Deep Learning-Based Adaptive Software Vulnerability Repair System

Through deep learning adaptive software vulnerability repair system, integrating multimodal feature fusion, space-time joint modeling and cross-language representation, it solves the shortcomings of traditional methods in detecting new or complex vulnerabilities, realizes efficient and accurate vulnerability detection and repair, and reduces false positive rates and development costs.

CN120086865BActive Publication Date: 2025-07-11ANHUI PERCEPTION FUTURE ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510577944.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-11
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

Traditional software vulnerability detection methods rely on rule matching and static analysis, making it difficult to effectively detect new or complex vulnerabilities, and are prone to false positives, increasing development and maintenance costs.

Method used

Adaptive software vulnerability repair system based on deep learning is adopted to generate mixed feature vectors through the multimodal feature fusion engine, and the code structure and timing dependence are captured using the space-time joint modeling module, and a vulnerability repair strategy generator is combined to generate a repair scheme that conforms to syntax rules and is consistent in semantics. Incremental training and adversarial sample training are carried out through cross-language representation modules to achieve automated repair.

Benefits of technology

It significantly improves the accuracy and recall rate of vulnerability detection, reduces false positive rates, ensures that the fixed code complies with syntax rules and maintains semantic consistency, reduces the need for manual intervention, and improves the efficiency and accuracy of software vulnerability detection and repair.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120086865B_ABST
    Figure CN120086865B_ABST
Patent Text Reader

Abstract

The present invention discloses an adaptive software vulnerability repair system based on deep learning, including a multimodal feature fusion engine, a spatio-temporal joint modeling module, a vulnerability repair strategy generator, and a cross-language representation model. The multimodal feature fusion engine generates a mixed feature vector of the code and inputs it into the spatio-temporal joint modeling module to capture the code structure and temporal dependencies and identify risk features. The vulnerability repair strategy generator generates a repair plan based on the risk features and optimizes it through static verification. The cross-language representation module uses the newly added samples for feedback training and outputs the final detection results and repair plans. The present invention can accurately locate the vulnerability trigger points and extract all related code fragments, providing a solid foundation for subsequent vulnerability analysis. The repaired code not only conforms to the syntax rules but also maintains the original semantic consistency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software detection and repair, and particularly to an adaptive software vulnerability repair system based on deep learning. Background Art

[0002] With the rapid development of information technology, the scale and complexity of software systems have been continuously increasing, and software vulnerabilities have become one of the key issues affecting system security. Traditional software vulnerability detection methods mainly rely on rule matching and static analysis tools. Although these methods can discover vulnerabilities with known patterns to a certain extent, they perform poorly when facing new or complex vulnerabilities. In addition, static analysis often generates a large number of false positives, which require manual secondary screening, greatly increasing the development and maintenance costs. To address these issues, deep learning-based methods have gradually been introduced into the field of software vulnerability detection. Such methods can automatically learn the mapping relationship between code features and vulnerabilities, thereby improving the detection accuracy and efficiency.

[0003] Therefore, there is an urgent need for a software vulnerability detection and repair system with strong adaptability, which can effectively integrate multiple information sources and has an automated repair ability. Summary of the Invention

[0004] In order to overcome the disadvantages that traditional software vulnerability detection methods mainly rely on rule matching and static analysis tools, although these methods can discover vulnerabilities with known patterns to a certain extent, they perform poorly when facing new or complex vulnerabilities. In addition, static analysis often generates a large number of false positives, which require manual secondary screening, greatly increasing the development and maintenance costs, the present invention provides an adaptive software vulnerability repair system based on deep learning.

[0005] The technical solution of the present invention is: an adaptive software vulnerability repair system based on deep learning, including:

[0006] A multimodal feature fusion engine generates a hybrid feature vector of the code, inputs it into a spatio-temporal joint modeling module to capture the code structure and temporal dependencies, and identify high-risk areas; a vulnerability repair strategy generator generates a repair plan based on the high-risk features and optimizes it through static verification; a cross-language representation module uses new samples for feedback training and outputs the final detection results and repair plans.

[0007] The multimodal feature fusion engine: generates a multi-dimensional hybrid feature vector through syntax-aware code slicing, context-sensitive control flow graph construction, and type-annotated abstract syntax tree parsing.

