A General Defect Detection Method Based on Graph Neural Networks
Through the method based on graph neural network learning defect features, constructing program semantic infographics and using gated graph neural network models, the problem of requiring a large amount of training data in the prior art is solved, and effective detection and prediction of defect types not in the training set is achieved.
Patent Information
- Application Number
- CN202210167928.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-23
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-02-23
AI Technical Summary
Existing machine learning-based defect prediction methods require a large number of training data to learn defect features, and cannot effectively predict defect types that are not in the training set.
The method based on graph neural network is used to learn defect features. By constructing program semantic infographics and using gated graph neural network models, the node weight mechanism is introduced to pay attention to defect-related codes, reduce the impact of irrelevant codes, and define a defect prediction method based on graph neural networks for general defect detection loss function and distance ranking.
The amount of training data required by the model is reduced, the ability to detect defect types not in the training set is improved, and the generalization ability and prediction efficiency of the model are enhanced.
Smart Images

Figure CN114489785B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to defect detection technology in the field of software engineering, and specifically to a general defect detection method based on graph neural network Background Art
[0002] Defect detection is one of the important methods to ensure software quality, and static analysis is the most commonly used defect detection means at present. Static analysis methods need to accurately model defects, but due to the complex causes of defects, it is difficult for static analysis methods to effectively solve the problems of false positives and false negatives; the scalability of static analysis methods is relatively low, and it is often difficult to meet the performance requirements such as specified time and memory consumption when facing large-scale programs. Due to the complex defect features, existing methods for defect prediction based on machine learning require a large amount of training data to learn defect features and cannot handle defect types not in the training set. At the same time, the more complex the defect features are, the more data sets the model needs to learn. Therefore, reducing the complexity of defect features can reduce the difficulty of model learning; defective code usually only accounts for a small part of the function where it is located. If the model can focus on the code related to defects and weaken the irrelevant code, the ability of the model can be improved, the learning cost can be reduced, and the amount of training set data can be reduced; although defects are not the same, there are some commonalities between different defects. By borrowing the idea of anomaly detection in static defect detection, the commonalities between defects can be found, enabling the model to detect defect types not in the training set
[0003] The present invention proposes a method based on graph neural network to learn defect features. Compared with using the Bert model based on transformer to learn the pure text information of programs, graph neural network can learn more semantic information. At the same time, the present invention adopts a variety of optimization methods to reduce the number of training sets required by the model, and proposes a new loss function and defect prediction method, enabling the model to be unrestricted by defect types and detect defect types not in the training set Summary of the Invention
[0004] The present invention proposes a general defect detection method based on graph neural network, which can solve the problem that the current defect prediction methods based on machine learning require a large amount of training data to learn defect features and cannot predict defect types not in the training set
[0005] To solve the above technical problems, the present invention is realized through the following technical solutions: A general defect detection method based on graph neural network, comprising the following steps
[0006] Step 1, program preprocessing. Taking the program source code as input, construct an inter-procedural program semantic information graph based on static analysis. On this basis, extract the semantic feature values of the nodes of the program semantic information graph, and vectorize the graphical representation to generate the vector representation required by the model
[0007] Step 2: Build a general defect prediction model based on graph neural network. Based on the defect report of the benchmark program, label the defect sample distribution with labels on the program vector representation. Use the labeled benchmark program vector representation as input to train the defect prediction ability of the graph neural network. Use the optimal model in the training process as the general defect detection model.
[0008] Step 3: Use the general defect detection model to predict the program to be tested. The user defines the target defect type and selects the samples to be tested that contain sensitive operations corresponding to the specific defect type as input; load the general defect detection model to generate the feature vector of the sample to be tested, and make predictions based on the defect prediction method based on the distance ranking. Output the prediction results for specific defects, manually confirm the prediction results, add labels to the program to be tested, and use the model for learning to enhance the model's prediction capabilities.
[0009] The above-mentioned universal defect detection method based on graph neural network is characterized in that the program preprocessing in step 1 includes:
[0010] Generate a statement-level program dependency graph corresponding to the program source code, with each statement in the program as a node and data dependency and control dependency as two types of edges;
[0011] Expand the nodes in the program dependency graph through the abstract syntax tree. That is, each node in the program dependency graph is the root node of an abstract syntax tree. After expansion, a new graph is formed. The graph contains two types of nodes: program dependency graph nodes and abstract syntax tree nodes, and three types of edges: data dependency edges, control dependency edges, and abstract syntax tree edges.
