Skip to content
Open access

SGRL: A Hybrid Semantic-Graph Representation Learning Framework for Software Vulnerability Detection

2026 · International Journal of Advanced Computer Science and Applications · 0 citations · 53 references

Abstract

The increasing scale and complexity of software increase the risk of security vulnerabilities, creating a need for automated and effective detection methods. Transformer-based methods can learn semantic representations but do not fully exploit structural information, whereas graph neural network-based methods remain limited in representing token-level semantics. In addition, data imbalance affects models’ learning and generalization capabilities. In this study, the author proposes SGRL (Semantic–Graph Representation Learning), a framework that combines CodeT5 and a Graph Convolutional Network (GCN) over a Code Property Graph (CPG) to jointly exploit the semantic and structural features of source code. The two feature sources are fused through concatenation and adjusted using BDC (Bernoulli Dropout in CNN) before classification by a Multi-Layer Perceptron (MLP). Experiments on the Verum dataset with the optimal configuration of a 512-token input length and a BDC probability of 0.2 achieve an Accuracy of 84.23%, Precision of 84.55%, Recall of 84.23%, and F1-score of 84.14%. Results on Verum and FFmpeg+Qume also show that SGRL outperforms REVEAL, Russell, VulDeePecker, SySeVR, and Devign under the corresponding experimental settings.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.