{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:09:01Z","timestamp":1782846541345,"version":"3.54.5"},"reference-count":80,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Zhongguancun Laboratory","award":["None"],"award-info":[{"award-number":["None"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Programmable Logic Controllers (PLCs) lack built-in security mechanisms, and their critical role in industrial control systems makes them prime targets for cyberattacks. Next-generation PLCs increasingly adopt embedded virtualization to partition functional domains and to integrate industrial control with advanced workloads on unified hardware. Nevertheless, many PLC vendors and researchers have largely overlooked the potential of virtualization to strengthen PLC security.<\/jats:p>\n                  <jats:p>To address this gap, we propose TriHaven, an embedded virtualization-based security architecture for PLCs. TriHaven separates the PLC control loop and deploys its components in dedicated virtual machines, each with distinct design characteristics. By further implementing a redundancy-compare strategy for PLC control logic execution, TriHaven enables real-time attack detection and rapid emergency response through control switching, thereby mitigating diverse and previously unknown threats. Integrating virtualization with PLC redundancy introduces new challenges: security-preserving multi-VM scan-cycle design under real-time constraints, low-latency integrity-safe cross-domain I\/O exchange, and secure synchronization of a network-isolated standby PLC, solving a consistency problem absent in prior redundancy designs.<\/jats:p>\n                  <jats:p>Using the Jailhouse virtualization, experiments on OpenPLC and Beremiz--two open-source PLC runtimes--demonstrate the feasibility of TriHaven while preserving essential security objectives, under the standard assumption that the PLC hardware and its underlying hypervisor remain physically protected and trustworthy.<\/jats:p>","DOI":"10.1145\/3808155","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"3344-3367","source":"Crossref","is-referenced-by-count":0,"title":["A Wily Hare Has Three Havens: Combating Programmable Logic Controller Attacks via Virtualization Redundancy"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0002-0845-5790","authenticated-orcid":false,"given":"Wenjie","family":"Wang","sequence":"first","affiliation":[{"name":"Zhongguancun Laboratory, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0001-8887-8752","authenticated-orcid":false,"given":"Yazhe","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhongguancun Laboratory, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0008-4002-4134","authenticated-orcid":false,"given":"Lei","family":"Ren","sequence":"additional","affiliation":[{"name":"Zhongguancun Laboratory, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","first-page":"1","article-title":"Ghost in the PLC: Designing an Undetectable Programmable Logic Controller Rootkit via Pin Control Attack. In Black Hat Europe 2016","author":"Abbasi Ali","year":"2016","unstructured":"Ali Abbasi and Majid Hashemi. 2016. Ghost in the PLC: Designing an Undetectable Programmable Logic Controller Rootkit via Pin Control Attack. In Black Hat Europe 2016. Black Hat, 1-35.","journal-title":"Black Hat"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134618"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453102"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/GHTC.2014.6970342"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCST.2005.847331"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOST55118.2023.10132957"},{"key":"e_1_2_1_7_1","unstructured":"BECKHOFF. 2022. TwinCAT\/BSD Hypervisor. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www.beckhoff.com\/en-gb\/products\/auto mation\/twincat-bsd-hypervisor\/."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/VTS48691.2020.9107609"},{"key":"e_1_2_1_9_1","first-page":"723","article-title":"Exploiting Siemens Simatic S7 PLCs","volume":"16","author":"Beresford Dillon","year":"2011","unstructured":"Dillon Beresford. 