Coca: Improving and Explaining Graph Neural Network-Based Vulnerability Detection Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Cao, Sicong, Sun, Xiaobing, Wu, Xiaoxue, Lo, David, Bo, Lili, Li, Bin, Liu, Wei
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916106640293888
author Cao, Sicong
Sun, Xiaobing
Wu, Xiaoxue
Lo, David
Bo, Lili
Li, Bin
Liu, Wei
author_facet Cao, Sicong
Sun, Xiaobing
Wu, Xiaoxue
Lo, David
Bo, Lili
Li, Bin
Liu, Wei
contents Recently, Graph Neural Network (GNN)-based vulnerability detection systems have achieved remarkable success. However, the lack of explainability poses a critical challenge to deploy black-box models in security-related domains. For this reason, several approaches have been proposed to explain the decision logic of the detection model by providing a set of crucial statements positively contributing to its predictions. Unfortunately, due to the weakly-robust detection models and suboptimal explanation strategy, they have the danger of revealing spurious correlations and redundancy issue. In this paper, we propose Coca, a general framework aiming to 1) enhance the robustness of existing GNN-based vulnerability detection models to avoid spurious explanations; and 2) provide both concise and effective explanations to reason about the detected vulnerabilities. \sysname consists of two core parts referred to as Trainer and Explainer. The former aims to train a detection model which is robust to random perturbation based on combinatorial contrastive learning, while the latter builds an explainer to derive crucial code statements that are most decisive to the detected vulnerability via dual-view causal inference as explanations. We apply Coca over three typical GNN-based vulnerability detectors. Experimental results show that Coca can effectively mitigate the spurious correlation issue, and provide more useful high-quality explanations.
format Preprint
id arxiv_https___arxiv_org_abs_2401_14886
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Coca: Improving and Explaining Graph Neural Network-Based Vulnerability Detection Systems
Cao, Sicong
Sun, Xiaobing
Wu, Xiaoxue
Lo, David
Bo, Lili
Li, Bin
Liu, Wei
Cryptography and Security
Software Engineering
Recently, Graph Neural Network (GNN)-based vulnerability detection systems have achieved remarkable success. However, the lack of explainability poses a critical challenge to deploy black-box models in security-related domains. For this reason, several approaches have been proposed to explain the decision logic of the detection model by providing a set of crucial statements positively contributing to its predictions. Unfortunately, due to the weakly-robust detection models and suboptimal explanation strategy, they have the danger of revealing spurious correlations and redundancy issue. In this paper, we propose Coca, a general framework aiming to 1) enhance the robustness of existing GNN-based vulnerability detection models to avoid spurious explanations; and 2) provide both concise and effective explanations to reason about the detected vulnerabilities. \sysname consists of two core parts referred to as Trainer and Explainer. The former aims to train a detection model which is robust to random perturbation based on combinatorial contrastive learning, while the latter builds an explainer to derive crucial code statements that are most decisive to the detected vulnerability via dual-view causal inference as explanations. We apply Coca over three typical GNN-based vulnerability detectors. Experimental results show that Coca can effectively mitigate the spurious correlation issue, and provide more useful high-quality explanations.
title Coca: Improving and Explaining Graph Neural Network-Based Vulnerability Detection Systems
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2401.14886