arrow
Return

A responsible AI-driven framework for robust and transparent software vulnerability detection

delete2026-04-01
delete0
delete
OA
AI
B
Basheer, Nihala
I
Islam, Shareeful
K
Kumar, Prabhat *
D
Danish Javeed
I
Islam, Najmul
DOI:10.1016/j.infsof.2026.108126delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Context: Software vulnerability detection (SVD) is increasingly challenged by the scale and complexity of modern software systems. Although deep learning and LLM-based approaches demonstrate strong detection performance, their adoption in security-critical settings is limited by insufficient interpretability, adversarial resilience, and systematic Responsible AI integration. Objective: This paper aims to design and evaluate a Responsible AI-driven framework for SVD that operationalizes fairness, interpretability, security, reliability, and transparency without compromising detection effectiveness. Method: We propose a model-agnostic vulnerability detection framework that incorporates fairness-aware data preprocessing, multi-model evaluation, and structured verification mechanisms. Interpretability is achieved through multi-view explanations combining global and local SHAP, LIME, and attention-based attribution. Explanation consistency is examined using attention-guided token occlusion, while security is evaluated via multiple white-box adversarial attacks on correctly classified test samples. The framework is validated on three public datasets - CWE-119, CWE-399, and DiverseVul - using deep learning and pre-trained LLMs. Results: Experimental results demonstrate competitive detection performance across datasets while providing structured explanation and adversarial evaluation evidence. Interpretability analyses reveal dataset-specific vulnerability cues aligned with domain knowledge, and perturbation studies show consistent confidence shifts under controlled token masking. Adversarial experiments further illustrate stable performance trends under attack conditions. Conclusion: The findings indicate that Responsible AI principles can be systematically operationalized within deep learning and LLM-based SVD pipelines. By integrating fairness, interpretability, security evaluation, reliability assessment, and transparency mechanisms, the proposed framework supports trustworthy and security-aware deployment of AI-driven vulnerability detection systems.
Keywords:
Responsible AI
Software vulnerability detection
Security
Deep learning
Large Language Model (LLMs)
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Information and Software Technology cover
Information and Software Technology
IF:
4.3
Papers:
3.7K
Citations:
7.7K

Organization

A
Anglia Ruskin University
Scholars:
2.6K
Papers: 2.5K
Citations: 3.3K
D
Dalian Maritime University
Scholars:
1.2W
Papers: 7.8K
Citations: 6.3K
L
Lappeenranta-Lahti University of Technology LUT
Scholars:
3.4K
Papers: 4.1K
Citations: 5
researcher View more organizations