상세 보기
Enhancing Graph-Based Vulnerability Detection through Standardized Deep Learning Pipelines
- Hao, Jiashun;
- Kwon, Young-Woo
WEB OF SCIENCE
0SCOPUS
0초록
Identifying vulnerable code is crucial to software system security. With the rise of deep learning, graph neural networks (GNNs) have received much attention for detecting vulnerabilities. While many studies aim to enhance GNN performance by refining graph structures, improving datasets, or optimizing model architectures, three key questions remain unanswered: 1) How do simple graph structures impact model performance? 2) How similar are artificially generated datasets to vulnerable code in the real world? 3) Does a more complex model provide better benefits in vulnerability detection? To find answers to these questions, we did experiments to show how basic graph structures affect GNN models and give guidelines on how to choose datasets. In addition, we introduce VulGCANet, a model with a relatively simple architecture that utilizes code property graphs and combines Graph Convolutional Networks (GCN) and Graph Attention Network (GAT) layers for vulnerability detection. The experimental results demonstrate that VulGCANet exhibits 30% improvements in recall while performing similarly to other graph neural network-based models, highlighting the importance of reducing the complexity of GNN model architectures in graph-based vulnerability detection. These findings provide valuable insights for advancing GNN-based vulnerability detection efforts.
키워드
- 제목
- Enhancing Graph-Based Vulnerability Detection through Standardized Deep Learning Pipelines
- 저자
- Hao, Jiashun; Kwon, Young-Woo
- 발행일
- 2024
- 유형
- Proceedings Paper
- 저널명
- 2024 IEEE 23RD INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM
- 페이지
- 1231 ~ 1238
- 언어
- ENG
- 출판사
- IEEE COMPUTER SOC
- 발행국가
- 미국
- 분량
- 8 페이지
- ISSN
- E 2324-9013
P 2324-898X