{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:NLAONIGFAVSC2ZWFCHRUO3XXBI","short_pith_number":"pith:NLAONIGF","schema_version":"1.0","canonical_sha256":"6ac0e6a0c505642d66c511e3476ef70a277c80841ad5723fbc6a84c9c6a47e23","source":{"kind":"arxiv","id":"2507.16661","version":1},"attestation_state":"computed","paper":{"title":"VulCoCo: A Simple Yet Effective Method for Detecting Vulnerable Code Clones","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"David Lo, Eng Lieh Ouh, Ferdian Thung, Frank Liauw, Han Wei Ang, Lwin Khin Shar, Tan Bui, Thanh Phuc Nguyen, Ting Zhang, Yan Naing Tun, Yide Yin, Yikun Li, Yindu Su","submitted_at":"2025-07-22T14:54:57Z","abstract_excerpt":"Code reuse is common in modern software development, but it can also spread vulnerabilities when developers unknowingly copy risky code. The code fragments that preserve the logic of known vulnerabilities are known as vulnerable code clones (VCCs). Detecting those VCCs is a critical but challenging task. Existing VCC detection tools often rely on syntactic similarity or produce coarse vulnerability predictions without clear explanations, limiting their practical utility. In this paper, we propose VulCoCo, a lightweight and scalable approach that combines embedding-based retrieval with large la"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.16661","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2025-07-22T14:54:57Z","cross_cats_sorted":[],"title_canon_sha256":"78d76ddecfe8b256b7faf33a5ded585d7a79cefba83a40e332c9431fadc5640d","abstract_canon_sha256":"362ddaf0fbea77e49638b1085541436bc08542223107b99290b6f9cadd467f79"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:41:28.712114Z","signature_b64":"7BrIp7szX6Lcm1N4C45DuRMq4qYGBIKMIXsk9VzSkk1Uub4fOEak6Zj0b3fus0p7+8iJFLitNKR/hMWvu3GzAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6ac0e6a0c505642d66c511e3476ef70a277c80841ad5723fbc6a84c9c6a47e23","last_reissued_at":"2026-07-05T11:41:28.711631Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:41:28.711631Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"VulCoCo: A Simple Yet Effective Method for Detecting Vulnerable Code Clones","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"David Lo, Eng Lieh Ouh, Ferdian Thung, Frank Liauw, Han Wei Ang, Lwin Khin Shar, Tan Bui, Thanh Phuc Nguyen, Ting Zhang, Yan Naing Tun, Yide Yin, Yikun Li, Yindu Su","submitted_at":"2025-07-22T14:54:57Z","abstract_excerpt":"Code reuse is common in modern software development, but it can also spread vulnerabilities when developers unknowingly copy risky code. The code fragments that preserve the logic of known vulnerabilities are known as vulnerable code clones (VCCs). Detecting those VCCs is a critical but challenging task. Existing VCC detection tools often rely on syntactic similarity or produce coarse vulnerability predictions without clear explanations, limiting their practical utility. In this paper, we propose VulCoCo, a lightweight and scalable approach that combines embedding-based retrieval with large la"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.16661","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.16661/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.16661","created_at":"2026-07-05T11:41:28.711681+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.16661v1","created_at":"2026-07-05T11:41:28.711681+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.16661","created_at":"2026-07-05T11:41:28.711681+00:00"},{"alias_kind":"pith_short_12","alias_value":"NLAONIGFAVSC","created_at":"2026-07-05T11:41:28.711681+00:00"},{"alias_kind":"pith_short_16","alias_value":"NLAONIGFAVSC2ZWF","created_at":"2026-07-05T11:41:28.711681+00:00"},{"alias_kind":"pith_short_8","alias_value":"NLAONIGF","created_at":"2026-07-05T11:41:28.711681+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI","json":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI.json","graph_json":"https://pith.science/api/pith-number/NLAONIGFAVSC2ZWFCHRUO3XXBI/graph.json","events_json":"https://pith.science/api/pith-number/NLAONIGFAVSC2ZWFCHRUO3XXBI/events.json","paper":"https://pith.science/paper/NLAONIGF"},"agent_actions":{"view_html":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI","download_json":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI.json","view_paper":"https://pith.science/paper/NLAONIGF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.16661&json=true","fetch_graph":"https://pith.science/api/pith-number/NLAONIGFAVSC2ZWFCHRUO3XXBI/graph.json","fetch_events":"https://pith.science/api/pith-number/NLAONIGFAVSC2ZWFCHRUO3XXBI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI/action/storage_attestation","attest_author":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI/action/author_attestation","sign_citation":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI/action/citation_signature","submit_replication":"https://pith.science/pith/NLAONIGFAVSC2ZWFCHRUO3XXBI/action/replication_record"}},"created_at":"2026-07-05T11:41:28.711681+00:00","updated_at":"2026-07-05T11:41:28.711681+00:00"}