[0012] Keep the control dependency edges at the statement level unchanged, and move the data dependency edges at the statement level down to the leaf nodes of the abstract syntax tree to form data dependency edges at the variable level;
[0013] During the preprocessing of the benchmark program, for defective programs, extract the complete function call chain that causes the defect; for correct programs, extract the complete function call chain that can prove the correctness of the program; connect the program semantic information graph of all functions in the call chain using data dependency edges and control dependency edges;
[0014] During the preprocessing of the program to be tested, each function is a sample to be tested. For each sample to be tested, its upper and lower calling functions are used as its context, and the corresponding program semantic information graphs are connected using the function context connection method of the program semantic information graph;
[0015] Add a meta-node to the graph and a new edge that connects the meta-node to every node in the graph. This node is used by the model to calculate the weights of other nodes.
[0016] · The nodes in the graph are transformed into one-dimensional state vectors. The size of the vector is the number of nodes in the graph, and each element in the vector takes an integer value representing the statement type of the node.
[0017] · The edges in the graph are transformed into triples consisting of a source node, an edge type, and a target node. The nodes are numbered with consecutive integers starting from 0, and the edge types are numbered with consecutive integers starting from 1.
[0018] The above-mentioned general defect detection method based on graph neural network is characterized in that the construction of the general defect prediction model based on gated graph neural network in the second step includes:
[0019] · Add labels to the program vector representation according to the defect reports of the benchmark programs to mark the distribution of defect samples. Add label 0 to correct samples and label 1 to defect samples.
[0020] · Based on the gated graph neural network, introduce a node weight mechanism. Define meta-nodes that connect all nodes in the graph. The meta-nodes are used to learn the weights of other nodes and attach this weight to the information of each node during the information passing process of the graph neural network, so that the model can strengthen key nodes and weaken irrelevant nodes.
[0021] · The graph neural network generates the feature vectors of each sample through multiple rounds of iteration. Map the feature vectors of each sample into a coordinate system and use the Euclidean distance to represent the distance between two sample points. This distance represents the similarity between samples. Through the defined loss function of the general defect prediction model based on graph neural network, the distance between all correct samples is minimized, and the distance between all defect samples and correct samples is greater than the distance threshold, enabling the model to acquire the ability to distinguish correct samples and defect samples. Save the model with the lowest loss in multiple rounds of iteration as the optimal model, which is used as the general defect detection model in the defect prediction stage.
[0022] · Train the benchmark programs of different defect types separately to improve the generalization ability of the model.
[0023] The above-mentioned general defect detection method based on graph neural network is characterized in that the prediction of the program to be tested using the general defect detection model in the third step includes:
[0024] · The user defines the defect type to be predicted and filters the samples to be tested that contain sensitive operations corresponding to the defect. For example, for the null pointer dereference defect, filter the samples to be tested that contain dereference operations; for the array out-of-bounds defect, filter the samples to be tested that contain array operations. If there is no specific defect, use all samples to be tested as input.
[0025] · Load the general defect prediction model, use the vector representation of the sample to be tested as the input, calculate the sample feature vector through the model, map the feature vector into the coordinate system, and calculate the distance from all samples to the center point of the sample set;
[0026] · Define a threshold M, that is, the M samples with the farthest distance are the defect samples, and report the prediction result;
[0027] · Manually confirm the model prediction result, add labels to the samples to be tested, and use the samples to be tested with added labels as training data to improve the model prediction ability.
[0028] The above general defect detection method based on the graph neural network is characterized in that the function context connection method for defining the program semantic information graph in step one includes:
[0029] · Use control dependence edges to connect the function call statement of the calling function and the entry node of the corresponding called function;
[0030] · Use control dependence edges to connect the exit node of the called function and the function call statement of the calling function;
[0031] · Use data dependence edges to connect the actual parameters of the calling function and the formal parameters of the called function;
[0032] · If the called function has a return value, use data dependence edges to connect the return value of the called function and the variable that receives the return value in the calling function;
[0033] By adopting the above technical solutions, the present invention can obtain the following beneficial effects:
[0034] 1. A method for constructing an inter-procedural program semantic information graph is proposed, which includes program data dependence information, control dependence information, and abstract syntax tree information, so that the graphical representation can efficiently and accurately express program semantic information;
[0035] 2. A method for extracting and vectorizing program source code features based on semantics is proposed. According to the semantic information contained in the nodes of the program semantic information graph, it is transformed into a vector representation, so that there is no information loss during the transformation of the graphical representation into a vector representation;
[0036] 3. A general defect detection model based on the gated graph neural network is proposed, which introduces the concept of node weights, enables the model to focus on defect-related nodes, weakens irrelevant nodes, and improves the efficiency of the model learning program defect semantics;
[0037] 4. Define a general defect detection loss function based on the graph neural network. This loss function can discover the essential differences between correct samples and defect samples in the same type of samples, so that the model is not restricted by the defect type;
[0038] 5. A defect prediction method based on distance ranking is proposed, which enables the model to sort samples according to the essential differences of the samples to be tested. Samples with a ranking exceeding the threshold are defective samples. This method is independent of the defect type, so that the model can predict defect types that are not in the training set;
[0039] 6. The model is trained using multiple defects to discover the commonalities between different defects and enhance the generalization ability of the model. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 This is a framework diagram of a general defect detection method based on graph neural network.
