Return
Function-level vulnerability detection via dual-view dependency modeling and semantic-structural alignment
DOI:10.1016/j.infsof.2026.108261.png)
Abstract
En 中文
Context: Function-level vulnerability detection is important for software security and code review, but existing learning-based methods often struggle to jointly capture semantic cues and intra-function dependency relations, especially when evidence is distributed across non-adjacent paths or heterogeneous control/data-flow structures. Objective: This study examines whether vulnerability detection can be improved by jointly modeling local dependency evidence, complementary global structural relations, and their alignment with code semantics under the function-level setting. Methods: We propose DualGraphVulD, a dual-view semantic-structural framework. The local view uses gated message passing for fine-grained dependency interactions, while the global view applies restarted diffusion to complement local aggregation during cross-path dependency propagation. A query-guided cross-view alignment module retrieves structure-relevant evidence through cross-attention. We further use Progressive Enhanced Loss as an imbalance-aware loss scheduling strategy without graph-only mutation, preserving consistency between source text and CPG inputs. The evaluation includes graph-size buckets, dependency-span buckets, adaptive gate analysis, Semantic Only behavior, and PrimeVul under realistic splits. Results: Experiments on existing vulnerability benchmarks and PrimeVul show that DualGraphVulD improves overall detection performance under the evaluated settings. Diagnostic analyses indicate that conventional full-graph message passing degrades more on structurally complex or long-span samples, whereas Dual-GraphVulD maintains more stable performance by combining local aggregation, restarted global diffusion, and semantic-structural alignment. Conclusion: Dual-view dependency modeling and semantic-structural alignment are useful for structurally heterogeneous functions. This study focuses on function-level detection and does not claim complete coverage of inter-procedural vulnerabilities.
Keywords:
Vulnerability detection
Software security
Function-level analysis
Graph neural networks
Program dependency modeling
Semantic-structural alignment
Journal
IF:
4.3
Papers:
3.8K
Citations:
7.7K
Organization
Cited Papers
No cited papers available

