Who Cited It

Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-Equivalent APIs in Open-Source Repositories

2025 · Leibniz international proceedings in informatics · 16,314 citations · 17 from inside this corpus

No author records on this work.

Functionality-specific vulnerabilities, which mainly occur in Application Programming Interfaces (APIs) with specific functionalities, are crucial for software developers to detect and avoid. When detecting individual functionality-specific vulnerabilities, the existing two categories of approaches are ineffective because they consider only the API bodies and are unable to handle diverse implementations of functionality-equivalent APIs. To effectively detect functionality-specific vulnerabilities, we propose APISS, the first approach to utilize API doc strings and signatures instead of API bodies. APISS first retrieves functionality-equivalent APIs for APIs with existing vulnerabilities and then migrates Proof-of-Concepts (PoCs) of the existing vulnerabilities for newly detected vulnerable APIs. To retrieve functionality-equivalent APIs, we leverage a Large Language Model for API embedding to improve the accuracy and address the effectiveness and scalability issues suffered by the existing approaches. To migrate PoCs of the existing vulnerabilities for newly detected vulnerable APIs, we design a semi-automatic schema to substantially reduce manual costs. We conduct a comprehensive evaluation to empirically compare APISS with four state-of-the-art approaches of detecting vulnerabilities and two state-of-the-art approaches of retrieving functionality-equivalent APIs. The evaluation subjects include 180 widely used Java repositories using 10 existing vulnerabilities, along with their PoCs. The results show that APISS effectively retrieves functionality-equivalent APIs, achieving a Top-1 Accuracy of 0.81 while the best of the baselines under comparison achieves only 0.55. APISS is highly efficient: the manual costs are within 10 minutes per vulnerability and the end-to-end runtime overhead of testing one candidate API is less than 2 hours. APISS detects 179 new vulnerabilities and receives 60 new CVE IDs, bringing high value to security practice.

Detecting Functionality-Specific Vulnerabilities via Retrieving Individual Functionality-… (2025)Detecting Functionality-Speci…Graph neural networks: A review of methods and applications (2020)Graph neural networks: A revi…A Comprehensive Survey on Graph Neural Networks (2020)A Comprehensive Survey on Gra…Graph WaveNet for Deep Spatial-Temporal Graph Modeling (2019)Graph WaveNet for Deep Spatia…A Survey on Knowledge Graphs: Representation, Acquisition, and Applications (2021)A Survey on Knowledge Graphs:…Deeper Insights Into Graph Convolutional Networks for Semi-Supervised Learning (2018)Deeper Insights Into Graph Co…Convolutional 2D Knowledge Graph Embeddings (2018)Convolutional 2D Knowledge Gr…A Comprehensive Survey of Graph Embedding: Problems, Techniques, and Applications (2018)A Comprehensive Survey of Gra…Graph Convolutional Networks for Text Classification (2019)Graph Convolutional Networks …Graph embedding techniques, applications, and performance: A survey (2018)Graph embedding techniques, a…Knowledge Graphs (2021)Hypergraph Neural Networks (2019)Hypergraph Neural NetworksA survey on deep learning and its applications (2021)A survey on deep learning and…Pre-trained models for natural language processing: A survey (2020)Pre-trained models for natura…An End-to-End Deep Learning Architecture for Graph Classification (2018)An End-to-End Deep Learning A…Graph Neural Networks: A Review of Methods and Applications (2018)Graph Neural Networks: A Revi…Explaining Deep Neural Networks and Beyond: A Review of Methods and Applications (2021)Explaining Deep Neural Networ…DeepGCNs: Can GCNs Go As Deep As CNNs? (2019)DeepGCNs: Can GCNs Go As Deep…
17 of 17 neighbouring works in this corpus. Blue is what this paper cites; orange is what cites it, and a dashed line is one neighbour citing another. Only the largest labels are drawn — every node carries its full title on hover.
this paper works it cites works citing it node size = global citations · hover for the full title

What cites it, inside the corpus

Topics

Advanced Graph Neural NetworksComputer Science
Domain Adaptation and Few-Shot LearningComputer Science
Machine Learning and ELMComputer Science

Is this record sound?

suspect

Several fields of this record are missing or contradict each other. Treat its figures with suspicion — it is shown unaltered because correcting a source's record silently is worse than showing you the problem.

  • weakensThe source lists no authors for this work at all, so there is nobody to attribute it to and it appears on no author page.
  • weakensNo references are recorded despite 16,314 citations. A paper this heavily cited did not cite nothing, so the record is incomplete.
  • supportsThe DOI's year agrees with the publication year.
  • supportsA title is present.

Provenance

Everything above was read from one stored OpenAlex payload, fetched 2026-09-04T03:58:40+00:00.

sha256 7e3d99a592f7f61f…