The Vulnerability Is in the Details: Locating Fine-grained Information of Vulnerable Code Identified by Graph-based Detectors

Baijun Cheng,Kailong Wang,Cuiyun Gao,Xiapu Luo,Yulei Sui,Li Li,Yao Guo,Xiangqun Chen,Haoyu Wang
2024-02-21
Abstract:Vulnerability detection is a crucial component in the software development lifecycle. Existing vulnerability detectors, especially those based on deep learning (DL) models, have achieved high effectiveness. Despite their capability of detecting vulnerable code snippets from given code fragments, the detectors are typically unable to further locate the fine-grained information pertaining to the vulnerability, such as the precise vulnerability triggering
Software Engineering
What problem does this paper attempt to address?