Bridging Semantics & Structure for Software Vulnerability Detection using Hybrid Network Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Gajjar, Jugal, Ranaware, Kaustik, Subramaniakuppusamy, Kamalasankari
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914089415999488
author Gajjar, Jugal
Ranaware, Kaustik
Subramaniakuppusamy, Kamalasankari
author_facet Gajjar, Jugal
Ranaware, Kaustik
Subramaniakuppusamy, Kamalasankari
contents Software vulnerabilities remain a persistent risk, yet static and dynamic analyses often overlook structural dependencies that shape insecure behaviors. Viewing programs as heterogeneous graphs, we capture control- and data-flow relations as complex interaction networks. Our hybrid framework combines these graph representations with light-weight (<4B) local LLMs, uniting topological features with semantic reasoning while avoiding the cost and privacy concerns of large cloud models. Evaluated on Java vulnerability detection (binary classification), our method achieves 93.57% accuracy-an 8.36% gain over Graph Attention Network-based embeddings and 17.81% over pretrained LLM baselines such as Qwen2.5 Coder 3B. Beyond accuracy, the approach extracts salient subgraphs and generates natural language explanations, improving interpretability for developers. These results pave the way for scalable, explainable, and locally deployable tools that can shift vulnerability analysis from purely syntactic checks to deeper structural and semantic insights, facilitating broader adoption in real-world secure software development.
format Preprint
id arxiv_https___arxiv_org_abs_2510_10321
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Bridging Semantics & Structure for Software Vulnerability Detection using Hybrid Network Models
Gajjar, Jugal
Ranaware, Kaustik
Subramaniakuppusamy, Kamalasankari
Software Engineering
Artificial Intelligence
Cryptography and Security
Software vulnerabilities remain a persistent risk, yet static and dynamic analyses often overlook structural dependencies that shape insecure behaviors. Viewing programs as heterogeneous graphs, we capture control- and data-flow relations as complex interaction networks. Our hybrid framework combines these graph representations with light-weight (<4B) local LLMs, uniting topological features with semantic reasoning while avoiding the cost and privacy concerns of large cloud models. Evaluated on Java vulnerability detection (binary classification), our method achieves 93.57% accuracy-an 8.36% gain over Graph Attention Network-based embeddings and 17.81% over pretrained LLM baselines such as Qwen2.5 Coder 3B. Beyond accuracy, the approach extracts salient subgraphs and generates natural language explanations, improving interpretability for developers. These results pave the way for scalable, explainable, and locally deployable tools that can shift vulnerability analysis from purely syntactic checks to deeper structural and semantic insights, facilitating broader adoption in real-world secure software development.
title Bridging Semantics & Structure for Software Vulnerability Detection using Hybrid Network Models
topic Software Engineering
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2510.10321