节点文献
基于多特征融合的源代码函数级漏洞检测
Function-Level Source Code Vulnerability Detection Based on Multi-feature Fusion
【作者】 王曦;
【作者基本信息】 东南大学 , 网络与信息安全(专业学位), 2025, 硕士
【摘要】 软件漏洞对用户隐私、数据资产乃至关键信息基础设施构成直接威胁。作为软件安全的源头防线,源代码漏洞检测能够在开发早期识别逻辑缺陷,以低成本阻断漏洞扩散风险。对于C/C++等系统级语言,其底层操作特性使其成为高危漏洞的主要载体。这类语言广泛应用于操作系统、工业控制等领域,代码中的缓冲区溢出、内存泄漏等漏洞一旦被利用,极易引发系统崩溃或权限劫持,直接威胁关键基础设施安全。近年来,C/C++代码漏洞检测研究逐渐从文件级转向函数级,因漏洞多存在于特定函数内的代码模式或逻辑缺陷,且函数级检测可降低数据处理复杂度,便于模型训练与验证,正成为研究的重点方向。尽管深度学习技术有效提升了漏洞检测效率,但现有模型在代码特征处理上存在局限性:基于文本序列的方法难以捕捉代码结构特征,而基于图神经网络的方法普遍忽略变量语义及上下文关联。此外,现有模型的特征融合策略往往难以捕捉不同特征间的复杂交互关系,且普遍面临模型鲁棒性不足的瓶颈。为解决上述问题,本文提出基于语义特征和结构特征融合的源代码函数级漏洞检测模型,通过源代码多特征动态交互建模与对抗训练优化,完成C/C++函数级漏洞的高精度检测。本文主要研究工作与成果包括:(1)为全面表征代码的语义与结构特征以提升漏洞检测准确率,提出了基于Code-BERT和GAT的源代码漏洞检测模型CBG-VulDet。该模型通过Code BERT提取代码函数的语义特征;借助Joern构建代码属性图并利用GAT提取结构特征;采用门控融合策略进行特征融合。实验选取Graph Code BERT、Code T5及多种预训练模型与图神经网络的组合作为基线模型,在本文构建的GMVul2025数据集上开展对比实验。实验结果表明,该模型相较于基线模型在数据集上取得了更高的准确率和F1分数,验证了CBG-VulDet漏洞检测模型的有效性。(2)针对CBG-VulDet模型中门控融合策略对特征复杂交互捕捉不足及模型鲁棒性不足的局限,设计了基于交叉注意力机制与对抗训练协同优化的源代码漏洞检测模型CAAT-VulDet。该模型在CBG-VulDet的基础上,引入交叉注意力机制完成语义特征和结构特征深度交互融合;同时引入对抗训练,设计了面向代码语义特征与结构特征的对抗样本生成方法,通过联合扰动策略增强模型对噪声数据的鲁棒性。实验结果表明,该模型在测试集上的准确率和F1分数优于Code T5+、Deep Wukong、Vul-LMGNN等基线模型,准确率较基线模型提高了2%-7%,漏检率和误检率分别降低至13.23%和17.46%,从而验证了本文模型有效提升了漏洞检测的准确率并增强了模型的鲁棒性。(3)以CAAT-VulDet漏洞检测模型为核心,设计并完成了一个C/C++源代码函数级漏洞检测系统。该系统采用用户友好型界面设计,集成源代码文件上传、检测结果可视化、文件管理等功能模块。本文工作的主要特色有:(1)在源代码漏洞检测任务中,使用Code BERT对源代码函数进行语义特征提取,使用GAT对源代码属性图进行结构特征提取。(2)使用交叉注意力机制及门控融合策略将语义特征和结构特征进行有效融合。(3)引入对抗训练机制,提出了一种面向代码语义与结构特征的对抗样本生成方法,通过联合扰动策略增强模型的鲁棒性。
【Abstract】 Software vulnerabilities pose direct threats to user privacy,data assets,and even critical information infrastructure.As the primary defense for software security,source code vulnerability detection can identify logical flaws in the early development stage and block the risk of vulnerability spread at a low cost.For system-level languages such as C/C++,their low-level operation characteristics make them the main carriers of high-risk vulnerabilities.These languages are widely used in operating systems,industrial control,and other fields.Once vulnerabilities such as buffer overflows and memory leaks in the code are exploited,they can easily lead to system crashes or privilege hijacking,directly threatening the security of critical infrastructure.In recent years,research on C/C++ code vulnerability detection has gradually shifted from the file-level to the function-level.Since most vulnerabilities exist in code patterns or logical flaws within specific functions,and function-level detection can reduce the complexity of data processing,facilitating model training and validation,it has become a key research direction.Although deep learning techniques have effectively improved the efficiency of vulnerability detection,existing models have limitations in code feature processing.Text-sequence-based methods struggle to capture code structure features,while graph-neural-network-based methods generally ignore variable semantics and context associations.In addition,the feature fusion strategies of existing models often fail to capture the complex interaction relationships between different features,and they generally face the bottleneck of insufficient model robustness.To address these issues,this paper proposes a source code function-level vulnerability detection model based on the fusion of semantic and structural features.Through the dynamic interaction modeling of multiple features of