Graph neural network detection method for FreeRTOS buffer overflow vulnerability
Through the graph neural network detection method, a code attribute graph is constructed and a model is trained, which solves the problem of difficulty in detecting multiple types of vulnerabilities in the existing technology, and realizes efficient multi-type classification detection of FreeRTOS buffer overflow vulnerabilities.
Patent Information
- Application Number
- CN202510623679.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-05-15
AI Technical Summary
The prior art is difficult to detect multiple types of software vulnerabilities simultaneously, and the vulnerabilities detected by methods based on single feature analysis are limited, so it is impossible to effectively utilize the structure and semantic information of the code.
The graph neural network detection method is adopted to obtain the source code of known vulnerability types, perform preprocessing and function-level code segmentation, build code attribute graphs, generate adjacency matrix and feature matrix, and train graph neural network models to detect buffer overflow vulnerabilities.
Multi-type classification detection of buffer overflow vulnerabilities in FreeRTOS is realized, which improves the accuracy and efficiency of detection, reduces the workload of manual analysis and avoids deviations in traditional methods.
Smart Images

Figure CN120145404A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and particularly to a graph neural network detection method for FreeRTOS buffer overflow vulnerabilities. Background Art
[0002] FreeRTOS is a widely used real-time operating system. Due to its popular development in resource-constrained embedded devices, the security requirements for FreeRTOS are increasing day by day.
[0003] Since the first buffer overflow attack in 1988, buffer overflow vulnerabilities have become the most common and serious type of software vulnerabilities, bringing many potential risks. Attackers can execute malicious code through buffer overflow vulnerabilities and gain control of the system. In recent years, vulnerabilities related to FreeRTOS have been reported from time to time, and buffer overflow vulnerabilities account for about 72.7%. Attackers can use the vulnerabilities to control the RTOS and gain access to the system, resulting in system crashes or arbitrary code execution, with a bad impact. However, there are still some problems in using machine learning or deep learning methods to detect vulnerabilities in software source code: 1) The existing technologies only focus on whether the software to be detected contains vulnerabilities and cannot detect multiple types of vulnerabilities simultaneously. Since there are many reasons for software vulnerabilities, there are also many types of software vulnerabilities. Buffer overflow vulnerabilities include stack overflow vulnerabilities, heap overflow vulnerabilities, integer overflow vulnerabilities, SHE structure base vulnerabilities, buffer lower bound writes, buffer out-of-bounds reads, and other types.
[0004] 2) The existing technologies are based on a single feature analysis program, and the detected vulnerabilities are limited. Some existing technologies use text-based features of the source code to analyze the program, but the diversity of software development naming leads to possible lexical ambiguity, and the code is different from ordinary text. It has richer structural and semantic information. Treating the code as text will lose some connection information between codes to a certain extent. This method still has deficiencies in capturing long-distance dependencies with less closely related context in the code. Some existing technologies combine graph representation learning to extract more code information, and some existing technologies use graph-based feature representations to analyze the program. However, their software graph slicing methods can only traverse all nodes in the graph as inputs and cannot make good use of the features of node edges or highlight the features that have a strong impact on a certain type of vulnerability in the graph. Summary of the Invention
[0005] Aiming at the above problems, the purpose of the present invention is to provide a graph neural network detection method for FreeRTOS buffer overflow vulnerabilities, which uses graph analysis and deep learning technologies to automatically detect buffer overflow vulnerabilities in the code and identify their types.
[0006] The present invention provides a graph neural network detection method for FreeRTOS buffer overflow vulnerability, comprising: Get source code for known vulnerability types; Preprocessing the source code and performing function-level code segmentation to obtain multiple function codes; Use the static analysis tool Joern to construct a code property graph of the function code; the JSON text corresponding to the code property graph includes node information and edge information; Construct an adjacency matrix of the code attribute graph according to the code attribute graph, and construct a feature matrix of the node information according to the JSON text; A graph neural network model is obtained by training according to the adjacency matrix and the feature matrix to detect buffer overflow vulnerabilities.
[0007] In a possible implementation, the preprocessing and function-level code segmentation of the source code to obtain multiple function codes includes: Scan and remove source code other than function definitions, output to files, and obtain function codes at the function level after segmentation; each file includes only a single function code.