[0008] Space-Time Joint Modeling Module: It is used to capture the structural features of the code and the temporal dependencies of the execution paths. The hybrid feature vector passes through a dual-channel parallel architecture that fuses the graph convolutional network and the dilated convolutional network. After the dual-channel output results are merged, through the dynamic attention mechanism of differentiable neural architecture search, a joint representation vector that combines the graph structure and temporal features is output, representing the risky code area, and the detection result is output through a classifier.

[0009] Vulnerability Repair Strategy Generator: When the detection result indicates the existence of a vulnerability, it is used to generate a repair solution that conforms to the syntax rules and is semantically consistent. It is a sequence generation model based on constraint conditions, integrating the policy optimization of reinforcement learning and the code static verification mechanism; the Vulnerability Repair Strategy Generator outputs a repair solution that conforms to the syntax constraints and passes the static verification by inputting the joint representation vector output by the space-time joint modeling module.

[0010] Cross-Language Representation Model: It supports the alignment of the code feature vector spaces of multiple languages, outputs the final detection result and repair solution, and performs incremental knowledge distillation and adversarial sample training by inputting newly added vulnerability samples, false positives, missed detections, and adversarial samples.

[0011] As a preference of the present invention, the implementation method of the multi-modal feature fusion engine includes:

[0012] The system first performs static analysis on the source code, reversely traces from the vulnerability trigger point through the data flow backtracking algorithm to extract relevant code fragments, then constructs an enhanced control flow graph, calculates the edge weights through the program dependence graph to quantify the importance of the control flow transfer, and at the same time parses the abstract syntax tree AST, performs type annotation and scope analysis on the abstract syntax tree nodes. Finally, the multi-head cross-attention mechanism is used to align and fuse the word vectors of the code, the AST node types, and the control flow graph edge weights to generate a hybrid feature vector containing syntax, semantics, and context information.

[0013] Method for constructing an enhanced control flow graph: Through the edge weight calculation of the program dependence graph, represents the edge weight from node to node , reflecting the importance of the control flow transfer, represents the number of all paths from node to node , represents the total number of all possible paths starting from node , and a control flow feature reflecting the program logic density is established.

[0014] Syntax-Semantic Joint Encoding: Use the multi-head cross-attention mechanism to align the AST node types with the code word vectors, dynamically align the abstract syntax tree node type features with the code word vector semantic features, and generate context-aware features that fuse the syntax structure.

[0015] As a preference of the present invention, the working process of the spatio-temporal joint modeling module is as follows:

[0016] In the graph structure feature extraction stage, the system uses a graph convolutional network to process the control flow graph, and captures the topological structure information of the code through iterative updates of the adjacency matrix and the node feature matrix. In the temporal feature modeling stage, the system uses a dilated convolutional network to process the code execution path, and captures the long-range dependence relationship through an exponentially increasing dilation rate. Finally, through the dynamic attention mechanism, the graph structure features and temporal features output by the graph convolutional network and the dilated convolutional network are dynamically attention-fused, the attention weights between nodes are calculated, and the high-risk code regions are focused on.

[0017] Dynamic Attention Fusion: , where is the edge type embedding vector, where represents node The attention weight of node , and represent the query vector and the key vector respectively, represents the dimension of the vector, which is used to scale the dot product result, represents the mapping function of the edge type embedding vector .

[0018] As a preference of the present invention, the generation method of the vulnerability repair strategy generator includes:

[0019] Ensure the legality of the repair scheme conforming to the AST structure in the decoding stage through an algorithm based on syntax constraints, providing a basic guarantee for the repair; the design of the reinforcement learning reward function further optimizes the repair scheme, comprehensively considering the syntax correctness, semantic consistency, and security rewards, and verifying the repair effect through AST parsing and symbolic execution; finally, the multi-candidate scheme sorting strategy scores and sorts the candidate schemes based on the probability and complexity of the repair scheme, and preferentially selects the most efficient and concise optimal repair scheme.

[0020] Algorithm based on syntax constraints: Enforce the legality of the AST structure in the decoding stage.

[0021] Design of the reinforcement learning reward function: , where represents the comprehensive reward value, represents the syntax correctness reward, verified through AST parsing, Represents the semantic consistency reward, verified through symbolic execution, Verify the behavioral consistency before and after repair through symbolic execution, and evaluate the vulnerability repair effect, 、 、 Represents the weight coefficient of each reward item.

[0022] Multi-candidate solution sorting strategy: where is the comprehensive score of the repair solution for the complexity penalty coefficient, is the probability value of the repair solution under the given output, and is the complexity of the repair solution.