[0041] Figure 2 is a code example.
[0042] Figure 3 is a graphical representation of a code example. DETAILED DESCRIPTION
[0043] In order to enable those skilled in the art to better understand the present invention, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0044] [Example 1]
[0045] like Figure 1 As shown, this embodiment provides a system framework of a general defect detection method based on a graph neural network, including the following steps:
[0046] Step 1: Program preprocessing. Using the program source code as input, we build an inter-procedural program semantic information graph based on static analysis. On this basis, we extract the semantic feature values of the program semantic information graph nodes, vectorize the graph representation, and generate the vector representation required by the model. The specific steps include:
[0047] Generate a statement-level program dependency graph corresponding to the program source code, with each statement in the program as a node and data dependency and control dependency as two types of edges;
[0048] Expand the nodes in the program dependency graph through the abstract syntax tree. That is, each node in the program dependency graph is the root node of an abstract syntax tree. After expansion, a new graph is formed. The graph contains two types of nodes: program dependency graph nodes and abstract syntax tree nodes, and three types of edges: data dependency edges, control dependency edges, and abstract syntax tree edges.
[0049] Keep the control dependency edges at the statement level unchanged, and move the data dependency edges at the statement level down to the leaf nodes of the abstract syntax tree to form data dependency edges at the variable level;
[0050] · During the preprocessing of the benchmark program, for the defective program, extract the complete function call chain that causes the defect; for the correct program, extract the complete function call chain that can prove the program is correct; connect the program semantic information graphs of all functions in the call chain using data dependence edges and control dependence edges; define the function context connection method for the program semantic information graph as follows: use a control dependence edge to connect the function call statement of the calling function and the entry node of the corresponding called function; use a control dependence edge to connect the exit node of the called function and the function call statement of the calling function; use a data dependence edge to connect the actual parameter of the calling function and the formal parameter of the called function; if the called function has a return value, use a data dependence edge to connect the return value of the called function and the variable that receives the return value in the calling function;
[0051] · During the preprocessing of the program under test, each function is a test sample. For each test sample, use its upper and lower two-level calling functions as its context, and use the function context connection method of the program semantic information graph described in step 1.4 to connect the corresponding program semantic information graphs;
[0052] · Add a meta-node to the graph and use a new type of edge to connect the meta-node and all nodes in the graph. This node is used to calculate the weights of other nodes.
[0053] · Create a number for each node in the graph, and represent the edges in the graph as [source node, edge type, target node], where the edge types are represented by 1, 2, 3, and 4 for data dependence edges, control dependence edges, abstract syntax tree edges, and edges from the meta-node to each node, respectively.
[0054] · Use the type value of the node statement to represent the statement feature, forming a feature vector. The length of the feature vector is the same as the number of nodes. The feature value of the meta-node is a random value, and the value of the statement type is shown in Table 1.
[0055] Table 1 Value of statement type
[0056]
[0057]
[0058]
[0059] Step 2: Build a general defect prediction model based on a graph neural network. Based on the defect reports of the benchmark program, mark the distribution of defect samples in the program vector representation. Use the labeled benchmark program vector representation as the input to train the defect prediction ability of the graph neural network, and use the optimal model during the training process as the general defect detection model. The specific steps are as follows:
[0060] · Add labels to the program vector representation according to the defect reports of the benchmark programs to mark the distribution of defect samples. Add label 0 to correct samples and label 1 to defect samples;
[0061] · Build a model based on the gated graph neural network. The gated neural network can solve the long-term dependence problem in the program. Introduce a node weight mechanism to enable the model to strengthen nodes related to defects, weaken irrelevant nodes, and enhance the model's learning ability. Define a meta-node to calculate the weights of each node. Let the initial feature vector of the meta-node be H, and the feature vectors of other nodes be h n , and the node weight be a n , if the number of nodes is |N|, the formula for calculating the node weight is:
[0062] e n = h n ⊙ H
[0063]
[0064] Through this formula, the model can automatically learn the weights of each node during iteration, based on the assumption that in the same type of code, the statements related to defects are the key nodes that distinguish defective programs from correct programs. Therefore, statements related to defects should be assigned higher weights. During the message passing process of the graph neural network, the messages sent by nodes should be multiplied by this weight.