[0008] In a possible implementation, constructing a feature matrix of the node information according to the JSON text includes: Extract and remove tags from the JSON text; Remove non-ASCII characters from the JSON text and replace each string constant; Each attribute label is classified and spliced in the order of grammatical information, data dependency, and control flow sequence to obtain the encoding sequence of node features.
[0009] In a possible implementation, constructing the feature matrix of the node information according to the JSON text further includes: The coding sequence is trained using the Word2Vec model to obtain a feature vector of the node information.
[0010] In a possible implementation, constructing the feature matrix of the node information according to the JSON text further includes: The feature vectors that are not within a preset length range are eliminated, and the remaining bits of the feature vectors are filled with zeros to obtain the feature matrix.
[0011] In a possible implementation, the training of the graph neural network model according to the adjacency matrix and the feature matrix includes: Construct a graph neural network model based on the input layer, embedding layer, graph convolution layer, attention pooling layer and output layer; Among them, the graph convolutional layer includes a first-layer GCN and a second-layer GCN; the activation functions of the first-layer GCN and the second-layer GCN are both ReLU.
[0012] In a possible implementation manner, training the graph neural network model according to the adjacency matrix and the feature matrix includes: Import the adjacency matrix and the feature matrix into the input layer; Compress the adjacency matrix and the feature matrix through the embedding layer, and then transmit the compressed adjacency matrix and feature matrix to the graph convolutional layer for learning; Assign different weights to different nodes through the attention mechanism pooling layer and aggregate to obtain attention scores; Sort the attention scores of the nodes in descending order and retain a preset proportion of nodes according to the descending order result to obtain a mask vector of the graph; Update the feature matrix and the adjacency matrix according to the mask vector of the graph; Output the detected vulnerability type through the output layer to determine whether the detected vulnerability type is consistent with the known vulnerability type.
[0013] In a possible implementation manner, the compressing the adjacency matrix and the feature matrix through the embedding layer, and then transmitting the compressed adjacency matrix and feature matrix to the graph convolutional layer for learning includes: Perform forward propagation according to the following formula: ; ; ; Among them, is the feature matrix, is the adjacency matrix, is the adjacency matrix is the Laplacian matrix obtained by adding self-connections and normalizing in is the activation function, is the output of the first-layer GCN, is the output of the second-layer GCN, is the output of the graph convolutional layer, is the weight parameter matrix.
[0014] In a possible implementation manner, the assigning different weights to different nodes through the attention mechanism pooling layer and aggregating to obtain attention scores includes: Calculate the self-attention scores according to the following formula: ; Among them, is the output of the graph convolutional layer, is the activation function, is the weight parameter matrix, is the attention score, is the adjacency matrix is the Laplacian matrix obtained by adding a self-connection to and normalizing
[0015] In a possible implementation, the obtaining of the mask vector of the graph by descendingly sorting the attention scores of the nodes and retaining a preset proportion of the nodes according to the descending sorting result includes: Obtaining the mask vector of the graph according to the following formula: ; wherein, is the attention score, is the updated mask vector of the graph, is the index of the nodes retained after sorting the attention scores in descending order, is the proportion of the retained nodes, is the total number of nodes; Updating the feature matrix and the adjacency matrix according to the mask vector of the graph includes: Updating the feature matrix according to the following formula: ; wherein, is the attention score of the retained nodes, is the hyperbolic tangent function, is the updated feature matrix, is the feature matrix of the retained nodes.
[0016] The graph neural network detection method for FreeRTOS buffer overflow vulnerabilities provided by the present invention aims to intelligently analyze the vulnerabilities existing in FreeRTOS by using automated technology, and focuses on multi-type classification and identification of buffer overflow vulnerabilities, aiming to reduce the difficulties in auditing and the deviations in experience in traditional methods, and help developers locate problems more accurately. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 is the first process schematic diagram of the graph neural network detection method provided by the embodiment of the present invention; Figure 2 is the second process schematic diagram of the graph neural network detection method provided by the embodiment of the present invention; Figure 3 is the structural schematic diagram of the graph neural network model provided by the embodiment of the present invention; Figure 4 is the working schematic diagram of the attention pooling layer provided by the embodiment of the present invention. Specific Embodiments
[0018] The following further describes in detail the embodiments of the present invention in conjunction with the accompanying drawings and examples. The detailed description and drawings of the following examples are used to exemplarily illustrate the principles of the present invention, but cannot be used to limit the scope of the present invention, that is, the present invention is not limited to the described preferred embodiments, and the scope of the present invention is defined by the claims.
