Page 119 - 《软件学报》2026年第7期
P. 119

2804                                                       软件学报  2026  年第  37  卷第  7  期


                      with program analysis. In: Proc. of the 47th IEEE/ACM Int’l Conf. on Software Engineering: Software Engineering in Practice. Ottawa:
                      IEEE, 2025. 203–214. [doi: 10.1109/ICSE-SEIP66354.2025.00024]
                 [150]   Raitsis  T,  Elgazari  Y,  Toibin  GE,  Lurie  Y,  Mark  S,  Margalit  O.  Code  obfuscation:  A  comprehensive  approach  to  detection,
                      classification, and ethical challenges. Algorithms, 2025, 18(2): 54. [doi: 10.3390/a18020054]
                 [151]   Mao  TY,  Wang  XY,  Chang  R,  Shen  WB,  Ren  K.  Software  supply  chain  analysis  techniques  for  Java  ecosystem.  Ruan  Jian  Xue
                      Bao/Journal of Software, 2023, 34(6): 2628–2640 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/6852.htm [doi:
                      10.13328/j.cnki.jos.006852]
                 [152]   Duan RA, Alrawi O, Kasturi RP, Elder R, Saltaformaggio B, Lee W. Towards measuring supply chain attacks on package managers for
                      interpreted languages. In: Proc. of the 28th Annual Network and Distributed System Security Symp. The Internet Society, 2021.
                 [153]   Fass A, Krawczyk RP, Backes M, Stock B. JaSt: Fully syntactic detection of malicious (obfuscated) JavaScript. In: Proc. of the 15th Int’l
                      Conf. Detection of Intrusions and Malware, and Vulnerability Assessment. Saclay: Springer, 2018. 303–325. [doi: 10.1007/978-3-319-
                      93411-2_14]
                 [154]   He  XC,  Xu  L,  Cha  CL.  Malicious  JavaScript  code  detection  based  on  hybrid  analysis.  In:  Proc.  of  the  25th  Asia-Pacific  Software
                      Engineering Conf. Nara: IEEE, 2018. 365–374. [doi: 10.1109/APSEC.2018.00051]
                 [155]   Alibaba Group AI Governance Initiative. White paper on generative ai governance: Robustness, interpretability, and misuse prevention.
                      2025 (in Chinese). https://s.alibaba.com/cn/aaigWhitePaperDetails/9x5JBSX2fyLEZWkRnKQ8f
                 [156]   National Institute of Standards and Technology. AI risk management framework. 2025. https://www.nist.gov/itl/ai-risk-management-
                      framework
                 [157]   OWASP  Foundation.  LLM04:  2025  data  and  model  poisoning.  2025.  https://genai.owasp.org/llmrisk/llm042025-data-and-model-
                      poisoning/
                 [158]   Ishibashi Y, Shimodaira H. Knowledge sanitization of large language models. arXiv:2309.11852, 2023.
                 [159]   Yu L, Do V, Hambardzumyan K, Cancedda N. Robust LLM safeguarding via refusal feature adversarial training. In: Proc. of the 13th
                      Int’l Conf. on Learning Representations. 2025.
                 [160]   Zhao S, Wu XB, Nguyen CD, Jia YH, Jia MHZ, Feng YC, Tuan LA. Unlearning backdoor attacks for LLMs with weak-to-strong
                      knowledge distillation. In: Findings of the Association for Computational Linguistics: ACL 2025. Vienna: ACL, 2025. 4937–4952. [doi:
                      10.18653/v1/2025.findings-acl.255]
                 [161]   Zeng  SL,  He  PF,  Guo  K,  Zheng  TQ,  Lu  HQ,  Xing  Y,  Liu  H.  Towards  context-robust  LLMs:  A  gated  representation  fine-tuning
                      approach. In: Proc. of the 63rd Annual Meeting of the Association for Computational Linguistics. Vienna: ACL, 2025. 10262–10276.
                      [doi: 10.18653/v1/2025.acl-long.506]
                 [162]   Agrawal A, Alazraki L, Honarvar S, Rei M. Enhancing LLM robustness to perturbed instructions: An empirical study. arXiv:2504.
                      02733, 2025.
                 [163]   Dai QM, Mao RF, Huang H, Rong GP, Shen HF, Shao D. DevSecOps: Exploring practices of realizing continuous security in DevOps.
                      Ruan Jian Xue Bao/Journal of Software, 2021, 32(10): 3014–3035 (in Chinese with English abstract). http://www.jos.org.cn/1000-9825/
                      6276.htm [doi: 10.13328/j.cnki.jos.006276]
                 [164]   Carter K. Francois raynaud on DevSecOps. IEEE Software, 2017, 34(5): 93–96. [doi: 10.1109/MS.2017.3571578]
                 [165]   Kumar R, Goyal R. Modeling continuous security: A conceptual model for automated DevSecOps using open-source software over
                      cloud (ADOC). Computers & Security, 2020, 97: 101967. [doi: 10.1016/j.cose.2020.101967]
                 [166]   Tomas N, Li JY, Huang H. An empirical study on culture, automation, measurement, and sharing of DevSeCops. In: Proc. of the 2019
                      Int’l  Conf.  on  Cyber  Security  and  Protection  of  Digital  Services.  Oxford:  IEEE,  2019.  1–8.  [doi: 10.1109/CyberSecPODS.2019.
                      8884935]
                 [167]   Haverinen H, Janhunen T, Päivärinta T, Lempinen S, Kaartinen S, Merilä S. Automating cybersecurity compliance in DevSecOps with
                      open information model for security as code. In: Proc. of the 4th Eclipse Security, AI, Architecture and Modelling Conf. on Data Space.
                      Mainz: ACM, 2024. 93–102. [doi: 10.1145/3685651.3686700]
                 [168]   Rindell  K,  Ruohonen  J,  Holvitie  J,  Hyrynsalmi  S,  Leppänen  V.  Security  in  agile  software  development:  A  practitioner  survey.
                      Information and Software Technology, 2021, 131: 106488. [doi: 10.1016/j.infsof.2020.106488]
                 [169]   Janisar AA, bin Kalid KS, Bt Sarlana A, Maiwada UD. Software development teams knowledge and awareness of security requirement
                      engineering and security requirement elicitation and analysis. Procedia Computer Science, 2024, 234: 1348–1355. [doi: 10.1016/j.procs.
                      2024.03.133]
                 [170]   Muñante D, Chiprianov V, Gallon L, Aniorté P. A review of security requirements engineering methods with respect to risk analysis and
                      model-driven engineering. In: Proc. of the 2014 IFIP WG 8.4, 8.9, TC 5 Int’l Cross-domain Conf. (CD-ARES 2014) and the 4th Int’l
   114   115   116   117   118   119   120   121   122   123   124