The significance of this work lies in its demonstration that a compact, edge-aware architecture can match independently reproduced results of far larger models while remaining deployable in resource-constrained settings, such as continuous-integration pipelines and developer workstations.
Abstract
Software vulnerabilities are a primary cause of security breaches, and their automated detection at scale has therefore become a pressing concern for both industry and academia. Most Graph Neural Network (GNN) approaches to vulnerability detection treat code graphs as homogeneous structures, and the semantic distinctions between Abstract Syntax Tree (AST) edges, Control-Flow Graph (CFG) edges, and data-flow dependency edges are consequently discarded. The main objective of this study is to determine whether explicitly conditioning message passing on edge type yields accurate yet lightweight detection. To this end, an edge-conditioned GNN named FastVulnGNN is proposed, in which the message-passing computation is conditioned on edge-type information drawn from Code Property Graphs (CPGs). FastVulnGNN operates on Joern-produced CPGs that contain 33 node types and 21 edge types, so that the full heterogeneous graph structure is preserved. A multi-scale readout mechanism that combines mean, maximum, and learned attention pooling is employed for graph-level classification, and the training configuration, which combines focal loss, label smoothing, and cosine annealing warm restarts, is individually validated by an ablation of the training objective. On the MegaVul dataset of 1904 balanced C/C++ samples, an accuracy of 71.1%, an F1 score of 0.70, and an AUC-ROC of 0.77 are achieved with only 71,810 parameters. Training completes in under two minutes on a single CPU core, and no GPU resources are required. The significance of this work lies in its demonstration that a compact, edge-aware architecture can match independently reproduced results of far larger models while remaining deployable in resource-constrained settings, such as continuous-integration pipelines and developer workstations. This study is deliberately framed as a controlled and reproducible engineering and evaluation contribution rather than as an architectural advance. An edge-type ablation study, a cross-dataset evaluation, and a per-vulnerability analysis are additionally reported to characterize the behavior and limitations of the model.
Software vulnerabilities represent an enduring threat to modern cyberspace. Effective vulnerability detection increasingly relies on reasoning about complex program semantics, structural dependencies, and execution behaviors. Consequently, extracting vulnerability-relevant features from code efficiently has become a pr...
Jun-Jie Wang, Tong Yu, Ming Li et al.· Transactions on Graph Intell...· 0 citations
Software defect detection plays a key role in improving system reliability, security, and maintainability. This study proposes a hybrid Transformer–GNN framework to jointly model code semantics and program structure. Source files are normalized, segmented at the function level, and converted into token sequences, while...
Z.-F. Wang, A.-X. Ding, C. Ma et al.· Advanced Electromagnetics· 0 citations
This article presents SEMA-GUARD, a framework that uses semantic analysis and graph neural networks to identify flaws in assembly code, and results imply that including semantic information in graph-based models may be a successful method for identifying vulnerabilities in compiled code.
Malware detection is a critical task in cybersecurity, and graph neural networks over control flow graphs have shown promising results for it. However, detectors are usually evaluated on a random split of a corpus collected over a single period, which cannot show how well a model generalizes to later samples. This stud...
M. Sajeed, Mayukh Mondal, Md. Ashraful Hossen Akash· 0 citations
FiCoVuL is presented, a framework for analyzing interconnected functions and providing fine-grained guidance for vulnerability fixing that significantly outperforms other methods in both vulnerability detection and localization.
Hong-Jun Huang, Fu-Tai Zou, Jia-Ping Gui et al.· ACM Transactions on Software...· 0 citations
This study evaluated existing research approaches and proposed SemVul, a vulnerability detection pipeline that demonstrates better generalization and higher accuracy in learning vulnerable code patterns, and is generic with respect to the programming language and supports multiple architectures.
Younas Affan, L. Regano, G. Giacinto· Journal of Systems and Softw...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.