2011. Exploiting Siemens Simatic S7 PLCs. Black Hat USA 16, 2 (2011), 723-733.","journal-title":"Black Hat USA"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the Twelfth Australasian Information Security Conference (AISC 2014)","volume":"65","author":"Bhatia Sajal","year":"2014","unstructured":"Sajal Bhatia, Nishchal Singh Kush, Chris Djamaludin, Ayodeji James Akande, and Ernest Foo. 2014. Practical Modbus Flooding Attack and Detection. In Proceedings of the Twelfth Australasian Information Security Conference (AISC 2014) (Conferences in Research and Practice in Information Technology, Vol. 149). Australian Computer Society, Auckland, New Zealand, 57-65. https:\/\/2.zoppoz.workers.dev:443\/https\/sacredheart.elsevierpure.com\/en\/publications\/practical-modbus-flooding-attack-anddetection"},{"key":"e_1_2_1_11_1","volume-title":"Black Hat USA 2019","author":"Biham Eli","year":"2019","unstructured":"Eli Biham, Sara Bitan, Aviad Carmel, Alon Dankner, Uriel Malin, and Avishai Wool. 2019. Rogue7: Rogue Engineeringstation Attacks on S7 Simatic PLCs. Black Hat USA 2019 (2019)."},{"key":"e_1_2_1_12_1","doi-asserted-by":"crossref","unstructured":"William Bolton. 2015. Programmable Logic Controllers. Newnes.","DOI":"10.1016\/B978-0-12-802929-9.00001-7"},{"key":"e_1_2_1_13_1","unstructured":"B&R Automation. 2018. Two Operating Systems on One Device. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www.br-automation.c om\/en\/about-us\/customer-magazine\/2018\/20189\/two-operating-systems-on-one-device\/."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485531"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607226"},{"key":"e_1_2_1_16_1","first-page":"1","article-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","volume":"388","author":"Case Defense Use","year":"2016","unstructured":"Defense Use Case. 2016. Analysis of the Cyber Attack on the Ukrainian Power Grid. Electricity Information Sharing and Analysis Center (E-ISAC) 388, 1-29 (2016), 3.","journal-title":"Electricity Information Sharing and Analysis Center (E-ISAC)"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2021.12.002"},{"key":"e_1_2_1_18_1","unstructured":"MITRE Corporation. 2021. CVE-2021-37204. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=2 021-37204."},{"key":"e_1_2_1_19_1","volume-title":"15th USENIX Security Symposium (USENIX Security 06)","author":"Cox Benjamin","year":"2006","unstructured":"Benjamin Cox, David Evans, Adrian Filipi, Jonathan Rowanhill, Wei Hu, Jack Davidson, John Knight, Anh Nguyen- Tuong, and Jason Hiser. 2006. N-Variant Systems: A Secretless Framework for Security through Diversity. In 15th USENIX Security Symposium (USENIX Security 06). USENIX Association, Vancouver, B.C. Canada. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usen ix.org\/conference\/15th-usenix-security-symposium\/n-variant-systems-secretless-framework-security-through"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA"},{"key":"e_1_2_1_21_1","first-page":"1","volume-title":"Proc. Black Hat USA 2018","author":"Pinto Alessandro Di","year":"2018","unstructured":"Alessandro Di Pinto, Younes Dragoni, and Andrea Carcano. 2018. TRITON: the First ICS Cyber Attack on Safety Instrument Systems. Proc. Black Hat USA 2018 (2018), 1-26."},{"key":"e_1_2_1_22_1","volume-title":"PIPEDREAM: Chernovite's Emerging Malware Targeting Industrial Control Systems. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/hub.dragos.com\/whitepaper\/chernovite-pipedream.","year":"2022","unstructured":"Dragos. 2022. PIPEDREAM: Chernovite's Emerging Malware Targeting Industrial Control Systems. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/hub.dragos.com\/whitepaper\/chernovite-pipedream."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1080\/00396338.2011.555586"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.34"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23313"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/RWEEK.2016.7573309"},{"key":"e_1_2_1_27_1","first-page":"58","volume-title":"9th International Conference on Cyber Warfare and Security","author":"Grandgenett Ryan","year":"2014","unstructured":"Ryan Grandgenett, Robin Gandhi, and William Mahoney. 2014. Exploitation of Allen Bradley's Implementation of EtherNet\/IP for Denial of Service against Industrial Control Systems. In 9th International Conference on Cyber Warfare and Security 2014. 58-65."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106"},{"key":"e_1_2_1_29_1","unstructured":"Vibhoosh Gupta. 2019. Virtualization for The Plant Floor. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www.emerson.com\/document s\/automation\/article-virtualization-for-plant-floor-emerson-en-6321138.pdf."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2"},{"key":"e_1_2_1_31_1","unstructured":"ICS-CERT. 2012. ABB AC500 PLC Webserver CoDeSys Vulnerability. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www.cisa.gov\/newsevents\/ics-advisories\/icsa-12-320-01."