[0023] As a preference of the present invention, the implementation of the construction method of the cross-language representation module includes:

[0024] In the incremental knowledge distillation stage, the system transfers the knowledge of the teacher model to the student model through the teacher-student model architecture to achieve lossless model update. In the adversarial training sample generation stage, the system uses gradient backpropagation to generate adversarial samples to enhance the robustness of the model. In the feature transfer learning stage, the system reduces the difference in the distribution of old and new vulnerability features through domain adaptation loss to achieve knowledge transfer across vulnerability types.

[0025] Contrastive learning multi-language pre-training optimizes the similarity of positive and negative samples through the loss function, learns language-independent code feature representations, and provides a basis for cross-language alignment; on this basis, the syntax structure projection matrix further aligns the syntax structures of multiple languages by minimizing the difference in feature representations between the source language and the target language, achieving unified cross-language representation. The two work together, with the former providing general features and the latter refining syntax alignment, jointly supporting cross-language code analysis and understanding.

[0026] As a preference of the present invention, the spatio-temporal joint modeling module further includes an interpretive generation method:

[0027] In the critical path identification stage, the system uses the integrated gradient method to calculate the contribution degree of each code node to the vulnerability detection result and identify the critical path. In the causal inference analysis stage, the system verifies the vulnerability triggering condition through counterfactual sample generation to ensure the reliability of the detection result. Finally, the system generates a control flow coloring graph and a data flow tracking animation, and displays the vulnerability detection result and interpretive analysis through the visualization audit interface.

[0028] Critical path identification based on integrated gradient:

[0029] where, is the node ​Contribution degree to the vulnerability detection structure is the input feature of the node ; is the input feature in the baseline state, F is the vulnerability detection model is the interpolation coefficient for calculating the gradient integral.

[0030] Causal inference analysis: Verify the vulnerability trigger conditions through counterfactual sample generation.

[0031] Visualization audit interface: Generate control flow coloring graphs and data flow tracking animations.

[0032] By adopting the above technical solutions, the present invention has the following advantages:

[0033] 1. By integrating a multi-modal feature fusion engine, the present invention realizes the deep fusion of code syntax, semantics, and context information, significantly improving the accuracy and recall rate of vulnerability detection. By using the data flow backtracking algorithm, the control flow graph enhancement construction method, and the syntax-semantics joint encoding technology, it can accurately locate the vulnerability trigger points and extract all relevant code fragments, providing a solid foundation for subsequent vulnerability analysis.

[0034] 2. The present invention not only considers the legality at the syntax level but also combines a reinforcement learning reward function to evaluate the quality of the repair solution, ensuring that the repaired code not only conforms to the syntax rules but also maintains the original semantic consistency. In particular, by using symbolic execution technology to verify the behavioral consistency before and after repair, the effectiveness of the repair is further guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 is a schematic structural diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] Reference to an embodiment in this specification means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0037] An adaptive software vulnerability detection and repair system based on deep learning, such as Figure 1As shown in the figure, it includes a multi-modal feature fusion engine, a spatio-temporal joint modeling module, a vulnerability repair strategy generator, an adaptive evolution framework, and a cross-language unified representation layer. The multi-modal feature fusion engine generates a multi-dimensional hybrid feature vector through syntax-aware code slicing, context-sensitive control flow graph construction, and type-annotated abstract syntax tree parsing. The spatio-temporal joint modeling module fuses the dual-channel architecture of a graph convolutional network and a temporal convolutional network, equipped with a dynamic attention mechanism for differentiable neural architecture search. The vulnerability repair strategy generator is a sequence generation model based on constraint conditions, integrating policy optimization of reinforcement learning and a code static verification mechanism. The adaptive evolution framework includes an online learning system with incremental knowledge distillation and adversarial sample training. The cross-language unified representation layer supports a multi-language code feature vector space alignment module.

[0038] The implementation method of the multi-modal feature fusion engine includes:

[0039] (1)Code slicing by data flow backtracking

[0040] Input source code file: The system first receives a source code file (such as C / C++, Java, Python, etc.).

[0041] Identify sensitive function call points: Identify dangerous function call points through static analysis tools (such as the Clang AST parser);

[0042] Forward data flow analysis: Starting from sensitive function call points, propagate forward along the data flow to trace all variables that may affect vulnerability triggering.

[0043] Backward data flow analysis: Trace backward from sensitive function call points to identify unvalidated input sources; for example, trace the buffer declaration of dest and its initialization process.

