{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:PJU67DCRHF7QD5C7XMXQG2PP5S","short_pith_number":"pith:PJU67DCR","schema_version":"1.0","canonical_sha256":"7a69ef8c51397f01f45fbb2f0369efec9f4d1e8c3e855058b91bca285e3f0402","source":{"kind":"arxiv","id":"2407.16235","version":1},"attestation_state":"computed","paper":{"title":"Comparison of Static Application Security Testing Tools and Large Language Models for Repo-level Vulnerability Detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.SE","authors_text":"Bach Le, David Lo, Duc-Manh Tran, Ivana Clairine Irsan, Joshua Sumarlin, Thanh Le-Cong, Ting Zhang, Xin Zhou","submitted_at":"2024-07-23T07:21:14Z","abstract_excerpt":"Software vulnerabilities pose significant security challenges and potential risks to society, necessitating extensive efforts in automated vulnerability detection. There are two popular lines of work to address automated vulnerability detection. On one hand, Static Application Security Testing (SAST) is usually utilized to scan source code for security vulnerabilities, especially in industries. On the other hand, deep learning (DL)-based methods, especially since the introduction of large language models (LLMs), have demonstrated their potential in software vulnerability detection. However, th"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.16235","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2024-07-23T07:21:14Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"f6b1bba740f34ba0763640bdc9ec4ba0ce44cbfd2594ad1369ce07ed359d0e35","abstract_canon_sha256":"a1007b1fa9b96f9eb12a7183d2d3e1bd6a89b806c7d253e99305d15d8fdcf41f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:47:30.114920Z","signature_b64":"FqQriktL34ac4DDa/69HFshug34zLq4yI2nmzmugRt9V4FyN5AlAS7Bbj9Q1kPHLZBK7+vbtqVc1uJEXc41rBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7a69ef8c51397f01f45fbb2f0369efec9f4d1e8c3e855058b91bca285e3f0402","last_reissued_at":"2026-07-05T08:47:30.114485Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:47:30.114485Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Comparison of Static Application Security Testing Tools and Large Language Models for Repo-level Vulnerability Detection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.SE","authors_text":"Bach Le, David Lo, Duc-Manh Tran, Ivana Clairine Irsan, Joshua Sumarlin, Thanh Le-Cong, Ting Zhang, Xin Zhou","submitted_at":"2024-07-23T07:21:14Z","abstract_excerpt":"Software vulnerabilities pose significant security challenges and potential risks to society, necessitating extensive efforts in automated vulnerability detection. There are two popular lines of work to address automated vulnerability detection. On one hand, Static Application Security Testing (SAST) is usually utilized to scan source code for security vulnerabilities, especially in industries. On the other hand, deep learning (DL)-based methods, especially since the introduction of large language models (LLMs), have demonstrated their potential in software vulnerability detection. However, th"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.16235","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.16235/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.16235","created_at":"2026-07-05T08:47:30.114542+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.16235v1","created_at":"2026-07-05T08:47:30.114542+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.16235","created_at":"2026-07-05T08:47:30.114542+00:00"},{"alias_kind":"pith_short_12","alias_value":"PJU67DCRHF7Q","created_at":"2026-07-05T08:47:30.114542+00:00"},{"alias_kind":"pith_short_16","alias_value":"PJU67DCRHF7QD5C7","created_at":"2026-07-05T08:47:30.114542+00:00"},{"alias_kind":"pith_short_8","alias_value":"PJU67DCR","created_at":"2026-07-05T08:47:30.114542+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.30587","citing_title":"Words Speak Louder Than Code: Investigating Cognitive Heuristics in LLM-Based Code Vulnerability Detection","ref_index":39,"is_internal_anchor":false},{"citing_arxiv_id":"2601.22655","citing_title":"Do Fine-Tuned LLMs Understand Vulnerabilities? An Investigation into the Semantic Trap","ref_index":53,"is_internal_anchor":false},{"citing_arxiv_id":"2605.07900","citing_title":"Longitudinal Analyses of SAST Tools: A CodeQL Case Study","ref_index":62,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S","json":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S.json","graph_json":"https://pith.science/api/pith-number/PJU67DCRHF7QD5C7XMXQG2PP5S/graph.json","events_json":"https://pith.science/api/pith-number/PJU67DCRHF7QD5C7XMXQG2PP5S/events.json","paper":"https://pith.science/paper/PJU67DCR"},"agent_actions":{"view_html":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S","download_json":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S.json","view_paper":"https://pith.science/paper/PJU67DCR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.16235&json=true","fetch_graph":"https://pith.science/api/pith-number/PJU67DCRHF7QD5C7XMXQG2PP5S/graph.json","fetch_events":"https://pith.science/api/pith-number/PJU67DCRHF7QD5C7XMXQG2PP5S/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S/action/storage_attestation","attest_author":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S/action/author_attestation","sign_citation":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S/action/citation_signature","submit_replication":"https://pith.science/pith/PJU67DCRHF7QD5C7XMXQG2PP5S/action/replication_record"}},"created_at":"2026-07-05T08:47:30.114542+00:00","updated_at":"2026-07-05T08:47:30.114542+00:00"}