arrow
Return

Code Aggregate Graph: Effective Representation for Graph Neural Networks to Detect Vulnerable Code

delete2022-01-01
delete4
delete
OA
AI
H
Hoang Viet Nguyen *
J
Junjun Zheng
A
Atsuo Inomata
T
Tetsutaro Uehara
DOI:10.1109/ACCESS.2022.3216395delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Deep learning, especially graph neural networks (GNNs), provides efficient, fast, and automated methods to detect vulnerable code. However, the accuracy could be improved as previous studies were limited by existing code representations. Additionally, the diversity of embedding techniques and GNN models can make selecting the appropriate method challenging. Herein we propose Code Aggregate Graph (CAG) to improve vulnerability detection efficiency. CAG combines the principles of different code analyses such as abstract syntax tree, control flow graph, and program dependence graph with dominator and post-dominator trees. This extensive representation empowers deep graph networks for enhanced classification. We also implement different data encoding methods and neural networks to provide a multidimensional view of the system performance. Specifically, three word embedding approaches and three deep GNNs are utilized to build classifiers. Then CAG is evaluated using two datasets: a real-world open-source dataset and the software assurance reference dataset. CAG is also compared with seven state-of-the-art methods and six classic representations. CAG shows the best performance. Compared to previous studies, CAG has an increased accuracy (5.4%) and F1-score (5.1%). Additionally, experiments confirm that encoding has a positive impact on accuracy (4-6%) but the network type does not. The study should contribute to a meaningful benchmark for future research on code representations, data encoding, and GNNs.
Keywords:
Codes
Source coding
Computer bugs
Syntactics
Deep learning
Feature extraction
Graph neural networks
Vulnerability detection
code representation
graph neural networks
deep learning

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

T
the university of osaka
Scholars:
2.8W
Papers: 1.8W
Citations: 6
R
ritsumeikan university
Scholars:
4.0K
Papers: 3.6K
Citations: 0
Cited Papers

Cited Papers

Titanium ketimide complexes as α-olefin homo- and copolymerisation catalysts. X-ray diffraction structures of [TiCp′(NCtBu2)Cl2] (Cp′=Ind, Cp*)
err2004-01-01
err0
PREAI
errAlberto R. Dias; M. Teresa Duarte; Anabela C. Fernandes; Susete Fernandes; Maria M. Marques; Ana M. Martins; João F. da Silva; Sandra S. Rodrigues
errShare
errSave
Nature-Based Citizen Science as a Mechanism to Improve Human Health in Urban Areas
err2021-12-22
err0
errOAAI
errCraig R. Williams; Sophie M. Burnell; Michelle Rogers; Emily J. Flies; Katherine L. Baldock
errShare
errSave
errShare
errSave
errShare
errSave
SySeVR: A Framework for Using Deep Learning to Detect Software Vulnerabilities
err2022-07-01
err261
errOAAI
errLi, Zhen; Zou, Deqing; Xu, Shouhuai; Jin, Hai; Zhu, Yawei; Chen, Zhaoxuan
errShare
errSave
errShare
errSave
Late Bronze Age climate change and the destruction of the Mycenaean Palace of Nestor at Pylos
err2017-12-27
err0
errOAAI
errMartin Finné; Karin Holmgren; Chuan-Chou Shen; Hsun-Ming Hu; Meighan Boyd; Sharon Stocker
errShare
errSave
Improving Vulnerability Inspection Efficiency Using Active Learning
err2021-11-01
err31
errOAAI
errYu, Zhe; Theisen, Christopher; Williams, Laurie; Menzies, Tim
errShare
errSave
researcher View more