[0044] Generate code slices: Merge the code fragments traced forward and backward to form a set of code slices related to vulnerabilities.

[0045] (2)Enhanced construction of the control flow graph

[0046] Generate a basic control flow graph: Use LLVM to generate a basic control flow graph and label the nodes and edges.

[0047] Calculate edge weights: Calculate the weight of each edge through the program dependence graph to reflect the importance of control flow transfer. The weight calculation is based on the number of paths and execution probability.

[0048] Normalize edge weights: Ensure that the sum of the out-edge weights of each node is 1 to reflect the relative importance of control flow transfer.

[0049] (3)Syntax-semantics joint encoding

[0050] Parse the Abstract Syntax Tree: Parse the code syntax to generate the AST and annotate the type of each node.

[0051] Generate word vectors: Use a pre-trained word vector model to convert variable names, function names, etc. in the code into vector representations;

[0052] Multi-Head Cross-Attention Mechanism: Through the Transformer architecture, dynamically align the AST node type vectors with the code word vectors to generate context-aware features that fuse syntax and semantics.

[0053] Feature Fusion: Concatenate the word vectors, AST type vectors, and control flow graph edge weights to generate a multi-dimensional hybrid feature vector.

[0054] Specifically, a code slicing algorithm based on data flow backtracking: , where is a set of sensitive function call nodes, such as unvalidated user input points, dangerous function call points, represents a set of code slices, that is, all relevant code fragments obtained by backtracking from the vulnerability trigger point, represents starting from node All code statements that can be reached through data flow or control flow. Build a set of vulnerability-related code fragments through reachability analysis to form data flow dependency features.

[0055] Control Flow Graph Enhancement Construction Method: Through the edge weight calculation of the program dependency graph, represents the edge weight from node to node , reflecting the importance of control flow transfer, represents the number of all paths from node to node , represents the total number of all possible paths starting from node .

[0056] Syntax-Semantics Joint Encoding: Use the multi-head cross-attention mechanism to align the AST node types with the code word vectors.

[0057] The workflow of the spatio-temporal joint modeling module is as follows:

[0058] (1) Graph Structure Feature Extraction

[0059] Construct the adjacency matrix: Generate the adjacency matrix based on the control flow graph and add self-connections to enhance the feature representation of the nodes themselves.

[0060] Calculate the degree matrix: Calculate the degree matrix of each node according to the adjacency matrix for normalization processing.

[0061] Graph Convolutional Network Processing: Iteratively update node features through multiple layers of GCNs to capture the topological structure information of the code.

[0062] (2) Temporal Feature Modeling

[0063] Generate the code execution path sequence: Generate the code execution path sequence based on the control flow graph to reflect the dynamic behavior of the code.

[0064] Dilated Convolutional Network Processing: Use a dilated convolutional network to process the execution path sequence and capture long-range dependencies through an exponentially increasing dilation rate.

[0065] Extract temporal features: Extract temporal features from the output of the TCN to reflect the evolution law of the code execution path.

[0066] (3) Dynamic Attention Fusion

[0067] Edge type embedding: Classify the edges in the control flow graph (such as data dependence, control dependence) and assign type embedding vectors.

[0068] Calculate attention weights: Calculate the attention weights between nodes through a dynamic attention mechanism to focus on high-risk code regions.

[0069] Feature fusion: Weightedly sum the graph structure features and temporal features to generate a fused joint representation vector.

[0070] Specifically, graph structure feature extraction: , where is the adjacency matrix after adding self-connections, represents the feature representation matrix of the -th layer nodes, represents 's degree matrix, represents the learnable parameter matrix of the -th layer, represents the non-linear activation function ReLU.

[0071] Temporal feature modeling: , where, represents the convolutional output feature at time step , represents the input sequence within the time window , represents the dilation rate of the dilated convolution, which increases exponentially to capture long-range dependencies, represents the ratio of time step to the scaling factor rounded down.

[0072] Dynamic attention fusion: , where is the edge type embedding vector, where represents the node For node the attention weight, and represent the query vector and the key vector respectively, represents the dimension of the vector, which is used to scale the dot product result, represents the edge type embedding vector mapping function.

[0073] (4)The joint representation vector outputs the detection result through the classifier.

[0074] The specific implementation of the vulnerability repair strategy generator includes:

[0075] (1)Heuristic search algorithm Beam Search based on syntax constraints

[0076] Initialize the decoder: Use the Transformer decoder, and the initial state is the feature vector of the high-risk code area.

