TY - GEN
T1 - GraphCodeBERT-Augmented Graph Attention Networks for Code Vulnerability Detection
AU - Rangapuram, Deekshith Sagar
AU - Ratha, Nalini
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Detecting software vulnerabilities is critical for the security of modern complex software systems. However, it is challenging due to the complexity of codebases and limitations in existing methods. Traditional approaches often struggle to capture both semantic and structural dependencies effectively. To represent code semantics comprehensively, this paper presents a novel framework integrating Graph Attention Networks (GATs) with Code Property Graphs (CPGs), which unify Abstract Syntax Trees (ASTs), Control Flow Graphs (CFGs), and Program Dependency Graphs (PDGs). Node embeddings are initialized using pretrained GraphCodeBERT, enhanced with multi-head attention layers, residual connections, and global attention pooling. GANbased data augmentation is employed to address the class imbalance, improving model robustness. Our extensive experimental evaluations demonstrate a detection accuracy of 88.5 percent, surpassing state-of-the-art baselines such as CodeBERT and GraphCodeBERT across multiple evaluation metrics, including precision, recall, and F1-score. Furthermore, interpretable attention mechanisms enable the prioritization of critical code regions, ensuring practical applicability. This work establishes a scalable and explainable AI-driven approach for vulnerability detection.
AB - Detecting software vulnerabilities is critical for the security of modern complex software systems. However, it is challenging due to the complexity of codebases and limitations in existing methods. Traditional approaches often struggle to capture both semantic and structural dependencies effectively. To represent code semantics comprehensively, this paper presents a novel framework integrating Graph Attention Networks (GATs) with Code Property Graphs (CPGs), which unify Abstract Syntax Trees (ASTs), Control Flow Graphs (CFGs), and Program Dependency Graphs (PDGs). Node embeddings are initialized using pretrained GraphCodeBERT, enhanced with multi-head attention layers, residual connections, and global attention pooling. GANbased data augmentation is employed to address the class imbalance, improving model robustness. Our extensive experimental evaluations demonstrate a detection accuracy of 88.5 percent, surpassing state-of-the-art baselines such as CodeBERT and GraphCodeBERT across multiple evaluation metrics, including precision, recall, and F1-score. Furthermore, interpretable attention mechanisms enable the prioritization of critical code regions, ensuring practical applicability. This work establishes a scalable and explainable AI-driven approach for vulnerability detection.
KW - code property graph
KW - deep learning
KW - explainable AI
KW - graph attention network
KW - graph neural network
KW - GraphCodeBERT
KW - software vulnerability detection
UR - https://www.scopus.com/pages/publications/105011259580
U2 - 10.1109/CAI64502.2025.00161
DO - 10.1109/CAI64502.2025.00161
M3 - Conference contribution
AN - SCOPUS:105011259580
T3 - Proceedings - 2025 IEEE Conference on Artificial Intelligence, CAI 2025
SP - 912
EP - 917
BT - Proceedings - 2025 IEEE Conference on Artificial Intelligence, CAI 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 3rd IEEE Conference on Artificial Intelligence, CAI 2025
Y2 - 5 May 2025 through 7 May 2025
ER -