arrow
返回

Deep Learning Based Vulnerability Detection: Are We There Yet?

delete2022-09-01
delete232
delete
OA
AI
S
Saikat Chakraborty
R
Rahul Krishna *
Y
Yangruibo Ding
B
Baishakhi Ray
DOI:10.1109/TSE.2021.3087402delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Automated detection of software vulnerabilities is a fundamental problem in software security. Existing program analysis techniques either suffer from high false positives or false negatives. Recent progress in Deep Learning (DL) has resulted in a surge of interest in applying DL for automated vulnerability detection. Several recent studies have demonstrated promising results achieving an accuracy of up to 95 percent at detecting vulnerabilities. In this paper, we ask, how well do the state-of-the-art DL-based techniques perform in a real-world vulnerability prediction scenario? To our surprise, we find that their performance drops by more than 50 percent. A systematic investigation of what causes such precipitous performance drop reveals that existing DL-based vulnerability prediction approaches suffer from challenges with the training data (e.g., data duplication, unrealistic distribution of vulnerable classes, etc.) and with the model choices (e.g., simple token-based models). As a result, these approaches often do not learn features related to the actual cause of the vulnerabilities. Instead, they learn unrelated artifacts from the dataset (e.g., specific variable/function names, etc.). Leveraging these empirical findings, we demonstrate how a more principled approach to data collection and model design, based on realistic settings of vulnerability prediction, can lead to better solutions. The resulting tools perform significantly better than the studied baseline-up to 33.57 percent boost in precision and 128.38 percent boost in recall compared to the best performing model in the literature. Overall, this paper elucidates existing DL-based vulnerability prediction systems' potential issues and draws a roadmap for future DL-based vulnerability prediction research.
Keyword:
Predictive models
Neural networks
Testing
Data models
Security
Training
Training data
Vulnerability
deep learning based vulnerability detection
real world vulnerabilities
graph neural network based vulnerability detection
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.9K
被引数:
1.1W

机构

C
Columbia University
学者数:
7.1W
论文数: 6.4W
被引数: 263
引用论文

引用论文

Challenges and future of biomarker tests in the era of precision oncology: Can we rely on immunohistochemistry (IHC) or fluorescencein situhybridization (FISH) to select the optimal patients for matched therapy?
err2017-08-01
err0
errOAAI
errYoung Kwang Chae; Ayush Arya; Lauren Chiec; Hiral Shah; Ari Rosenberg; Sandip Patel; Kirtee Raparia; Jaehyuk Choi; Derek A. Wainwright; Victoria Villaflor; Massimo Cristofanilli; Francis Giles
err分享
err收藏
err分享
err收藏
err分享
err收藏
Polymerization of 1,2,4,5-tetramethylbenzene (durene) in direct-current discharge
err2010-09-10
err0
PREAI
errM. Yu. Yablokov; A. B. Gil’man; N. M. Surin; I. V. Semenov; A. A. Kuznetsov; I. A. Chmutin
err分享
err收藏
Regional differences in type 2 diabetes treatment and outcomes in Germany—An analysis of the German DPV and DIVE registries
err2018-09-19
err0
PREAI
errBettina Hartmann; Peter Bramlage; Stefanie Lanzinger; Thomas Danne; Michael Hummel; Matthias Kaltheuner; Dirk Raddatz; Wolfgang Rathmann; Hans‐Martin Reuter; Jochen Seufert; Reinhard W. Holl
err分享
err收藏
Causes of pneumonia presenting to a district general hospital.
err1981-08-01
err0
errOAAI
errR J White; A D Blainey; K J Harrison; S K Clarke
err分享
err收藏
err分享
err收藏
Treatment and outcome of severe lower-limb ischaemia
err1994-04-01
err0
PREAI
errR D Sayers; M M Thompson; T Hartshorne; J S Budd; P R F Bell
err分享
err收藏
学者 查看更多内容