arrow
Return

Function-level vulnerability detection via dual-view dependency modeling and semantic-structural alignment

delete2026-07-01
delete0
PRE
AI
D
Dawei Zhao
Q
Qu, Guangpeng
X
Xin Li *
H
Hao Sun
S
Shumian Yang
L
Lijuan Xu
DOI:10.1016/j.infsof.2026.108261delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Context: Function-level vulnerability detection is important for software security and code review, but existing learning-based methods often struggle to jointly capture semantic cues and intra-function dependency relations, especially when evidence is distributed across non-adjacent paths or heterogeneous control/data-flow structures. Objective: This study examines whether vulnerability detection can be improved by jointly modeling local dependency evidence, complementary global structural relations, and their alignment with code semantics under the function-level setting. Methods: We propose DualGraphVulD, a dual-view semantic-structural framework. The local view uses gated message passing for fine-grained dependency interactions, while the global view applies restarted diffusion to complement local aggregation during cross-path dependency propagation. A query-guided cross-view alignment module retrieves structure-relevant evidence through cross-attention. We further use Progressive Enhanced Loss as an imbalance-aware loss scheduling strategy without graph-only mutation, preserving consistency between source text and CPG inputs. The evaluation includes graph-size buckets, dependency-span buckets, adaptive gate analysis, Semantic Only behavior, and PrimeVul under realistic splits. Results: Experiments on existing vulnerability benchmarks and PrimeVul show that DualGraphVulD improves overall detection performance under the evaluated settings. Diagnostic analyses indicate that conventional full-graph message passing degrades more on structurally complex or long-span samples, whereas Dual-GraphVulD maintains more stable performance by combining local aggregation, restarted global diffusion, and semantic-structural alignment. Conclusion: Dual-view dependency modeling and semantic-structural alignment are useful for structurally heterogeneous functions. This study focuses on function-level detection and does not claim complete coverage of inter-procedural vulnerabilities.
Keywords:
Vulnerability detection
Software security
Function-level analysis
Graph neural networks
Program dependency modeling
Semantic-structural alignment

Journal

Information and Software Technology cover
Information and Software Technology
IF:
4.3
Papers:
3.8K
Citations:
7.7K

Organization

Q
qilu university of technology
Scholars:
700
Papers: 172
Citations: 0
Cited Papers

Cited Papers

No cited papers available