DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866913113396215808 |
|---|---|
| author | Tang, Wenxin Li, Wenbin Liu, Junliang Xiao, Jingyu Xiao, Xi Liu, Mingzhe Yang, Jinlong Liu, Xuan Ma, Yuehe Luo, Wang Li, Qing Wang, Lei Xiangli, Peng |
| author_facet | Tang, Wenxin Li, Wenbin Liu, Junliang Xiao, Jingyu Xiao, Xi Liu, Mingzhe Yang, Jinlong Liu, Xuan Ma, Yuehe Luo, Wang Li, Qing Wang, Lei Xiangli, Peng |
| contents | Software vulnerability detection plays a critical role in ensuring system security, where real-world auditing requires not only determining whether a function is vulnerable but also pinpointing the specific lines responsible. However, existing approaches either rely on a single information source -- sequential, structural, or semantic -- failing to jointly exploit the complementary strengths across modalities, or treat statement-level localization merely as a byproduct of function-level detection without explicit line-level supervision. To address these limitations, we propose DCVD (Dual-Channel Cross-Modal Vulnerability Detection), a unified framework that performs joint function-level detection and statement-level localization. DCVD extracts control-dependency and semantic features through two parallel branches and integrates them via contrastive alignment coupled with bidirectional cross-attention, effectively bridging the cross-modal representation gap. It further introduces explicit supervision signals at both the function and statement levels, enabling collaborative optimization across the two granularities. Extensive experiments on a large-scale real-world vulnerability benchmark demonstrate that DCVD consistently outperforms state-of-the-art methods on both function-level detection and statement-level localization. Our code is available at https://github.com/vinsontang1/DCVD. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2605_11015 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization Tang, Wenxin Li, Wenbin Liu, Junliang Xiao, Jingyu Xiao, Xi Liu, Mingzhe Yang, Jinlong Liu, Xuan Ma, Yuehe Luo, Wang Li, Qing Wang, Lei Xiangli, Peng Cryptography and Security Artificial Intelligence Software vulnerability detection plays a critical role in ensuring system security, where real-world auditing requires not only determining whether a function is vulnerable but also pinpointing the specific lines responsible. However, existing approaches either rely on a single information source -- sequential, structural, or semantic -- failing to jointly exploit the complementary strengths across modalities, or treat statement-level localization merely as a byproduct of function-level detection without explicit line-level supervision. To address these limitations, we propose DCVD (Dual-Channel Cross-Modal Vulnerability Detection), a unified framework that performs joint function-level detection and statement-level localization. DCVD extracts control-dependency and semantic features through two parallel branches and integrates them via contrastive alignment coupled with bidirectional cross-attention, effectively bridging the cross-modal representation gap. It further introduces explicit supervision signals at both the function and statement levels, enabling collaborative optimization across the two granularities. Extensive experiments on a large-scale real-world vulnerability benchmark demonstrate that DCVD consistently outperforms state-of-the-art methods on both function-level detection and statement-level localization. Our code is available at https://github.com/vinsontang1/DCVD. |
| title | DCVD: Dual-Channel Cross-Modal Fusion for Joint Vulnerability Detection and Localization |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2605.11015 |