VerDiff: Vulnerability Presence Verification for Comprehensive Reporting Using Constraint Programming
Published in 2025 IEEE Annual Computer Security Applications Conference (ACSAC), 2025
VerDiff introduces a novel signature-matching framework to accurately identify all software versions affected by a vulnerability, correcting 265 misclassifications in official advisories. Read more
Recommended citation: M. S. Anwar, C. Yagemann and Z. Lin, "VerDiff: Vulnerability Presence Verification for Comprehensive Reporting Using Constraint Programming," 2025 IEEE Annual Computer Security Applications Conference (ACSAC), Honolulu, HI, USA, 2025, pp. 77-91, doi: 10.1109/ACSAC67867.2025.00022.
Download Paper | Download Slides | View on GitHub | View on Docker Hub
