A Study on Mixup-Inspired Augmentation Methods for Software Vulnerability Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Daneshvar, Seyed Shayan, Tan, Da, Wang, Shaowei, Leung, Carson
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909595510767616
author Daneshvar, Seyed Shayan
Tan, Da
Wang, Shaowei
Leung, Carson
author_facet Daneshvar, Seyed Shayan
Tan, Da
Wang, Shaowei
Leung, Carson
contents Various deep learning (DL) methods have recently been utilized to detect software vulnerabilities. Real-world software vulnerability datasets are rare and hard to acquire, as there is no simple metric for classifying vulnerability. Such datasets are heavily imbalanced, and none of the current datasets are considered huge for DL models. To tackle these problems, a recent work has tried to augment the dataset using the source code and generate realistic single-statement vulnerabilities, which is not quite practical and requires manual checking of the generated vulnerabilities. In this paper, we aim to explore the augmentation of vulnerabilities at the representation level to help current models learn better, which has never been done before to the best of our knowledge. We implement and evaluate five augmentation techniques that augment the embedding of the data and have recently been used for code search, which is a completely different software engineering task. We also introduced a conditioned version of those augmentation methods, which ensures the augmentation does not change the vulnerable section of the vector representation. We show that such augmentation methods can be helpful and increase the F1-score by up to 9.67%, yet they cannot beat Random Oversampling when balancing datasets, which increases the F1-score by 10.82%.
format Preprint
id arxiv_https___arxiv_org_abs_2504_15632
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A Study on Mixup-Inspired Augmentation Methods for Software Vulnerability Detection
Daneshvar, Seyed Shayan
Tan, Da
Wang, Shaowei
Leung, Carson
Software Engineering
Cryptography and Security
Machine Learning
Various deep learning (DL) methods have recently been utilized to detect software vulnerabilities. Real-world software vulnerability datasets are rare and hard to acquire, as there is no simple metric for classifying vulnerability. Such datasets are heavily imbalanced, and none of the current datasets are considered huge for DL models. To tackle these problems, a recent work has tried to augment the dataset using the source code and generate realistic single-statement vulnerabilities, which is not quite practical and requires manual checking of the generated vulnerabilities. In this paper, we aim to explore the augmentation of vulnerabilities at the representation level to help current models learn better, which has never been done before to the best of our knowledge. We implement and evaluate five augmentation techniques that augment the embedding of the data and have recently been used for code search, which is a completely different software engineering task. We also introduced a conditioned version of those augmentation methods, which ensures the augmentation does not change the vulnerable section of the vector representation. We show that such augmentation methods can be helpful and increase the F1-score by up to 9.67%, yet they cannot beat Random Oversampling when balancing datasets, which increases the F1-score by 10.82%.
title A Study on Mixup-Inspired Augmentation Methods for Software Vulnerability Detection
topic Software Engineering
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2504.15632