[0019] In the description of the present invention, it should be noted that unless otherwise stated, the meaning of "a plurality" is two or more; the terms "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or implying relative importance; for those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0020] Figure 1 The first flowchart of the graph neural network detection method provided for the embodiments of the present invention Figure 2 The second flowchart of the graph neural network detection method provided for the embodiments of the present invention, in combination with Figure 1 and Figure 2 , the present invention provides a graph neural network detection method for FreeRTOS buffer overflow vulnerabilities, including: Step S1, obtain the source code of known vulnerability types; In one example, download and obtain the source code files of FreeRTOS v10.0.1 version, including the operating system kernel code and common function libraries attached to FreeRTOS such as FreeRTOS-Plus-TCP (TCP / IP protocol component), FreeRTOS-Plus-CLI (command line interpreter), FreeRTOS-Plus-Trace (visualization tracking), FreeRTOS-Plus-IO (providing a communication interface for hardware I / O pins).
[0021] Step S2, preprocess the source code and perform function-level code splitting to obtain multiple function codes; In a possible implementation, scan and remove the source code outside the function definition, output it to a file, and obtain the function-level function code after splitting; each file only includes a single function code.
[0022] In one example, scan the source code file, remove code information other than function definitions such as comments, spaces, global variables, and function declarations. Match the function definitions and "{", "}", and output them to independent files to obtain the split source code at the function level, that is, each.c file only contains a single function.
[0023] Step S3: Use the static analysis tool Joern to construct a code property graph for the function code; In a possible implementation, for each function code, use the static analysis tool Joern to abstract it and construct a code property graph that describes the internal structure and control flow of the function.
[0024] As a graph-based representation method, the code property graph CPG combines the abstract syntax tree AST, control flow graph CFG, and program dependence graph PDG, and contains various information such as function syntax, semantics, and control flow.
[0025] Among them, the JSON text corresponding to the code property graph includes node information and edge information. The nodes in the graph represent code elements such as variables, variable types, parameters, operators, etc.; the edges represent the relationships between code elements such as control flow and data flow.
[0026] Each node in the graph is uniquely labeled, and the numeric string before the label represents the label of the node. Each node in the graph is represented by two main attributes: type and code. The type of the node refers to the semantic label symbolized by the node in the code structure, such as method label, local variable label, operator, etc. The code attribute of the node contains the specific implementation details of the node, such as the name of the method, parameter types, and return types.
[0027] For example, the node "label="( <operator>.assignment, data = NULL)"”.
[0028] Among them, ' <operator>.assignment ' indicates that the operation type is assignment, and ' data=NULL ' indicates code. Similar types of operators include basic operations, logical operations, shift operations, ternary operators, compile-time operators, index access, address access, forced conversion, etc.
[0029] Each edge of the graph is represented by "node label" → "node label".
[0030] Step S4, constructing an adjacency matrix of the code attribute graph according to the code attribute graph, and constructing a feature matrix of the node information according to the JSON text; In a possible implementation, constructing an adjacency matrix of a code property graph based on the code property graph includes: parsing a data file of the code property graph, extracting link relationships between nodes in the graph, constructing an adjacency matrix of the graph, and vectorizing graph topology information.
[0031] In an example, if the graph structure G of the function V contains N nodes, the adjacency matrix is represented as A(N×N), and there is a directed edge i→j, then A(i,j)=1, which maps the calling, transfer, and dependency relationships between nodes.
[0032] In a possible implementation, constructing a feature matrix of node information based on JSON text includes: extracting and removing tags in JSON text; removing non-ASCII characters in JSON text and replacing each string constant; classifying and splicing each attribute tag in the order of grammatical information, data dependency, and control flow sequence to obtain a coding sequence of node features. The coding sequence is trained using the Word2Vec model to obtain a feature vector of node information. Feature vectors that are not within a preset length range are eliminated, and the remaining bits of the feature vector are filled with zeros to obtain a feature matrix.
[0033] Specifically, the JSON text is processed. Tags are extracted and removed from the data file, non-ASCII characters are removed, and each string constant is replaced, for example, printf("vTaskStartScheduler") is replaced with printf("str"). Each attribute tag is classified and spliced in the order of grammatical information, data dependency, and control flow sequence to form a coding sequence of node features.