[0077] Generate candidate repair solutions: During the decoding process, force the candidate code fragments to conform to the AST structure to ensure syntactic legality.

[0078] Retain the top-k candidate solutions: Retain the top-k candidate repair solutions with the highest scores (usually k = 5) through the Beam Search algorithm.

[0079] (2)Design of the reinforcement learning reward function

[0080] Syntax correctness reward: Verify the syntactic legality of the repair solution through AST parsing to ensure that the generated code conforms to the syntax rules.

[0081] Semantic consistency reward: Verify the semantic consistency of the program before and after repair through symbolic execution to ensure that the repair solution does not introduce new logical errors.

[0082] Security reward: Ensure that the vulnerability is completely eliminated through dynamic taint analysis to avoid the failure of the repair solution.

[0083] Calculate the comprehensive reward: Weighted sum of the syntax correctness, semantic consistency, and security rewards to obtain the comprehensive reward value.

[0084] (3)Sorting of multiple candidate solutions

[0085] Calculate the score of the repair solution: Calculate the comprehensive score based on the probability and complexity of the repair solution, and give priority to recommending the solution with a high score.

[0086] Sorting and recommendation: Sort in descending order of scores and recommend the best repair solution to the user.

[0087] Syntax-constraint-based algorithm: Enforce the legality of the AST structure during the decoding phase.

[0088] Reinforcement learning reward function design: , where represents the comprehensive reward value, represents the syntax correctness reward, verified through AST parsing, represents the semantic consistency reward, verified through symbolic execution, Verify the consistency of the behavior before and after repair through symbolic execution, and evaluate the vulnerability repair effect, , , represent the weight coefficients of each reward item.

[0089] Multi-candidate solution ranking strategy: , where is the comprehensive score of the repair solution, is the penalty coefficient for complexity, is the probability value of the repair solution under the given output, is the complexity of the repair solution.

[0090] The implementation of the cross-language representation module includes:

[0091] (1) Incremental knowledge distillation

[0092] Freeze the teacher model: Fix the parameters of the teacher model to ensure that historical knowledge is not overwritten.

[0093] Train the student model: Through the L2 loss function, make the output of the student model as close as possible to the output of the teacher model to achieve lossless model update.

[0094] (2) Adversarial training sample generation

[0095] Generate adversarial samples: Generate adversarial samples through gradient backpropagation to enhance the robustness of the model against adversarial attacks.

[0096] Train the model: Use adversarial samples to train the model to improve its generalization ability in complex environments.

[0097] (3) Feature transfer learning

[0098] Calculate the domain adaptation loss: Narrow the difference in the distribution of old and new vulnerability features through the domain adaptation loss to achieve knowledge transfer across vulnerability types.

[0099] Update the model parameters: Optimize the domain adaptation loss through gradient descent to ensure that the model can adapt to new vulnerability types.

[0100] Incremental knowledge distillation: , where learning loss represents the output of the input object for the sample represents the output of the learning object for the sample represents the newly added training data set

[0101] Adversarial training sample generation: , where is the perturbation vector of the adversarial sample is the maximum norm constraint of the perturbation vector is the loss function, used to measure the difference between the model output and the true label is the output value of the model for the adversarial sample

[0102] Feature transfer learning: Narrow the distribution difference between new and old vulnerability features through domain adaptation loss

[0103] (4) Multi-language contrastive pre-training

[0104] Construct positive and negative samples: The positive samples are the implementations of the same vulnerability in different languages, and the negative samples are the code snippets of different vulnerabilities

[0105] Contrastive learning training: Maximize the similarity of positive sample pairs and minimize the similarity of negative sample pairs through the contrastive learning loss function

[0106] (5) Construction of syntactic structure projection matrix

[0107] Construct the projection matrix: Map the AST node features of different languages to the same vector space to achieve cross-language feature alignment

[0108] Optimize the projection matrix: Optimize the projection matrix by minimizing the difference between the feature representations of the source language and the target language

[0109] Use contrastive learning for multi-language pre-training:

[0110] where is the contrastive learning loss is the similarity of positive samples is the similarity of negative samples is the temperature parameter, used to adjust the smoothness

[0111] Syntactic structure projection matrix:

[0112] , where is the syntactic structure projection matrix is the feature representation of the source language code of is the target language code Feature representation.

