NatGVD: Natural Adversarial Example Attack towards Graph-based Vulnerability Detection

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Rath, Avilash, Qi, Weiliang, Li, Youpeng, Wang, Xinda
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866918155144658944
author Rath, Avilash
Qi, Weiliang
Li, Youpeng
Wang, Xinda
author_facet Rath, Avilash
Qi, Weiliang
Li, Youpeng
Wang, Xinda
contents Graph-based models learn rich code graph structural information and present superior performance on various code analysis tasks. However, the robustness of these models against adversarial example attacks in the context of vulnerability detection remains an open question. This paper proposes NatGVD, a novel attack methodology that generates natural adversarial vulnerable code to circumvent GNN-based and graph-aware transformer-based vulnerability detectors. NatGVD employs a set of code transformations that modify graph structure while preserving code semantics. Instead of injecting dead or unrelated code like previous works, NatGVD considers naturalness requirements: generated examples should not be easily recognized by humans or program analysis tools. With extensive evaluation of NatGVD on state-of-the-art vulnerability detection systems, the results reveal up to 53.04% evasion rate across GNN-based detectors and graph-aware transformer-based detectors. We also explore potential defense strategies to enhance the robustness of these systems against NatGVD.
format Preprint
id arxiv_https___arxiv_org_abs_2510_04987
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle NatGVD: Natural Adversarial Example Attack towards Graph-based Vulnerability Detection
Rath, Avilash
Qi, Weiliang
Li, Youpeng
Wang, Xinda
Cryptography and Security
I.2
Graph-based models learn rich code graph structural information and present superior performance on various code analysis tasks. However, the robustness of these models against adversarial example attacks in the context of vulnerability detection remains an open question. This paper proposes NatGVD, a novel attack methodology that generates natural adversarial vulnerable code to circumvent GNN-based and graph-aware transformer-based vulnerability detectors. NatGVD employs a set of code transformations that modify graph structure while preserving code semantics. Instead of injecting dead or unrelated code like previous works, NatGVD considers naturalness requirements: generated examples should not be easily recognized by humans or program analysis tools. With extensive evaluation of NatGVD on state-of-the-art vulnerability detection systems, the results reveal up to 53.04% evasion rate across GNN-based detectors and graph-aware transformer-based detectors. We also explore potential defense strategies to enhance the robustness of these systems against NatGVD.
title NatGVD: Natural Adversarial Example Attack towards Graph-based Vulnerability Detection
topic Cryptography and Security
I.2
url https://arxiv.org/abs/2510.04987