[0065] · Iteratively generate new feature vectors for each node in the program semantic information graph through the graph neural network, and generate the feature vector of this sample through a feedforward neural network.
[0066] · Map the feature vector of the sample to the coordinate system, use the Euclidean distance to measure the similarity between two samples, and make the distance between correct samples approach zero during training, and the distance between correct and defective samples is greater than the threshold. Let P be the set of correct samples and Q be the set of defective samples, be the sample center point, g θ be the graph neural network, ∈ be the distance threshold, and the formula for defining the model loss function is as follows:
[0067]
[0068] When this loss function is 0, it means that the distance between any two correct samples is 0, and the distance between any two correct samples and defective samples is greater than the distance threshold. 2.5: The model when the model loss value is the smallest is the optimal model. 2.6: Repeat steps 2.2 - 3.5, train the model with multiple groups of different types of defect data to improve the model's generalization ability, save the optimal model, and use it as a general defect detection model in the defect prediction stage.
[0069] Step 3: Use the general defect detection model to predict the program to be tested. The user customizes the target defect type, filters the samples to be tested that contain sensitive operations corresponding to the specific defect type as the input; loads the general defect detection model to generate the feature vectors of the samples to be tested, and makes predictions based on the defect prediction method based on distance ranking. Output the prediction results for specific defects, manually confirm the prediction results, add labels to the program to be tested and use the model for learning to enhance the model's prediction ability. The specific steps are as follows:
[0070] · Add labels to the program vector representation according to the defect report of the benchmark program to mark the distribution of defect samples. Add label 0 to the correct samples and label 1 to the defect samples; the user customizes the defect type to be predicted and filters the samples to be tested that contain sensitive operations corresponding to the defect. For example, for the null pointer dereference defect, filter the samples to be tested that contain dereference operations; for the array out-of-bounds defect, filter the samples to be tested that contain array operations. If there is no specific defect, use all samples to be tested as the input;
[0071] · Load the general defect detection model, use the vector representation of the test data as the input, calculate the feature vectors of the samples through the model, map the feature vectors into the coordinate system, calculate the distances from all samples to the center point of the sample set, and rank the samples according to this distance;
[0072] · Propose a defect prediction method based on distance ranking, define the threshold M, that is, the M samples with the farthest distance are defect samples, and report the prediction results;
[0073] · Manually confirm the model prediction results, add labels to the test data, 0 for correct samples and 1 for defect samples, and use the labeled data as training data to improve the model's prediction ability.
[0074] The present invention proposes an inter-procedural program semantic information graph construction method, enabling the graphical representation to efficiently and accurately express program semantic information; proposes a semantic-based program source code feature extraction and vectorization method, ensuring no information loss during the conversion of the graphical representation into a vector representation; proposes a general defect detection model based on gated graph neural networks to improve the model's efficiency in learning program semantics; defines a general defect detection loss function based on graph neural networks, making the model unrestricted by defect types; trains with various types of defects respectively to discover the commonalities between different defects, enabling the model to predict defect types not in the benchmark program; proposes a defect prediction method based on distance ranking, enabling the model to predict defect types not in the training set.
[0075] The above are embodiments of the present invention, but the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Any omissions, modifications, equivalent substitutions, etc. made within the scope of the patent application of the present invention without departing from the principle and spirit of the present invention shall be included within the protection scope of this disclosure.
