EDBT 2026 Demo / reviewers in the wild / expert
Ying Wei 0012
dblp:14/4899-12
· DBLP profile ↗
9ranked-venue papers
2as first author
9since 2021 · last 2024
0000-0003-4652-5083ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 2 first-author · 9 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | ChatBR: Automated assessment and improvement of bug report quality using ChatGPTabstractBug reports, containing crucial information such as the Observed Behavior (OB), the Expected Behavior (EB), and the Steps to Reproduce (S2R), can help developers localize and fix bugs efficiently. However, due to the increasing complexity of some bugs and the limited experience of some reporters, large numbers of bug reports miss this crucial information. Although machine learning (ML)-based and information retrieval (IR)-based approaches are proposed to detect and supplement the missing information in bug reports, the performance of these approaches depends heavily on the size and quality of bug report datasets. Lili Bo, Wangjie Ji, Xiaobing Sun 0001, Ting Zhang 0011, Xiaoxue Wu 0001, Ying Wei 0012 |
ASE | 6 |
| 2024 | Software bug localization based on optimized and ensembled deep learning modelsabstractAbstract An automated task for finding the essential buggy files among software projects with the help of a given bug report is termed bug localization. The conventional approaches suffer from the challenges of performing lexical matching. Particularly, the terms utilized for describing the bugs in the bug reports are observed to be irrelevant to the terms used in the source code files. To resolve these problems, we propose an optimized and ensemble deep learning model for software bug localization. These features are reduced by the principle component analysis (PCA). Then, they are selected by the weighted convolutional neural network (CNN) model with the support of the Modified Scatter Probability‐based Coyote Optimization Algorithm (MSP‐COA). Finally, the optimal features are subjected to the ensemble deep neural network and long short‐term memory (DNN‐LSTM), with parameter tuning by the MSP‐COA. Experimental results show that the proposed approach can achieve higher bug localization accuracy than individual models. Lili Bo, Xiaobing Sun 0001, Xiaoxue Wu 0001, Aakash Ali, Ying Wei 0012 |
J. Softw. Evol. Process. | 6 |
| 2024 | Automatic software vulnerability classification by extracting vulnerability triggersabstractAbstract Vulnerability classification is a significant activity in software development and software maintenance. Natural Language Processing (NLP) techniques, which utilize the descriptions in public repositories, are widely used in automatic software vulnerability classification. However, vulnerability descriptions are ordinarily short and contain many technical terms, making them difficult for machines to automatically comprehend. In this paper, we present an approach based on vulnerability triggers to automatically classify vulnerabilities. First, we extract vulnerability triggers with Bert Question and Answer (Bert Q&A). Then, we use Recurrent Convolutional Neural Networks for Text classification (TextRCNN) to classify vulnerabilities based on Common Weakness Enumeration (CWE). We statistically perform an analysis of vulnerability triggers and comprehensively evaluate the classification performance of our approach on a set of 4769 prelabeled vulnerability entries, as well as compare it with state‐of‐the‐art vulnerability classification approaches. Experiment results show that our approach can achieve a F1‐measure of 95% on extraction and 80.8% on classification. Xiaobing Sun 0001, Lili Bo, Xiaojun Wu 0001, Ying Wei 0012, Bin Li 0006 |
J. Softw. Evol. Process. | 5 |
| 2023 | Automated event extraction of CVE descriptions
Ying Wei 0012, Lili Bo, Xiaobing Sun 0001, Bin Li 0006, Tao Zhang 0001, Chuanqi Tao |
Inf. Softw. Technol. | 1 |
| 2023 | Automatic software vulnerability assessment by extracting vulnerability elements
Xiaobing Sun 0001, Zhenlei Ye, Lili Bo, Xiaoxue Wu 0001, Ying Wei 0012, Tao Zhang 0001, Bin Li 0006 |
J. Syst. Softw. | 5 |
| 2022 | KVS: a tool for knowledge-driven vulnerability searchingabstractIt is difficult to quickly locate and search for specific vulnerabilities and their solutions because vulnerability information is scattered in the existing vulnerability management library. To alleviate this problem, we extract knowledge from vulnerability reports and organize the vulnerability information into the form of a knowledge graph. Then, we implement a tool for knowledge-driven vulnerability searching, KVS. This tool mainly uses the BERT model to realize the vulnerability named entity recognition and construct the vulnerability knowledge graph (VulKG). Finally, we can search vulnerabilities of interest-based on VulKG. The URL of this tool is https://cinnqi.github.io/Neo4j-D3-VKG/. Video of our demo is available at https://youtu.be/FT1BaLUGPk0. Xingqi Cheng, Xiaobing Sun 0001, Lili Bo, Ying Wei 0012 |
ESEC/SIGSOFT FSE | 4 |
| 2022 | Towards the identification of bug entities and relations in bug reports
Bin Li 0006, Ying Wei 0012, Xiaobing Sun 0001, Lili Bo, Dingshan Chen, Chuanqi Tao |
Autom. Softw. Eng. | 2 |
| 2021 | BGNN4VD: Constructing Bidirectional Graph Neural-Network for Vulnerability Detection
Sicong Cao, Xiaobing Sun 0001, Lili Bo, Ying Wei 0012, Bin Li 0006 |
Inf. Softw. Technol. | 4 |
| 2021 | A comprehensive study on security bug characteristicsabstractAbstract Security bugs can catastrophically impact our increasingly digital lives. Designing effective tools for detecting and fixing software security bugs requires a deep understanding of security bug characteristics. In this paper, we conducted a comprehensive study on security bugs and proposed the classification criteria for security bug category, that is, root cause, consequence, and location. In addition, we selected 1076 bug reports from five projects (i.e., Apache Tomcat, Apache HTTP Server, Mozilla Firefox, Linux Kernel, and Eclipse) in the NVD for investigation. Finally, we investigated the correlation between the classification results and obtained some findings: (1) memory operation is the most common security bug; (2) the primary root causes of security bugs are CON (Configuration Error), INP (Input Validation Error), and MEM (Memory Error); (3) the severity of more than 40% of security bugs is high; (4) security bugs caused by INP mainly occur on web; and (5) security bugs caused by LOG (Logic Resource Error) usually lead to DoS (Denial of Service). We discussed these findings through data analysis, which can also help developers better understand the characteristics of security bugs. Ying Wei 0012, Xiaobing Sun 0001, Lili Bo, Sicong Cao, Xin Xia 0001, Bin Li 0006 |
J. Softw. Evol. Process. | 1 |