SemVul:基于代码属性图的语义增强图神经网络漏洞检测
SemVul: Semantic-Enhanced Graph Neural Networks for Code Property Graph-based Vulnerability Detection
- Dipartimento di Ingegneria Elettrica e Elettronica, Università di Cagliari(卡利亚里大学电气与电子工程系)
- Interuniversity National Consortium for Informatics, CINI(意大利国家信息学大学联盟)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
SemVul是一种基于代码属性图的语义增强图神经网络漏洞检测方法,通过结合节点级和边级语义嵌入,提升漏洞检测的准确性和泛化能力。
AI中文摘要:
源代码中的漏洞往往是全球网络攻击的根源,因为攻击者利用软件中的弱点来获取未经授权的访问、窃取数据或中断服务。在本研究中,我们评估了现有的研究方法,并提出了SemVul,一个漏洞检测流水线,该流水线在学习易受攻击的代码模式方面表现出更好的泛化能力和更高的准确性。我们提出了一种基于代码属性图的漏洞检测方法,并结合语义级增强,使模型能够同时捕获程序的结构流和代码的语义含义。我们的方法利用预训练的代码嵌入技术,集成了节点级和边级语义嵌入。我们在公开可用的基准数据集上系统地评估了多种图神经网络架构。SemVul在编程语言方面具有通用性,并支持多种架构。通过整合结构和语义信息,所提出的方法提高了漏洞检测性能。我们的结果表明,SemVul优于现有方法,并提供了更好的泛化能力。
英文摘要:
Vulnerabilities in source code are often the root cause of cyberattacks worldwide, as attackers exploit weaknesses in software to gain unauthorized access, steal data, or disrupt services. In this study, we evaluated existing research approaches and propose SemVul, a vulnerability detection pipeline that demonstrates better generalization and higher accuracy in learning vulnerable code patterns. We propose a Code Property Graph-based vulnerability-detection approach combined with semantic-level enhancement, enabling the model to capture both the program's structural flow and the semantic meaning of the code. Our approach integrates both node-level and edge-level semantic embeddings using pre-trained code embedding techniques. We systematically evaluate multiple GNN architectures on publicly available benchmark datasets. SemVul is generic with respect to the programming language and supports multiple architectures. By integrating structural and semantic information, the proposed approach improves vulnerability detection performance. Our results show that SemVul outperforms existing approaches and provides better generalization.