代码漏洞模型在保持行为的有意变换下的嵌入漂移
Embedding Drift in Code Vulnerability Models Under Intended Behaviour-Preserving Transformations
- University of Waterloo(滑铁卢大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本研究针对代码漏洞模型在语义保持变换下的嵌入漂移问题,提出一种仅训练防御方法,将干净与变异表示投影更近,显著降低漏洞翻转率,但引入误报权衡。
AI中文摘要:
保持程序行为的代码编辑可以使冻结的代码嵌入跨越分类器决策边界,导致原本正确检测到的漏洞被预测为良性。这种不稳定性是有问题的,因为语义中性的更改,包括注释移除、不可达代码插入、变量重命名和循环重写,不应改变模型的安全判断。我们使用来自Big-Vul数据集的15,000个C/C++函数(组织为7,500对易受攻击-已修补对)来研究此问题。对易受攻击和良性样本应用四种变异轨道:注释移除、不可达代码插入、变量重命名、循环重写,以及应用所有变换的组合设置。使用冻结的microsoft/codebert-base嵌入和六个下游分类器,我们评估漏洞预测的鲁棒性,并引入一种仅训练的防御方法,该方法将干净和变异表示投影得更近,同时保留漏洞类别信息。在组合变异下,基线易受攻击翻转率(VFR)范围为35.55%至42.15%。所提出的防御方法将平均公共集VFR从22.60%降至11.32%,并将平均变异准确率从55.33%提高到57.10%。对于逻辑回归,VFR降低了17.29个百分点,尽管良性到易受攻击的翻转增加了11.95个百分点。这些结果表明,该防御方法提高了对语义保持代码变换的鲁棒性,但引入了误报权衡,并未完全消除预测不稳定性。
英文摘要:
Code edits that preserve program behaviour can shift frozen code embeddings across classifier decision boundaries, causing correctly detected vulnerabilities to be predicted as benign. Such instability is problematic because semantically neutral changes, including comment removal, insertion of unreachable code, variable renaming, and loop rewriting, should not alter a model's security judgment. We investigate this issue using 15,000 C/C++ functions organized as 7,500 vulnerable-patched pairs from the Big-Vul dataset. Four mutation tracks are applied to both vulnerable and benign samples: comment removal, unreachable code insertion, variable renaming, loop rewriting, and a combined setting that applies all transformations. Using frozen microsoft/codebert-base embeddings with six downstream classifiers, we evaluate the robustness of vulnerability predictions and introduce a train-only defence that projects clean and mutated representations closer together while preserving vulnerability-class information. Under combined mutations, the baseline Vulnerable Flip Rate (VFR) ranges from 35.55% to 42.15%. The proposed defence reduces the mean common-set VFR from 22.60% to 11.32% and improves mean mutated accuracy from 55.33% to 57.10%. For Logistic Regression, VFR decreases by 17.29 percentage points, although benign-to-vulnerable flips increase by 11.95 percentage points. These results indicate that the defence improves robustness to semantics-preserving code transformations but introduces a false-positive trade-off and does not fully eliminate prediction instability.