Skip to content
Preprint

SEMA-GUARD: Semantic and Graph-Based Vulnerability Detection in Assembly Code

Sep 2026 · 0 citations · 10 references
Computer Science

TL;DR

This article presents SEMA-GUARD, a framework that uses semantic analysis and graph neural networks to identify flaws in assembly code, and results imply that including semantic information in graph-based models may be a successful method for identifying vulnerabilities in compiled code.

Abstract

In cases where source code is not available, such as malware analysis, firmware analysis, and embedded systems analysis, vulnerability detection in compiled programs has gained importance. Current methods are heavily reliant on syntactical regularities or higher level representations that are vulnerable to changes in the compiler and may not be readily applicable to assembly code.In this article, we present SEMA-GUARD, a framework that uses semantic analysis and graph neural networks to identify flaws in assembly code. The approach improves the representation of control flow graphs by adding information about the program's execution at a lower level of abstraction, including stack manipulations, memory accesses, and data flow. A set based on the Juliet Test Suite was used to evaluate the effectiveness of SEMA-GUARD. In this set, each piece of source code is initially translated into assembly language and then broken down into function-level chunks. The suggested method, which relies only on statistical or structural data, achieves an accuracy of 85.1\% and an F1 score of 0.801, according to the results. Such results imply that including semantic information in graph-based models may be a successful method for identifying vulnerabilities in compiled code.

View source

Similar papers

Sep 2026

FiCoVuL: A Framework for Fine-grained and Cross-function Code Vulnerability Detection

FiCoVuL is presented, a framework for analyzing interconnected functions and providing fine-grained guidance for vulnerability fixing that significantly outperforms other methods in both vulnerability detection and localization.

Hong-Jun Huang, Fu-Tai Zou, Jia-Ping Gui et al. · 0 citations
#small language model Preprint Sep 2026

Towards Behavior Tree-Guided Vulnerability Detection with Lightweight LLMs

Investigating Behavior Trees (BTs) as an alternative intermediate representation for LLM-based vulnerability detection suggests that BTs can provide a compact and useful structured representation for vulnerability detection with quantized, locally deployable LLMs.

Enna Bašić, A. Giaretta · 0 citations
Preprint Aug 2026

Finding Vulnerabilities via LLM-Augmented Semantics-Aware Type-Checking

SETYPE is presented, a semantics-aware type system that can be derived directly from source code based solely on the meanings of symbols and expressions in natural language that achieves 87% detection precision and 88% detection accuracy on real-world applications.

Ruizhe Wang, Meng Xu, N. Asokan · 0 citations
Open access Sep 2026

On-Premise CodeBERT-Driven Model for Vulnerability Detection in Source Code

An on premise Artificial Intelligence (AI)-based model for vulnerability detection in source code, designed to ensure there is efficiency in identifying potential weaknesses, and deployed locally within a Dockerized environment.

D. Sako · 0 citations
Aug 2026

SemASTer: Cross-Architecture Binary Code Similarity Detection via AST-Driven Semantic Compensation

SemASTer is proposed, a robust framework for cross-architecture binary code similarity detection that leverages Abstract Syntax Tree (AST) as its semantic backbone and introduces two complementary compensation pathways: behavioral semantic compensation to recover lost runtime dynamics, and control-flow compensation to...

Zhichao Wang, Xiao-Kang Yin, Xiaoya Zhu et al. · 0 citations
Review Open access Sep 2026

Program Graph Learning for Software Vulnerability Analysis: A Survey

Software vulnerabilities represent an enduring threat to modern cyberspace. Effective vulnerability detection increasingly relies on reasoning about complex program semantics, structural dependencies, and execution behaviors. Consequently, extracting vulnerability-relevant features from code efficiently has become a pr...

Jun-Jie Wang, Tong Yu, Ming Li et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.