LLMxCPG: Context-Aware Vulnerability Detection Through Code Property Graph-Guided Large Language Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Lekssays, Ahmed, Mouhcine, Hamza, Tran, Khang, Yu, Ting, Khalil, Issa
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916856395202560
author Lekssays, Ahmed
Mouhcine, Hamza
Tran, Khang
Yu, Ting
Khalil, Issa
author_facet Lekssays, Ahmed
Mouhcine, Hamza
Tran, Khang
Yu, Ting
Khalil, Issa
contents Software vulnerabilities present a persistent security challenge, with over 25,000 new vulnerabilities reported in the Common Vulnerabilities and Exposures (CVE) database in 2024 alone. While deep learning based approaches show promise for vulnerability detection, recent studies reveal critical limitations in terms of accuracy and robustness: accuracy drops by up to 45% on rigorously verified datasets, and performance degrades significantly under simple code modifications. This paper presents LLMxCPG, a novel framework integrating Code Property Graphs (CPG) with Large Language Models (LLM) for robust vulnerability detection. Our CPG-based slice construction technique reduces code size by 67.84 to 90.93% while preserving vulnerability-relevant context. Our approach's ability to provide a more concise and accurate representation of code snippets enables the analysis of larger code segments, including entire projects. This concise representation is a key factor behind the improved detection capabilities of our method, as it can now identify vulnerabilities that span multiple functions. Empirical evaluation demonstrates LLMxCPG's effectiveness across verified datasets, achieving 15-40% improvements in F1-score over state-of-the-art baselines. Moreover, LLMxCPG maintains high performance across function-level and multi-function codebases while exhibiting robust detection efficacy under various syntactic code modifications.
format Preprint
id arxiv_https___arxiv_org_abs_2507_16585
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LLMxCPG: Context-Aware Vulnerability Detection Through Code Property Graph-Guided Large Language Models
Lekssays, Ahmed
Mouhcine, Hamza
Tran, Khang
Yu, Ting
Khalil, Issa
Cryptography and Security
Software vulnerabilities present a persistent security challenge, with over 25,000 new vulnerabilities reported in the Common Vulnerabilities and Exposures (CVE) database in 2024 alone. While deep learning based approaches show promise for vulnerability detection, recent studies reveal critical limitations in terms of accuracy and robustness: accuracy drops by up to 45% on rigorously verified datasets, and performance degrades significantly under simple code modifications. This paper presents LLMxCPG, a novel framework integrating Code Property Graphs (CPG) with Large Language Models (LLM) for robust vulnerability detection. Our CPG-based slice construction technique reduces code size by 67.84 to 90.93% while preserving vulnerability-relevant context. Our approach's ability to provide a more concise and accurate representation of code snippets enables the analysis of larger code segments, including entire projects. This concise representation is a key factor behind the improved detection capabilities of our method, as it can now identify vulnerabilities that span multiple functions. Empirical evaluation demonstrates LLMxCPG's effectiveness across verified datasets, achieving 15-40% improvements in F1-score over state-of-the-art baselines. Moreover, LLMxCPG maintains high performance across function-level and multi-function codebases while exhibiting robust detection efficacy under various syntactic code modifications.
title LLMxCPG: Context-Aware Vulnerability Detection Through Code Property Graph-Guided Large Language Models
topic Cryptography and Security
url https://arxiv.org/abs/2507.16585