返回
Neural Transfer Learning for Repairing Security Vulnerabilities in C Code
DOI:10.1109/TSE.2022.3147265.png)
摘要
En 中文
In this paper, we address the problem of automatic repair of software vulnerabilities with deep learning. The major problem with data-driven vulnerability repair is that the few existing datasets of known confirmed vulnerabilities consist of only a few thousand examples. However, training a deep learning model often requires hundreds of thousands of examples. In this work, we leverage the intuition that the bug fixing task and the vulnerability fixing task are related and that the knowledge learned from bug fixes can be transferred to fixing vulnerabilities. In the machine learning community, this technique is called transfer learning. In this paper, we propose an approach for repairing security vulnerabilities named VRepair which is based on transfer learning. VRepair is first trained on a large bug fix corpus and is then tuned on a vulnerability fix dataset, which is an order of magnitude smaller. In our experiments, we show that a model trained only on a bug fix corpus can already fix some vulnerabilities. Then, we demonstrate that transfer learning improves the ability to repair vulnerable C functions. We also show that the transfer learning model performs better than a model trained with a denoising task and fine-tuned on the vulnerability fixing task. To sum up, this paper shows that transfer learning works well for repairing security vulnerabilities in C compared to learning on a small dataset.
Keyword:
Vulnerability fixing
transfer learning
seq2seq learning
期刊
IF:
5.6
论文数:
2.9K
被引数:
1.1W
机构
引用论文
Polysialylated Neural Cell Adhesion Molecule Is Involved in Induction of Long-Term Potentiation and Memory Acquisition and Consolidation in a Fear-Conditioning Paradigm聚唾液酸化的神经细胞粘附分子在恐惧调节范式中参与诱导长期增强和记忆获取和巩固
Desempenho de crianças do ensino fundamental na solução de problemas aritméticos<A NAME="top"></A>问题的基本解决方案

