{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:R5PPBHYIOSJR5EPI5RBP64GLGH","short_pith_number":"pith:R5PPBHYI","schema_version":"1.0","canonical_sha256":"8f5ef09f0874931e91e8ec42ff70cb31fc71efd11440b2fab473b25639185238","source":{"kind":"arxiv","id":"2606.28403","version":1},"attestation_state":"computed","paper":{"title":"Reinforcement Learning for Software Vulnerability Analysis: A Systematic Review with Emphasis on C/C++ Source Code and Static Analysis","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.LG"],"primary_cat":"cs.SE","authors_text":"Bruno Caro-V\\'asquez, Carola Figueroa-Flores, Gast\\'on Marquez","submitted_at":"2026-06-24T13:09:42Z","abstract_excerpt":"Vulnerability detection in C/C++ software remains a major security challenge due to code complexity, manual memory management, and the limitations of traditional static analysis. Reinforcement Learning (RL) has emerged as a promising approach, particularly for fuzzing, test generation, program exploration, and, more recently, vulnerability detection and localization. Following PRISMA 2020 guidelines, this work reviews RL techniques for software vulnerability analysis, focusing on C/C++ source code and static analysis. We identified 21 primary studies published between 2015 and 2026 from major "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.28403","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-06-24T13:09:42Z","cross_cats_sorted":["cs.AI","cs.CR","cs.LG"],"title_canon_sha256":"36872749cf44a4d344da49c19a4ad58234cbf8cba56300e5c0d25419ffc5be30","abstract_canon_sha256":"83b27f96de0dda77f469d208ad49abd1e2b96fc62161e443e755674e67f916b3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T00:15:13.131476Z","signature_b64":"LGAEJeiVtLLsevkHTn0B8CDu6fGwJyabUbtpws2KpKLUjfzxXU8eMM1V4dErBINIo0s27ESEayuMVs7lqO4qBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8f5ef09f0874931e91e8ec42ff70cb31fc71efd11440b2fab473b25639185238","last_reissued_at":"2026-06-30T00:15:13.130292Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T00:15:13.130292Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Reinforcement Learning for Software Vulnerability Analysis: A Systematic Review with Emphasis on C/C++ Source Code and Static Analysis","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.LG"],"primary_cat":"cs.SE","authors_text":"Bruno Caro-V\\'asquez, Carola Figueroa-Flores, Gast\\'on Marquez","submitted_at":"2026-06-24T13:09:42Z","abstract_excerpt":"Vulnerability detection in C/C++ software remains a major security challenge due to code complexity, manual memory management, and the limitations of traditional static analysis. Reinforcement Learning (RL) has emerged as a promising approach, particularly for fuzzing, test generation, program exploration, and, more recently, vulnerability detection and localization. Following PRISMA 2020 guidelines, this work reviews RL techniques for software vulnerability analysis, focusing on C/C++ source code and static analysis. We identified 21 primary studies published between 2015 and 2026 from major "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.28403","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.28403/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.28403","created_at":"2026-06-30T00:15:13.130873+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.28403v1","created_at":"2026-06-30T00:15:13.130873+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.28403","created_at":"2026-06-30T00:15:13.130873+00:00"},{"alias_kind":"pith_short_12","alias_value":"R5PPBHYIOSJR","created_at":"2026-06-30T00:15:13.130873+00:00"},{"alias_kind":"pith_short_16","alias_value":"R5PPBHYIOSJR5EPI","created_at":"2026-06-30T00:15:13.130873+00:00"},{"alias_kind":"pith_short_8","alias_value":"R5PPBHYI","created_at":"2026-06-30T00:15:13.130873+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH","json":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH.json","graph_json":"https://pith.science/api/pith-number/R5PPBHYIOSJR5EPI5RBP64GLGH/graph.json","events_json":"https://pith.science/api/pith-number/R5PPBHYIOSJR5EPI5RBP64GLGH/events.json","paper":"https://pith.science/paper/R5PPBHYI"},"agent_actions":{"view_html":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH","download_json":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH.json","view_paper":"https://pith.science/paper/R5PPBHYI","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.28403&json=true","fetch_graph":"https://pith.science/api/pith-number/R5PPBHYIOSJR5EPI5RBP64GLGH/graph.json","fetch_events":"https://pith.science/api/pith-number/R5PPBHYIOSJR5EPI5RBP64GLGH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH/action/storage_attestation","attest_author":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH/action/author_attestation","sign_citation":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH/action/citation_signature","submit_replication":"https://pith.science/pith/R5PPBHYIOSJR5EPI5RBP64GLGH/action/replication_record"}},"created_at":"2026-06-30T00:15:13.130873+00:00","updated_at":"2026-06-30T00:15:13.130873+00:00"}