LLaVul: A Multimodal LLM for Interpretable Vulnerability Reasoning about Source Code

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jararweh, Ala, Adams, Michael, Sahu, Avinash, Mueen, Abdullah, Anwar, Afsah
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911168171343872
author Jararweh, Ala
Adams, Michael
Sahu, Avinash
Mueen, Abdullah
Anwar, Afsah
author_facet Jararweh, Ala
Adams, Michael
Sahu, Avinash
Mueen, Abdullah
Anwar, Afsah
contents Increasing complexity in software systems places a growing demand on reasoning tools that unlock vulnerabilities manifest in source code. Many current approaches focus on vulnerability analysis as a classifying task, oversimplifying the nuanced and context-dependent real-world scenarios. Even though current code large language models (LLMs) excel in code understanding, they often pay little attention to security-specific reasoning. We propose LLaVul, a multimodal LLM tailored to provide fine-grained reasoning about code through question-answering (QA). Our model is trained to integrate paired code and natural queries into a unified space, enhancing reasoning and context-dependent insights about code vulnerability. To evaluate our model performance, we construct a curated dataset of real-world vulnerabilities paired with security-focused questions and answers. Our model outperforms state-of-the-art general-purpose and code LLMs in the QA and detection tasks. We further explain decision-making by conducting qualitative analysis to highlight capabilities and limitations. By integrating code and QA, LLaVul enables more interpretable and security-focused code understanding.
format Preprint
id arxiv_https___arxiv_org_abs_2509_17337
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LLaVul: A Multimodal LLM for Interpretable Vulnerability Reasoning about Source Code
Jararweh, Ala
Adams, Michael
Sahu, Avinash
Mueen, Abdullah
Anwar, Afsah
Artificial Intelligence
Computation and Language
Increasing complexity in software systems places a growing demand on reasoning tools that unlock vulnerabilities manifest in source code. Many current approaches focus on vulnerability analysis as a classifying task, oversimplifying the nuanced and context-dependent real-world scenarios. Even though current code large language models (LLMs) excel in code understanding, they often pay little attention to security-specific reasoning. We propose LLaVul, a multimodal LLM tailored to provide fine-grained reasoning about code through question-answering (QA). Our model is trained to integrate paired code and natural queries into a unified space, enhancing reasoning and context-dependent insights about code vulnerability. To evaluate our model performance, we construct a curated dataset of real-world vulnerabilities paired with security-focused questions and answers. Our model outperforms state-of-the-art general-purpose and code LLMs in the QA and detection tasks. We further explain decision-making by conducting qualitative analysis to highlight capabilities and limitations. By integrating code and QA, LLaVul enables more interpretable and security-focused code understanding.
title LLaVul: A Multimodal LLM for Interpretable Vulnerability Reasoning about Source Code
topic Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2509.17337