Sep 2026· Journal of Systems and Software· Vol 243, pp. 113104· 0 citations· 56 references
Computer Science
TL;DR
This study evaluated existing research approaches and proposed SemVul, a vulnerability detection pipeline that demonstrates better generalization and higher accuracy in learning vulnerable code patterns, and is generic with respect to the programming language and supports multiple architectures.
Abstract
Vulnerabilities in source code are often the root cause of cyberattacks worldwide, as attackers exploit weaknesses in software to gain unauthorized access, steal data, or disrupt services. In this study, we evaluated existing research approaches and propose SemVul, a vulnerability detection pipeline that demonstrates better generalization and higher accuracy in learning vulnerable code patterns. We propose a Code Property Graph-based vulnerability-detection approach combined with semantic-level enhancement, enabling the model to capture both the program's structural flow and the semantic meaning of the code. Our approach integrates both node-level and edge-level semantic embeddings using pre-trained code embedding techniques. We systematically evaluate multiple GNN architectures on publicly available benchmark datasets. SemVul is generic with respect to the programming language and supports multiple architectures. By integrating structural and semantic information, the proposed approach improves vulnerability detection performance. Our results show that SemVul outperforms existing approaches and provides better generalization.
The increasing scale and complexity of software increase the risk of security vulnerabilities, creating a need for automated and effective detection methods. Transformer-based methods can learn semantic representations but do not fully exploit structural information, whereas graph neural network-based methods remain li...
Cong Bui Van· International Journal of Adv...· 0 citations
Software vulnerabilities represent an enduring threat to modern cyberspace. Effective vulnerability detection increasingly relies on reasoning about complex program semantics, structural dependencies, and execution behaviors. Consequently, extracting vulnerability-relevant features from code efficiently has become a pr...
Jun-Jie Wang, Tong Yu, Ming Li et al.· Transactions on Graph Intell...· 0 citations
HSF-Vul is proposed, a novel approach for software vulnerability detection and localization based on hierarchical semantic fusion that frame vulnerability detection as a binary classification task and extend it to line-level localization by analyzing the contribution of individual code lines.
Hong-Tao Wang, Xin Yang, Xiao-Feng Liu et al.· International Conference on...· 0 citations
FiCoVuL is presented, a framework for analyzing interconnected functions and providing fine-grained guidance for vulnerability fixing that significantly outperforms other methods in both vulnerability detection and localization.
Hong-Jun Huang, Fu-Tai Zou, Jia-Ping Gui et al.· ACM Transactions on Software...· 0 citations
The proliferation of AI models from open-source platforms has introduced significant security risks, as these models may contain hidden vulnerabilities that compromise application security. Existing static analysis tools rely on fixed rule sets that fail to generalise to novel AI-specific threat patterns, while LLM-bas...
Ikeagwuchi E. Ekeke, Amit Kumar Singh, Xiao-Hang Wang· Coins· 0 citations
The significance of this work lies in its demonstration that a compact, edge-aware architecture can match independently reproduced results of far larger models while remaining deployable in resource-constrained settings, such as continuous-integration pipelines and developer workstations.
A. Elalfy, G. Ebrahim, M. B. Mansour· Information· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.