arrow
Return

Aspect-centric vulnerability understanding via semantics-aware commit representation learning

delete2026-06-26
delete0
PRE
AI
X
Xiaobing Sun
Y
Yifan Xu
S
Sicong Cao *
Z
Zhenlei Ye
DOI:10.1007/s10664-026-10907-2delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Open-source software (OSS) has become pervasive in modern software ecosystems; however, the inability to promptly comprehend newly introduced vulnerabilities poses substantial security risks. A particularly pressing challenge stems from silent OSS updates, in which downstream users often remain unaware of latent vulnerabilities, resulting in delayed mitigation and prolonged exposure to persistent, indirect, and potentially stealthy attacks. While prior research has examined the detection of silent vulnerability fixes, it frequently neglects an essential requirement: delivering precise vulnerability aspects that enable third-party developers to mitigate risks effectively. To bridge this gap, we present VulPilot, a novel framework for aspect-level vulnerability explanation generation via semantics-aware commit representation learning. VulPilot addresses two core challenges: (1) the limitations of existing representation learning strategies and (2) noise in commit messages. First, it constructs differential program dependency graphs (diff-PDGs) and applies program slicing to extract semantics-aware code contexts, thereby capturing vulnerability-relevant control and data flows. Second, it incorporates a denoising mechanism for commit messages by ranking key phrases using mask similarity, filtering out irrelevant content while preserving critical vulnerability aspects. Experimental results show that VulPilot surpasses state-of-the-art baselines, yielding ROUGE-L improvements of 5.9%–18.8%. A user study further substantiates its practical utility, indicating that explanations generated by VulPilot substantially enhance both vulnerability comprehension and mitigation efficiency.
Keywords:
Open-source software
Vulnerability Understanding
Explainability
Commit Representation Learning

Journal

Empirical Software Engineering cover
Empirical Software Engineering
IF:
3.6
Papers:
1.9K
Citations:
5.3K

Organization

N
nanjing university of posts and telecommunications
Scholars:
3.4K
Papers: 1.4K
Citations: 0