Enhancing Graph-Based Vulnerability Detection through Standardized Deep Learning Pipelines

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Identifying vulnerable code is crucial to software system security. With the rise of deep learning, graph neural networks (GNNs) have received much attention for detecting vulnerabilities. While many studies aim to enhance GNN performance by refining graph structures, improving datasets, or optimizing model architectures, three key questions remain unanswered: 1) How do simple graph structures impact model performance? 2) How similar are artificially generated datasets to vulnerable code in the real world? 3) Does a more complex model provide better benefits in vulnerability detection? To find answers to these questions, we did experiments to show how basic graph structures affect GNN models and give guidelines on how to choose datasets. In addition, we introduce VulGCANet, a model with a relatively simple architecture that utilizes code property graphs and combines Graph Convolutional Networks (GCN) and Graph Attention Network (GAT) layers for vulnerability detection. The experimental results demonstrate that VulGCANet exhibits 30% improvements in recall while performing similarly to other graph neural network-based models, highlighting the importance of reducing the complexity of GNN model architectures in graph-based vulnerability detection. These findings provide valuable insights for advancing GNN-based vulnerability detection efforts.

키워드

Vulnerability detection; program representations; graph neural networks; deep learning
제목
Enhancing Graph-Based Vulnerability Detection through Standardized Deep Learning Pipelines
저자
Hao, Jiashun; Kwon, Young-Woo
DOI
10.1109/TrustCom63139.2024.00174
발행일
2024
유형
Proceedings Paper
저널명
2024 IEEE 23RD INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM
페이지
1231 ~ 1238