},{"key":"e_1_2_1_32_1","unstructured":"ICS-CERT. 2012. Schneider Electric Modicon Quantum Vulnerabilities (Update B). [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www. cisa.gov\/news-events\/ics-alerts\/ics-alert-12-020-03b."},{"key":"e_1_2_1_33_1","unstructured":"ICS-CERT. 2015. Schneider Electric Modicon M340 Buffer Overflow Vulnerability. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www. cisa.gov\/news-events\/ics-advisories\/icsa-15-351-01."},{"key":"e_1_2_1_34_1","unstructured":"ICS-CERT. 2016. Rockwell Automation MicroLogix 1100 PLC Overflow Vulnerability. [Online]. Available: https: \/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-16-026-02."},{"key":"e_1_2_1_35_1","unstructured":"Intel. 2023. A Quick Guide to Building A New Generation of Smart Industrial Controllers. [Online]. Available: https: \/\/www.intel.cn\/content\/www\/cn\/zh\/internet-of-things\/next-gen-industrial-controllers-guide.html."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-020-00529-0"},{"key":"e_1_2_1_37_1","unstructured":"Tal Keren. 2021. The Race to Native Code Execution in PLCs. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/claroty.com\/team82\/resea rch\/the-race-to-native-code-execution-in-plcs."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCNT49239.2020.9225382"},{"key":"e_1_2_1_39_1","unstructured":"Eduard Kovacs. 2014. OpenVPN Vulnerable to ShellShock Attacks: Researcher. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/www.se curityweek.com\/openvpn-vulnerable-shellshock-attacks-researcher\/."},{"key":"e_1_2_1_40_1","unstructured":"Ravie Lakshmanan. 2023. 16 New CODESYS SDK Flaws Expose OT Environments to Remote Attacks. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/thehackernews.com\/2023\/08\/15-new-codesys-sdk-flaws-expose-ot.html."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.25"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3440943.3444742"},{"key":"e_1_2_1_43_1","volume-title":"Zero Things Cool about A Threat Group Targeting the Power Grid. Black Hat USA","author":"Lee Robert","year":"2017","unstructured":"Robert Lee, Joe Slowik, Ben Miller, Anton Cherepanov, and Robert Lipovsky. 2017. Industroyer\/Crashoverride: Zero Things Cool about A Threat Group Targeting the Power Grid. Black Hat USA (2017)."},{"key":"e_1_2_1_44_1","first-page":"1","article-title":"German Steel Mill Cyber Attack","volume":"30","author":"Lee Robert M","year":"2014","unstructured":"Robert M Lee, Michael J Assante, and Tim Conway. 2014. German Steel Mill Cyber Attack. Industrial Control Systems 30, 62 (2014), 1-15.","journal-title":"Industrial Control Systems"},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/IISR.2018.8535915"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/36"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00044"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3046267"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11390-021-1647-7"},{"key":"e_1_2_1_50_1","first-page":"7103","volume-title":"SoK: Security of Programmable Logic Controllers. In 33rd USENIX Security Symposium (USENIX Security 24)","author":"L\u00f3pez-Morales Efr\u00e9n","year":"2024","unstructured":"Efr\u00e9n L\u00f3pez-Morales, Ulysse Planta, Carlos Rubio-Medrano, Ali Abbasi, and Alvaro A Cardenas. 2024. SoK: Security of Programmable Logic Controllers. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, USA, 7103-7122. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/lopezmorales"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/LES.2020.3011309"},{"key":"e_1_2_1_52_1","unstructured":"Robin Maisch Nils Niehues Timur Sa\u011flam Sebastian Hahner Alexander Vogt Alexander Milster Dominik Fuch\u00df Tobias Hey and Larissa Schmid. 2015. JPlag -Detecting Source Code Plagiarism. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/github .com\/jplag\/JPlag\/."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23043"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35764-0_5"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627106.3627179"},{"key":"e_1_2_1_56_1","volume-title":"12th USENIX Workshop on Offensive Technologies (WOOT 18)","author":"Niedermaier Matthias","year":"2018","unstructured":"Matthias Niedermaier, Jan-Ole Malchow, Florian Fischer, Daniel Marzin, Dominik Merli, Volker Roth, and Alexander Von Bodisco. 2018. You Snooze, You Lose: Measuring PLC Cycle Times under Attacks. In 12th USENIX Workshop on Offensive Technologies (WOOT 18). USENIX Association, Baltimore, MD. