[PDF]

Attention-Based Sequence Models for Security Patch Detection Using Behavioural Data


William Godfrey

06/05/2026

Supervised by Neetesh Saxena; Moderated by Oktay Karakus

It is a common practice that once a vulnerability is detected and fixed, the developers behind the software issue a Common Vulnerabilities and Exposures or CVE record to alert the user community of the security hazard and urge them to integrate the security patch. However, some companies might not disclose their vulnerabilities and just update their repository. As a result, users are unaware of the vulnerability and may remain exposed. In this work, we aim to develop an approach for the system to automatically identify security patches using only the developer behaviour in the code repository without analysing the code itself.


Initial Plan (01/02/2026) [Zip Archive]

Final Report (06/05/2026) [Zip Archive]

Publication Form