Claims
1. A general defect detection method based on graph neural network, characterized in that, The steps include: Step 1, program preprocessing; taking the program source code as input, constructing an inter-procedural program semantic information graph based on static analysis, on this basis, extracting the semantic feature values of the program semantic information graph nodes, and vectorizing the graph representation to generate the vector representation required by the model; the program preprocessing includes: generating a statement-level program dependency graph corresponding to the program source code, taking each statement in the program as a node, and taking data dependency and control dependency as two types of edges; expanding the nodes in the program dependency graph through an abstract syntax tree, that is, each node in the program dependency graph is a root node of an abstract syntax tree, and a new graph is formed after expansion, the graph contains two types of nodes, program dependency graph nodes and abstract syntax tree nodes, and contains three types of edges, data dependency edges, control dependency edges and abstract syntax tree edges; keeping the control dependency edges at the statement level unchanged, and moving the data dependency edges at the statement level down to the leaf nodes of the abstract syntax tree to form variable-level data dependency edges; in the preprocessing process of the benchmark program, for defective programs, extract the complete function call chain that causes the defect; for correct programs, extract the complete function call chain that can prove the correctness of the program; connect the program semantic information graphs of all functions in the call chain using data dependency edges and control dependency edges; Step 2: Build a general defect prediction model based on graph neural network. Based on the defect report of the benchmark program, use labels to mark the distribution of defect samples on the program vector representation. Based on the gated graph neural network, use the benchmark program vector representation with labels as input and introduce a node weight mechanism. Define meta nodes, which connect all nodes in the graph. Meta nodes are used to learn the weights of other nodes. In the process of information transmission in the graph neural network, this weight is added to the information of each node, so that the model can strengthen key nodes and weaken irrelevant nodes, train the defect prediction ability of the graph neural network, and use the optimal model in the training process as a general defect detection model. Step three, use the general defect detection model to predict the program under test; the user customizes the target defect type and filters the samples under test that contain sensitive operations corresponding to the specific defect type as input; loads the general defect detection model to generate the feature vector of the sample under test, and makes predictions based on the defect prediction method based on distance ranking; outputs the prediction results for specific defects, manually confirms the prediction results, adds labels to the program under test and uses the model for learning to enhance the model's prediction capabilities.
2. The general defect detection method based on graph neural network according to claim 1, characterized in that The program preprocessing of step 1 also includes: In the preprocessing process of the program to be tested, each function is a sample to be tested; for each sample to be tested, its upper and lower calling functions are used as its context, and the corresponding program semantic information graphs are connected using the function context connection method of the program semantic information graph; Add a meta-node to the graph and add a new edge that connects the meta-node to each node in the graph, which is used by the model to calculate the weights of other nodes; The nodes in the graph are converted into one-dimensional state vectors. The vector size is the number of nodes in the graph, and each bit of the vector is an integer value representing the node statement type. Edges in the figure are transformed into triples consisting of a source node, an edge type, and a target node. Nodes are numbered with integer values starting from 0, and edge types are numbered with integer values starting from 1.
3. The general defect detection method based on a graph neural network according to claim 1, wherein The construction of the general defect prediction model based on the gated graph neural network in the second step includes: Adding labels to the program vector representation according to the defect reports of the benchmark programs to mark the distribution of defect samples; adding a label of 0 to correct samples and a label of 1 to defect samples; The graph neural network generates the feature vectors of each sample through multiple rounds of iteration, maps the feature vectors of each sample into a coordinate system, and uses the Euclidean distance to represent the distance between two sample points. This distance represents the similarity between samples. Through the defined loss function of the general defect prediction model based on the graph neural network, the distance between all correct samples is minimized, and the distance between all defect samples and correct samples is greater than the distance threshold, enabling the model to acquire the ability to distinguish between correct samples and defect samples. The model with the lowest loss in multiple rounds of iteration is saved as the optimal model and used as the general defect detection model in the defect prediction stage; Benchmark programs of different defect types are trained separately to improve the generalization ability of the model.
4. The general defect detection method based on a graph neural network according to claim 1, characterized in that The prediction of the program to be tested using the general defect detection model in the third step includes: The user customizes the defect type to be predicted and filters the samples to be tested that contain sensitive operations corresponding to the defect; for example, for the null pointer dereference defect, the samples to be tested that contain dereference operations are filtered; for the array out-of-bounds defect, the samples to be tested that contain array operations are filtered; if there is no specific defect, all samples to be tested are used as input; Load the general defect prediction model, use the vector representation of the samples to be tested as input, calculate the sample feature vectors through the model, map the feature vectors into a coordinate system, and calculate the distances from all samples to the center point of the sample set; Define a threshold M, that is, the M samples with the farthest distances are defect samples, and report the prediction results; Manually confirm the model prediction results, add labels to the samples to be tested, and use the samples to be tested with added labels as training data to improve the model prediction ability.
5. The general defect detection method based on graph neural network according to claim 2, characterized in that The function context connection method using the program semantic information graph includes: Using control dependence edges to connect the function call statements of the calling function and the entry nodes of the corresponding called functions; Using control dependence edges to connect the exit nodes of the called functions and the function call statements of the calling functions; Using data dependence edges to connect the actual parameters of the calling function and the formal parameters of the called function; If the called function has a return value, use a data dependence edge to connect the return value of the called function and the variable in the calling function that receives the return value.
Citation Information
Patent Citations
Intelligent contract multi-vulnerability detection method and system based on source code graph representation learning
CN113360915A
Defect prediction method based on combination of traditional features and semantic features
CN113626034A