Distinguishing Look-Alike Innocent and Vulnerable Code by Subtle Semantic Representation Learning and Explanation
Abstract
Though many deep learning (DL)-based vulnerability detection approaches have been proposed and indeed achieved remarkable performance, they still have limitations in the generalization as well as the practical usage. More precisely, existing DL-based approaches (1) perform negatively on prediction tasks among functions that are lexically similar but have contrary semantics; (2) provide no intuitive developer-oriented explanations to the detected results.
BibTeX
@inproceedings{Ni-al:FSE23,
author = {Chao Ni and
Xin Yin and
Kaiwen Yang and
Dehai Zhao and
Zhenchang Xing and
Xin Xia},
title = {Distinguishing {Look-Alike} Innocent and Vulnerable Code by Subtle Semantic Representation Learning and Explanation},
booktitle = {{ESEC/SIGSOFT} {FSE}},
pages = {1611--1622},
publisher = {{ACM}},
year = {2023},
}