[0113] Specifically, the system first uses contrastive learning for multilingual pre-training. By maximizing the similarity of positive sample pairs and minimizing the similarity of negative sample pairs, it learns a unified cross-lingual feature representation. Then, it constructs a syntactic structure projection matrix to map the AST node features of different languages into the same vector space, achieving cross-lingual feature alignment.

[0114] The interpretive generation method for vulnerability detection results includes:

[0115] Identification of important paths based on integrated gradients:

[0116] , where is the contribution degree of node to the vulnerability detection structure, is the input feature of node , is the input feature in the baseline state, is the vulnerability detection model, is the interpolation coefficient used to calculate the gradient integral.

[0117] Causal inference analysis: Verifying the vulnerability trigger conditions through the generation of counterfactual samples.

[0118] Visualization audit interface: Generating a control flow coloring graph and a data flow tracking animation.

[0119] Specifically, in the important path identification stage, the system uses the integrated gradient method to calculate the contribution degree of each code node to the vulnerability detection result and identify the critical path. In the causal inference analysis stage, the system verifies the vulnerability trigger conditions through the generation of counterfactual samples to ensure the reliability of the detection result. Finally, the system generates a control flow coloring graph and a data flow tracking animation, and displays the vulnerability detection result and interpretive analysis through the visualization audit interface.

[0120] Specifically, the deployment architecture features include:

[0121] Edge-cloud collaborative computing framework: Deploying a lightweight detection model locally in the development environment and synchronously updating the knowledge base in the cloud. Real-time hot update channel: Achieving a model update latency < 30 seconds through the differential parameter transmission protocol. Multi-granularity privacy protection mechanism: Using federated learning for distributed training and processing sensitive code after homomorphic encryption.

[0122] In the specific implementation process, the system workflow is divided into four stages:

[0123] The first stage is the feature engineering stage: First, the input code is parsed by syntax to generate an enhanced AST, where nodes are annotated with types, scopes, and variable dependencies. Then, key paths are extracted relying on data flow-sensitive slicing to construct a weighted program dependence graph. Finally, the AST vector spaces of different languages are aligned through contrastive learning.

[0124] The second stage is the vulnerability detection stage: First, the control flow structure features are extracted relying on graph convolutional networks, and dilated convolutions capture long-range dependencies. Then, a dynamic attention mechanism is used to focus on high-risk code regions to generate a vulnerability heat map. Finally, low-confidence warnings are evaluated and filtered (threshold > 85%).

[0125] The third stage is the repair generation stage: A constraint decoder is used to generate candidate repair solutions to ensure syntactic legality. The equivalence of the program before and after the repair is verified through a symbolic execution engine. Finally, the solutions are sorted based on code readability metrics (cyclomatic complexity, indentation consistency).

[0126] The fourth stage is the adaptive evolution stage: False positive / missed alert cases are collected online to generate adversarial samples to enhance robustness. Global knowledge is aggregated through federated learning and the input object model is updated. Finally, differential distillation compresses the model update amount to 3% - 5% of the original parameters.

[0127] Take the detection and repair of buffer overflow vulnerabilities as an example:

[0128] The system first identifies dangerous function call points (such as strcpy), extracts relevant code fragments through data flow backtracking, and constructs a data flow subgraph containing input sources, copy operations, and buffer declarations. Then, the graph network discovers unvalidated user input paths, the temporal model detects boundary misses in loop structures, and the attention mechanism focuses on high-risk code lines. Then, the system generates a replacement solution for strncpy, automatically adds length verification logic, and ensures the security of the repair solution through the reinforcement learning reward mechanism. Finally, the system encodes the new vulnerability pattern as a feature template, uploads the encrypted feature vector through edge devices, and the system model completes parameter update and distribution within 11 minutes.

[0129] Experimental design: Cross-language vulnerability detection and repair verification experiments based on the CVE vulnerability database

[0130] I. Experimental settings

[0131] Vulnerability Sample Set: Select verified buffer overflow, format string, and memory leak vulnerability samples between CVE-2023 and CVE-2025, covering three languages: C / C++, Java, and Python, with a total of 1,200 positive samples and 3,600 negative samples. Training and Validation Set Division: Divide it into a training set, a validation set, and a test set according to a ratio of 6:2:2 to ensure an even distribution of cross-language samples. Comparison Baselines: Checkmarx static analysis tool, VulDeePecker deep learning model, and MSAFF multi-modal fusion model.

