arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

ObliVul:面向代码漏洞检测的警报条件安全义务建模与双向反事实验证

ObliVul: Alert-Conditioned Safety Obligation Modeling and Bidirectional Counterfactual Validation for Code Vulnerability Detection

Heyang Tan, Chengxin Gao, Xin Wen, Jiaxin Li, Rui Cao

arXiv 2610.11801首次发表:更新:

发表机构

Taiyuan University of Technology(太原理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究针对代码漏洞检测中静态分析产生大量警报难以筛选的问题,提出ObliVul框架,通过安全义务建模与双向反事实验证提升漏洞检测的准确性,减少误报。

AI 中文摘要

在实际软件开发中,漏洞检测的主要挑战往往不在于发现可疑代码,而在于从静态分析产生的大量候选警报中识别出哪些警报真正值得关注。现有基于学习的方法主要在函数或代码行级别识别可疑模式,难以提取以单个警报为中心的完整程序证据。尽管大型语言模型可以从局部程序事实中推断风险源、危险操作、保护条件和状态前置条件,但此类语义信息无法可靠地与特定程序节点、依赖关系和传播路径对齐,因此不足以验证对应的安全义务是否真正影响当前警报。为解决该问题,我们提出ObliVul,一种用于漏洞检测的警报条件安全义务建模与双向反事实验证框架。对于每个候选警报,ObliVul首先从代码属性图(CPG)中提取局部证据包(LEP),并使用大型语言模型恢复候选安全义务;随后将安全义务与程序节点、依赖边和路径范围对齐,构建局部安全义务图(LSOG);最后,VAFI聚合互补的已验证警报证据,同时抑制冗余或较弱的证据,以生成函数级漏洞预测。实验结果表明,ObliVul可有效区分漏洞版本与修复版本,并减少修复代码上的持续误报; ablation研究进一步证实了每个组件对于安全义务恢复、风险响应验证和函数级漏洞推断的必要性。

英文摘要

In real-world software development, the primary challenge in vulnerability detection is often not finding suspicious code, but identifying which alerts among the large number of candidate alerts produced by static analysis truly warrant attention. Existing learning-based methods mainly identify suspicious patterns at the function or line level, making it difficult to extract complete program evidence centered on an individual alert. Although large language models can infer risk sources, dangerous operations, protection conditions, and state preconditions from local program facts, such semantic information cannot be reliably aligned with specific program nodes, dependency relations, and propagation paths, and is therefore insufficient to verify whether the corresponding safety obligations truly affect the current alert. To address this problem, we propose ObliVul, an alert-conditioned safety obligation modeling and bidirectional counterfactual validation framework for vulnerability detection. For each candidate alert, ObliVul first extracts a Local Evidence Pack (LEP) from the Code Property Graph (CPG) and uses a large language model to recover candidate safety obligations. It then aligns the safety obligations with program nodes, dependency edges, and path scopes to construct a Local Safety Obligation Graph (LSOG). Finally, VAFI aggregates complementary verified alert evidence while suppressing redundant or weaker evidence to produce a function-level vulnerability prediction. Experimental results show that ObliVul effectively distinguishes vulnerable versions from fixed versions and reduces persistent false positives on fixed code. Ablation studies further confirm the necessity of each component for safety obligation recovery, risk response validation, and function-level vulnerability inference.

Comments20 pages, 4 figures, 7 tables. Preprint

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