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/woot 18\/presentation\/niedermaier"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA52439.2022.9921545"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23049"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2023.01.013"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-93511-"},{"key":"e_1_2_1_61_1","first-page":"6861","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Narayan Rajput Prashant Hari","year":"2023","unstructured":"Prashant Hari Narayan Rajput, Constantine Doumanidis, and Michail Maniatakos. 2023. ICSPatch: Automated Vulnerability Localization and Non-Intrusive Hotpatching in Industrial Control Systems using Data Dependence Graphs. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 6861-6876. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/rajput"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.13140\/RG.2.2.32"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/1400097.1400108"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3040237"},{"key":"e_1_2_1_65_1","unstructured":"siemens. 2017. Be Open and Independent: SIMATIC S7-1500 Software Controller. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/assets .new.siemens.com\/siemens\/assets\/api\/uuid:f088231a33215e94cb4a9a0f39cd56dadfa765b0\/dffa-b10006-03-7600-wssimatic-s7-1500-software-controller-en.pdf."},{"key":"e_1_2_1_66_1","unstructured":"siemens. 2022. Questions and Answers about the Security Features as of TIA Portal V17. [Online]. Available: https: \/\/support.industry.siemens.com\/cs\/document\/109799540\/questions-and-answers-about-the-security-features-as-oftia-portal-v17?dti=0&lc=en-WW."},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.5555\/2775334.2775336"},{"key":"e_1_2_1_68_1","first-page":"1","article-title":"PLC-Blaster: A Worm Living Solely in the PLC","volume":"16","author":"Spenneberg Ralf","year":"2016","unstructured":"Ralf Spenneberg, Maik Br\u00fcggemann, and Hendrik Schwartke. 2016. PLC-Blaster: A Worm Living Solely in the PLC. Black Hat Asia 16 (2016), 1-16.","journal-title":"Black Hat Asia"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/TASE"},{"key":"e_1_2_1_70_1","unstructured":"Team82. 2024. Unpacking the Blackjack Group's Fuxnet Malware. [Online]. Available: https:\/\/2.zoppoz.workers.dev:443\/https\/claroty.com\/team82\/r esearch\/unpacking-the-blackjack-groups-fuxnet-malware."},{"key":"e_1_2_1_71_1","first-page":"2847","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Tychalas Dimitrios","year":"2021","unstructured":"Dimitrios Tychalas, Hadjer Benkraouda, and Michail Maniatakos. 2021. ICSFuzz: Manipulating I\/Os and Repurposing Binary Code to Enable Instrumented Fuzzing in ICS Control Applications. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2847-2862. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity21\/prese ntation\/tychalas"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.23919\/DATE48585.2020.9116365"},{"key":"e_1_2_1_73_1","unstructured":"IEC TC57 WG15. 2016. IEC 62351 Security Standards for the Power System Information Infrastructure. Technical Report. Technical report International Electrotechnical Commission."},{"key":"e_1_2_1_74_1","unstructured":"R WIGHTMAN and D PETERSON. 2013. Project Basecamp 3S CoDeSys Vulns and Tools. [Online]. Available: https: \/\/web.archive.org\/web\/20130806010310\/http:\/www.digitalbond.com\/tools\/basecamp\/3s-codesys\/."},{"key":"e_1_2_1_75_1","first-page":"333","volume-title":"PLC-Sleuth: Detecting and Localizing PLC Intrusions Using Control Invariants. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Yang Zeyu","year":"2020","unstructured":"Zeyu Yang, Liang He, Peng Cheng, Jiming Chen, David KY Yau, and Linkang Du. 2020. PLC-Sleuth: Detecting and Localizing PLC Intrusions Using Control Invariants. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). USENIX Association, San Sebastian, 333-348. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/raid20 20\/presentation\/yang"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678896"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22312-0_3"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00034"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.promfg.2020.01.334"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627703.3650068"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808155","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:20:16Z","timestamp":1782843616000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3808155"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":80,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808155"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3808155","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}