Skip to content
Open access

Efficient Software Vulnerability Detection Using Edge-Conditioned Graph Neural Networks on Heterogeneous Code Property Graphs

Aug 2026 · Information · 0 citations · 33 references

TL;DR

The significance of this work lies in its demonstration that a compact, edge-aware architecture can match independently reproduced results of far larger models while remaining deployable in resource-constrained settings, such as continuous-integration pipelines and developer workstations.

Abstract

Software vulnerabilities are a primary cause of security breaches, and their automated detection at scale has therefore become a pressing concern for both industry and academia. Most Graph Neural Network (GNN) approaches to vulnerability detection treat code graphs as homogeneous structures, and the semantic distinctions between Abstract Syntax Tree (AST) edges, Control-Flow Graph (CFG) edges, and data-flow dependency edges are consequently discarded. The main objective of this study is to determine whether explicitly conditioning message passing on edge type yields accurate yet lightweight detection. To this end, an edge-conditioned GNN named FastVulnGNN is proposed, in which the message-passing computation is conditioned on edge-type information drawn from Code Property Graphs (CPGs). FastVulnGNN operates on Joern-produced CPGs that contain 33 node types and 21 edge types, so that the full heterogeneous graph structure is preserved. A multi-scale readout mechanism that combines mean, maximum, and learned attention pooling is employed for graph-level classification, and the training configuration, which combines focal loss, label smoothing, and cosine annealing warm restarts, is individually validated by an ablation of the training objective. On the MegaVul dataset of 1904 balanced C/C++ samples, an accuracy of 71.1%, an F1 score of 0.70, and an AUC-ROC of 0.77 are achieved with only 71,810 parameters. Training completes in under two minutes on a single CPU core, and no GPU resources are required. The significance of this work lies in its demonstration that a compact, edge-aware architecture can match independently reproduced results of far larger models while remaining deployable in resource-constrained settings, such as continuous-integration pipelines and developer workstations. This study is deliberately framed as a controlled and reproducible engineering and evaluation contribution rather than as an architectural advance. An edge-type ablation study, a cross-dataset evaluation, and a per-vulnerability analysis are additionally reported to characterize the behavior and limitations of the model.

Read PDF

Similar papers

Review Open access Sep 2026

Program Graph Learning for Software Vulnerability Analysis: A Survey

Software vulnerabilities represent an enduring threat to modern cyberspace. Effective vulnerability detection increasingly relies on reasoning about complex program semantics, structural dependencies, and execution behaviors. Consequently, extracting vulnerability-relevant features from code efficiently has become a pr...

Jun-Jie Wang, Tong Yu, Ming Li et al. · 0 citations
Open access Aug 2026

A Software Code Defect Detection Method Based on the Fusion of Transformer and Graph Neural Networks

Software defect detection plays a key role in improving system reliability, security, and maintainability. This study proposes a hybrid Transformer–GNN framework to jointly model code semantics and program structure. Source files are normalized, segmented at the function level, and converted into token sequences, while...

Z.-F. Wang, A.-X. Ding, C. Ma et al. · 0 citations
Preprint Sep 2026

SEMA-GUARD: Semantic and Graph-Based Vulnerability Detection in Assembly Code

This article presents SEMA-GUARD, a framework that uses semantic analysis and graph neural networks to identify flaws in assembly code, and results imply that including semantic information in graph-based models may be a successful method for identifying vulnerabilities in compiled code.

H. Dursunoglu, Kaan Sulkalar · 0 citations
#artificial intelligence Preprint Sep 2026

Temporal Generalization and Explanation Stability of Control Flow Graph Neural Networks for Malware Detection

Malware detection is a critical task in cybersecurity, and graph neural networks over control flow graphs have shown promising results for it. However, detectors are usually evaluated on a random split of a corpus collected over a single period, which cannot show how well a model generalizes to later samples. This stud...

M. Sajeed, Mayukh Mondal, Md. Ashraful Hossen Akash · 0 citations
Sep 2026

FiCoVuL: A Framework for Fine-grained and Cross-function Code Vulnerability Detection

FiCoVuL is presented, a framework for analyzing interconnected functions and providing fine-grained guidance for vulnerability fixing that significantly outperforms other methods in both vulnerability detection and localization.

Hong-Jun Huang, Fu-Tai Zou, Jia-Ping Gui et al. · 0 citations
Open access Sep 2026

SemVul: Semantic-enhanced graph neural networks for code property graph-based vulnerability detection

This study evaluated existing research approaches and proposed SemVul, a vulnerability detection pipeline that demonstrates better generalization and higher accuracy in learning vulnerable code patterns, and is generic with respect to the programming language and supports multiple architectures.

Younas Affan, L. Regano, G. Giacinto · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.