious. Our research demonstrates that using prompt tuning can help to achieve better performance in vulnerability detection tasks and is a promising research direction in the future.
Guilong Lu, Xiaolin Ju, Xiang Chen 0005, Shaoyu Yang 0002, Hao Shen 0011
APSEC1