亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

VulExplainer: A Transformer-Based Hierarchical Distillation for Explaining Vulnerability Types

计算机科学 软件 又称作 机器学习 脆弱性(计算) 人工智能 变压器 数据挖掘 计算机安全 程序设计语言 工程类 电气工程 图书馆学 电压
作者
Michael C. Fu,Van Nguyen,Chakkrit Tantithamthavorn,Trung Le,Dinh Phung
出处
期刊:IEEE Transactions on Software Engineering [IEEE Computer Society]
卷期号:49 (10): 4550-4565 被引量:16
标识
DOI:10.1109/tse.2023.3305244
摘要

Deep learning-based vulnerability prediction approaches are proposed to help under-resourced security practitioners to detect vulnerable functions. However, security practitioners still do not know what type of vulnerabilities correspond to a given prediction (aka CWE-ID). Thus, a novel approach to explain the type of vulnerabilities for a given prediction is imperative. In this paper, we propose VulExplainer , an approach to explain the type of vulnerabilities. We represent VulExplainer as a vulnerability classification task. However, vulnerabilities have diverse characteristics (i.e., CWE-IDs) and the number of labeled samples in each CWE-ID is highly imbalanced (known as a highly imbalanced multi-class classification problem), which often lead to inaccurate predictions. Thus, we introduce a Transformer-based hierarchical distillation for software vulnerability classification in order to address the highly imbalanced types of software vulnerabilities. Specifically, we split a complex label distribution into sub-distributions based on CWE abstract types (i.e., categorizations that group similar CWE-IDs). Thus, similar CWE-IDs can be grouped and each group will have a more balanced label distribution. We learn TextCNN teachers on each of the simplified distributions respectively, however, they only perform well in their group. Thus, we build a transformer student model to generalize the performance of TextCNN teachers through our hierarchical knowledge distillation framework. Through an extensive evaluation using the real-world 8,636 vulnerabilities, our approach outperforms all of the baselines by 5%–29%. The results also demonstrate that our approach can be applied to Transformer-based architectures such as CodeBERT, GraphCodeBERT, and CodeGPT. Moreover, our method maintains compatibility with any Transformer-based model without requiring any architectural modifications but only adds a special distillation token to the input. These results highlight our significant contributions towards the fundamental and practical problem of explaining software vulnerability.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
朴素的语兰完成签到,获得积分10
3秒前
默默无闻完成签到 ,获得积分10
52秒前
酷酷的雨完成签到,获得积分10
1分钟前
j7完成签到,获得积分10
1分钟前
malen111完成签到 ,获得积分10
1分钟前
1分钟前
verymiao完成签到 ,获得积分10
1分钟前
葵花宝典发布了新的文献求助10
1分钟前
儒雅的月光完成签到,获得积分10
1分钟前
Lifel完成签到 ,获得积分10
1分钟前
大模型应助葵花宝典采纳,获得10
2分钟前
yue应助Sandy采纳,获得20
2分钟前
2分钟前
TadeoEB完成签到,获得积分10
2分钟前
Ava应助科研通管家采纳,获得10
3分钟前
赘婿应助科研通管家采纳,获得10
3分钟前
生动盼兰完成签到,获得积分10
3分钟前
SiboN发布了新的文献求助10
3分钟前
MingH应助Sandy采纳,获得10
3分钟前
3分钟前
DarknessDuck发布了新的文献求助10
3分钟前
美丽的沛菡完成签到,获得积分10
3分钟前
DarknessDuck完成签到,获得积分20
3分钟前
Owen应助DarknessDuck采纳,获得10
3分钟前
科研通AI6.3应助白告采纳,获得10
4分钟前
可爱的新儿完成签到,获得积分10
4分钟前
外向的妍完成签到,获得积分10
5分钟前
5分钟前
5分钟前
脑洞疼应助科研通管家采纳,获得10
5分钟前
5分钟前
负责的如萱完成签到,获得积分10
5分钟前
白告发布了新的文献求助10
5分钟前
沿途有你完成签到 ,获得积分10
5分钟前
ChenW.完成签到,获得积分10
6分钟前
风趣手链完成签到,获得积分10
6分钟前
冷傲的怜寒完成签到,获得积分10
6分钟前
wanci应助风趣手链采纳,获得10
6分钟前
7分钟前
小蘑菇应助汤姆采纳,获得10
7分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
The Cambridge History of China: Volume 4, Sui and T'ang China, 589–906 AD, Part Two 1500
Cowries - A Guide to the Gastropod Family Cypraeidae 1200
Quality by Design - An Indispensable Approach to Accelerate Biopharmaceutical Product Development 800
Signals, Systems, and Signal Processing 610
Research Methods for Applied Linguistics 500
A Social and Cultural History of the Hellenistic World 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6394582
求助须知:如何正确求助?哪些是违规求助? 8209702
关于积分的说明 17382316
捐赠科研通 5447800
什么是DOI,文献DOI怎么找? 2880027
邀请新用户注册赠送积分活动 1856542
关于科研通互助平台的介绍 1699160