DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tang, Wenxin, Li, Wenbin, Liu, Junliang, Xiao, Jingyu, Xiao, Xi, Liu, Mingzhe, Yang, Jinlong, Liu, Xuan, Ma, Yuehe, Luo, Wang, Li, Qing, Wang, Lei, Xiangli, Peng
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913113396215808
author Tang, Wenxin
Li, Wenbin
Liu, Junliang
Xiao, Jingyu
Xiao, Xi
Liu, Mingzhe
Yang, Jinlong
Liu, Xuan
Ma, Yuehe
Luo, Wang
Li, Qing
Wang, Lei
Xiangli, Peng
author_facet Tang, Wenxin
Li, Wenbin
Liu, Junliang
Xiao, Jingyu
Xiao, Xi
Liu, Mingzhe
Yang, Jinlong
Liu, Xuan
Ma, Yuehe
Luo, Wang
Li, Qing
Wang, Lei
Xiangli, Peng
contents Software vulnerability detection plays a critical role in ensuring system security, where real-world auditing requires not only determining whether a function is vulnerable but also pinpointing the specific lines responsible. However, existing approaches either rely on a single information source -- sequential, structural, or semantic -- failing to jointly exploit the complementary strengths across modalities, or treat statement-level localization merely as a byproduct of function-level detection without explicit line-level supervision. To address these limitations, we propose DCVD (Dual-Channel Cross-Modal Vulnerability Detection), a unified framework that performs joint function-level detection and statement-level localization. DCVD extracts control-dependency and semantic features through two parallel branches and integrates them via contrastive alignment coupled with bidirectional cross-attention, effectively bridging the cross-modal representation gap. It further introduces explicit supervision signals at both the function and statement levels, enabling collaborative optimization across the two granularities. Extensive experiments on a large-scale real-world vulnerability benchmark demonstrate that DCVD consistently outperforms state-of-the-art methods on both function-level detection and statement-level localization. Our code is available at https://github.com/vinsontang1/DCVD.
format Preprint
id arxiv_https___arxiv_org_abs_2605_11015
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization
Tang, Wenxin
Li, Wenbin
Liu, Junliang
Xiao, Jingyu
Xiao, Xi
Liu, Mingzhe
Yang, Jinlong
Liu, Xuan
Ma, Yuehe
Luo, Wang
Li, Qing
Wang, Lei
Xiangli, Peng
Cryptography and Security
Artificial Intelligence
Software vulnerability detection plays a critical role in ensuring system security, where real-world auditing requires not only determining whether a function is vulnerable but also pinpointing the specific lines responsible. However, existing approaches either rely on a single information source -- sequential, structural, or semantic -- failing to jointly exploit the complementary strengths across modalities, or treat statement-level localization merely as a byproduct of function-level detection without explicit line-level supervision. To address these limitations, we propose DCVD (Dual-Channel Cross-Modal Vulnerability Detection), a unified framework that performs joint function-level detection and statement-level localization. DCVD extracts control-dependency and semantic features through two parallel branches and integrates them via contrastive alignment coupled with bidirectional cross-attention, effectively bridging the cross-modal representation gap. It further introduces explicit supervision signals at both the function and statement levels, enabling collaborative optimization across the two granularities. Extensive experiments on a large-scale real-world vulnerability benchmark demonstrate that DCVD consistently outperforms state-of-the-art methods on both function-level detection and statement-level localization. Our code is available at https://github.com/vinsontang1/DCVD.
title DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2605.11015