[0132] II. Evaluation Metrics

[0133] Vulnerability Detection Performance: Accuracy, Recall, F1 score, False Positive Rate (FPR). Vulnerability Fix Quality: Fix Success Rate, Syntax Correctness Rate, Semantic Consistency Score. System Performance: Single-function Inference Latency (ms), Model Incremental Update Latency (s).

[0134] III. Core Experimental Results

[0135] Verification of the Effectiveness of Multi-modal Feature Fusion: The hybrid feature vector improves the cross-language detection F1 score by 12.6% (compared to the single-modal baseline). The multi-head cross-attention mechanism increases the accuracy of identifying critical control flow paths to 93.2%. Syntax-semantic joint encoding reduces the AST parsing error rate by 58.4%.

[0136] Comparison of Spatio-temporal Joint Modeling: The dynamic attention mechanism achieves a 97.1% recall rate in buffer overflow detection, a 9.3% improvement compared to traditional GCN; the dilated convolutional network improves the efficiency of capturing temporal dependencies in loop structure vulnerabilities by 2.8 times. The false positive rate is controlled below 1.2%, which is 3-5 percentage points better than the baseline model.

[0137] Quality of Fix Strategy Generation: The constrained decoder ensures 100% syntax correctness, a 36.7% improvement compared to the unconstrained model. The reinforcement learning reward mechanism enables the semantic consistency score to reach 94.6 points (on a 100-point scale). The hit rate of the multi-candidate sorting strategy for recommending the optimal fix solution is increased to 89.3%.

[0138] Adaptive Evolution Effect: Incremental knowledge distillation enables lossless model updates, with the F1 score of old vulnerability detection only decreasing by 0.8%. Adversarial training improves the robustness of the model under adversarial sample attacks by 41.2%. The federated learning framework improves the efficiency of cross-institutional knowledge aggregation by 3.6 times.

[0139] IV. Visualization Analysis

[0140] The risk weight of the call point of the strcpy function shown in the vulnerability heat map reaches 0.92 (threshold 0.85). The repair case shows that the system successfully replaces the dangerous function with strncpy and automatically adds boundary check logic. The visualization of the feature space projection proves that multi-language AST nodes form semantic clusters in a unified space.

[0141] The above embodiments are provided for those skilled in the art to implement or use the present invention. Those skilled in the art can make various modifications or changes to the above embodiments without departing from the idea of the present invention. Therefore, the protection scope of the present invention is not limited by the above embodiments, but should be the maximum scope that conforms to the innovative features mentioned in the claims.

Claims

1. An adaptive software vulnerability repair system based on deep learning, characterized in that It includes a multi-modal feature fusion engine, a spatio-temporal joint modeling module, a vulnerability repair strategy generator, and a cross-language representation model; The multi-modal feature fusion engine generates a hybrid feature vector of the code, inputs it into the spatio-temporal joint modeling module to capture the code structure and temporal dependencies, and identify risk features; The vulnerability repair strategy generator generates a repair plan based on the risk features and optimizes it through static verification; The cross-language representation module uses the newly added samples for feedback training and outputs the final detection results and repair plans; The multi-modal feature fusion engine: generates a multi-dimensional hybrid feature vector through syntax-aware code slicing, context-sensitive control flow graph construction, and type-annotated abstract syntax tree parsing; The spatio-temporal joint modeling module: is used to capture the structural features of the code and the temporal dependencies of the execution path. The hybrid feature vector passes through a dual-channel parallel architecture that fuses a graph convolutional network and a dilated convolutional network. After the outputs of the two channels are merged, through the dynamic attention mechanism of differentiable neural architecture search, an integrated representation vector of graph structure and temporal features is output, representing the risk code area, and the detection result is output through a classifier; The vulnerability repair strategy generator: when the detection result indicates a vulnerability, it is used to generate a repair plan that conforms to the syntax rules and is semantically consistent, a sequence generation model based on constraint conditions, integrating the policy optimization of reinforcement learning and the code static verification mechanism; the vulnerability repair strategy generator outputs a repair plan that conforms to the syntax constraints and passes the static verification by inputting the integrated representation vector output by the spatio-temporal joint modeling module; The cross-language representation module: supports the alignment of code feature vector spaces in multiple languages, outputs the final detection results and repair plans, and conducts incremental knowledge distillation and adversarial sample training by inputting newly added vulnerability samples, false positives, missed detections, and adversarial samples.