the source code and adversarial training optimization,high-precision detection of C/C++ function-level vulnerabilities is achieved.The main research work and results of this paper include:(1)To comprehensively represent the semantic and structural features of the code and improve the accuracy of vulnerability detection,a source code vulnerability detection model named CBG-VulDet based on Code BERT and GAT is proposed.This model extracts the semantic features of code functions through Code BERT,constructs a code property graph with Joern and extracts structural features using GAT,and adopts a gated fusion strategy for feature fusion.In the experiments,combinations of Graph Code BERT,Code T5,and various pre-trained models and graph neural networks are selected as baseline models,and comparative experiments are conducted on the GMVul2025 dataset constructed in this paper.The experimental results show that this model achieves higher accuracy and F1 scores on the dataset compared with the baseline models,verifying the effectiveness of the CBG-VulDet vulnerability detection model.(2)Aiming at the limitations of the gated fusion strategy in the CBG-VulDet model,such as the insufficient capture of complex feature interactions and the lack of model robustness,a source code vulnerability detection model named CAAT-VulDet based on the collaborative optimization of cross-attention mechanism and adversarial training is designed.On the basis of CBG-VulDet,this model introduces a cross-attention mechanism to achieve in-depth interactive fusion of semantic and structural features.At the same time,adversarial training is introduced,and a method for generating adversarial samples for code semantic and structural features is designed.The robustness of the model to noisy data is enhanced through a joint perturbation strategy.The experimental results show that the accuracy and F1 scores of this model on the test set are better than those of baseline models such as Code T5+,Deep Wukong,and Vul-LMGNN.The accuracy is improved by 2%-7% compared with the baseline models,and the missed-detection rate and false-detection rate are reduced to 13.23% and 17.46%respectively,thus verifying that the model in this paper effectively improves the accuracy of vulnerability detection and enhances the robustness of the model.(3)Centered on the CAAT-VulDet vulnerability detection model,a C/C++ source code function-level vulnerability detection system is designed and completed.This system features a user-friendly interface design and integrates functional modules such as source code file upload,visualization of detection results,and file management.The main features of the work in this paper are as follows:(1)In the source code vulnerability detection task,Code BERT is used to extract the semantic features of source code functions,and GAT is used to extract the structural features of the source code property graph.(2)The cross-attention mechanism and gated fusion strategy are used to effectively fuse semantic and structural features.(3)An adversarial training mechanism is introduced,and a method for generating adversarial samples for code semantic and structural features is proposed.The robustness of the model is enhanced through a joint perturbation strategy.
【Key words】 Vulnerability Detection; Deep Learning; Feature Fusion; Attention Mechanism; Adversarial Training;
- 【网络出版投稿人】 东南大学 【网络出版年期】2026年 07期
- 【分类号】TP309;TP311.5