2. The adaptive software vulnerability repair system based on deep learning according to claim 1, wherein The implementation of the multi-modal feature fusion engine is as follows: First, perform static analysis on the source code, reverse trace from the vulnerability trigger point through the data flow backtracking algorithm to extract relevant code fragments, then construct an enhanced control flow graph, calculate the edge weights through the program dependence graph to quantify the importance of control flow transfer, at the same time parse the abstract syntax tree AST, perform type annotation and scope analysis on the abstract syntax tree nodes, and finally use the multi-head cross-attention mechanism to align and fuse the word vectors of the code, the AST node types, and the control flow graph edge weights to generate a hybrid feature vector containing syntax, semantics, and context information.

3. The adaptive software vulnerability repair system based on deep learning according to claim 2, characterized in that During the process of constructing the enhanced control flow graph, the following steps are included: Through the edge weight calculation of the program dependence graph, w ij represents the edge weight from node i to node j, reflecting the importance of the control flow transfer. PathCount(i→j) represents the number of all paths from node i to node j, and ∑ k PathCount(i→k) represents the total number of all paths starting from node i, and a control flow feature reflecting the program logic density is established.

4. The adaptive software vulnerability repair system based on deep learning according to claim 3, characterized in that The specific implementation of the spatio-temporal joint modeling module is as follows: In the graph structure feature extraction stage, use the graph convolutional network to process the control flow graph, capture the topological structure information of the code through the iterative update of the adjacency matrix and the node feature matrix. In the temporal feature modeling stage, use the dilated convolutional network to process the code execution path, capture the long-range dependence relationship through the exponentially increasing dilation rate. Finally, perform dynamic attention fusion on the graph structure features and temporal features output by the graph convolutional network and the dilated convolutional network through the dynamic attention mechanism, and calculate the attention weights between nodes to focus on the risk code area; The dynamic attention fusion is as follows: where E ij is the edge type embedding vector, and α ij where represents the attention weight of node i to node j, Q i and K j represent the query vector and the key vector respectively, d k represents the dimension of the vector, which is used to scale the dot product result, represents the mapping function of the edge type embedding vector E ij of.

5. The adaptive software vulnerability repair system based on deep learning according to claim 4, characterized in that, The specific implementation of the vulnerability repair strategy generator is as follows: Ensure that the repair plan conforms to the AST structure legality during the decoding phase through a grammar-constrained algorithm, providing a basic guarantee for the repair; optimize the repair plan through the design of the reinforcement learning reward function, integrating rewards for grammar correctness, semantic consistency, and security, and verify the repair effect through AST parsing and symbolic execution; finally, the multi-candidate solution sorting strategy scores and sorts the candidate solutions based on the probability and complexity of the repair plan, and selects the optimal repair plan; The reinforcement learning reward function is designed as: R = λ1R syntactic + λ2R semantic + λ3R security , where R represents the comprehensive reward value, R syntactic represents the syntax correctness reward, which is verified by AST parsing, R semantic represents the semantic consistency reward, which is verified by symbolic execution, R security verifies the consistency of behavior before and after repair through symbolic execution, and evaluates the vulnerability repair effect. λ1, λ2, and λ3 represent the weight coefficients of each reward item; The multi-candidate solution sorting strategy is: Score(p) = log P(p|X - β·Complexity(p)), where Score(p) is the comprehensive score of the repair plan p, β is the penalty coefficient of complexity, P is the probability value of the repair plan under the given output, and Complexity(p) is the complexity of the repair plan.

6. The adaptive software vulnerability repair system based on deep learning according to claim 5, characterized in that The spatio-temporal joint modeling module also includes the interpretive generation of the hole detection results, which is implemented as: In the important path identification phase, use the integrated gradient method to calculate the contribution of each code node to the vulnerability detection result and identify the critical path. In the causal reasoning analysis phase, verify the vulnerability trigger conditions through the generation of counterfactual samples to ensure the reliability of the detection result. Finally, generate a control flow coloring graph and a data flow tracking animation, and display the vulnerability detection result and the interpretive analysis through the visual audit interface; Important path identification based on integrated gradients: Among them, Attribution i is the contribution degree of node i to the vulnerability detection structure, x i is the input feature of node i, x' i is the input feature in the baseline state, F is the vulnerability detection model, and α is the interpolation coefficient used to calculate the gradient integral.

Citation Information

Patent Citations

  • Source code detection method

    CN119442240A

  • Multi-modal decentration vulnerability assessment method capable of protecting privacy

    CN119830306A