[0034] In one example, a function data dependency is expressed as: [METHOD,eARPProcessPacket,… <operator>.equals, ulTargetProtocolAddress, ==, ulSenderProtocolAddress, METHOD_RETURN, eFrameProcessingResult_t]; The control dependence B is expressed as: <operator>.equals, ulTargetProtocolAddress, ==, ulSenderProtocolAddress, memcpy, memcpy, (, pxARPHeader, ->, xTargetHardwareAddress, …), …, METHOD_RETURN, eFrameProcessingResult_t]; Then, the encoded sequence C of the node features is expressed as: [[METHOD, eARPProcessPacket, … <operator>.equals, ulTargetProtocolAddress, ==, ulSenderProtocolAddress, METHOD_RETURN, eFrameProcessingResult_t, … <operator>.equals, ulTargetProtocolAddress, ==, ulSenderProtocolAddress, memcpy, memcpy, (, pxARPHeader, ->, xTargetHardwareAddress, …), …, METHOD_RETURN, eFrameProcessingResult_t].
[0035] The encoded sequence C is the result of combining various different information in A and B and splicing A and B.
[0036] Next, the encoded sequence obtained by training with the Word2Vec model is used to obtain the feature vector of the node information.
[0037] In one example, "(METHOD RETURN, void, <operator>"assignment, data,...)" is mapped to "(0.12, -0.45, 0.78, 0.67,...)".
[0038] Finally, normalize the length of the feature vectors. Eliminate the samples with feature vector lengths greater than 200 and less than 10. The proportion of this part of the samples is very small and has little impact on the results. Moreover, the overly long vectors contain more information unrelated to buffer overflow vulnerabilities, which affects the learning of the subsequent neural network model. For the samples with feature vector lengths less than 200 but greater than 10, the remaining bits are filled with zeros.
[0039] Step S5: Train a graph neural network model based on the adjacency matrix and the feature matrix to detect buffer overflow vulnerabilities.
[0040] In a possible implementation, training a graph neural network model based on the adjacency matrix and the feature matrix includes: Construct a graph neural network model according to the input layer, the embedding layer, the graph convolutional layer, the attention pooling layer, and the output layer; Among them, the graph convolutional layer includes the first-layer GCN and the second-layer GCN; the activation functions of the first-layer GCN and the second-layer GCN are both ReLU. Figure 3 This is a schematic diagram of the structure of the graph neural network model provided by the embodiments of the present invention.
[0041] In order to amplify the influence of the part related to buffer overflow vulnerabilities in the features, the present invention introduces an attention mechanism pooling layer, which can assign different weights to different nodes during message passing and then aggregate them, enabling the neural network to focus on more important node features on the feature map of each layer.
[0042] In a possible implementation, training a graph neural network model based on the adjacency matrix and the feature matrix includes: importing the adjacency matrix and the feature matrix into the input layer; compressing the adjacency matrix and the feature matrix through the embedding layer, and then transmitting the compressed adjacency matrix and feature matrix to the graph convolutional layer for learning; assigning different weights to different nodes and aggregating them through the attention mechanism pooling layer to obtain attention scores; among them, the attention scores are the node importance scores obtained using GCN. Sort the attention scores of the nodes in descending order and retain a preset proportion of the nodes according to the descending order result to obtain the mask vector of the graph; update the feature matrix and the adjacency matrix according to the mask vector of the graph; output the detected vulnerability type through the output layer to determine whether the detected vulnerability type is consistent with the known vulnerability type.
[0043] In one example, the adjacency matrix A (N×N) and the feature matrix X (N×D) are imported into the input layer; where N is the number of nodes and D is the feature dimension; the embedding layer sets the hidden dimension to M, and the original features are dimensionally reduced through a fully connected network, and then the compressed feature matrix X (N×M) and the Laplacian matrix (N×N) obtained by self-connecting and normalizing are transmitted to a two-layer graph convolutional network for learning; In a possible implementation, to improve the calculation speed, batch processing is adopted. In the process of this invention, multiple graphs are jointly created, the attention scores of each sub-graph are sorted in descending order, and a mask vector for each sub-graph is obtained. The proportion of important nodes is taken as k, and key code features with great influence are screened. The mask vectors of all sub-graphs are concatenated to obtain an updated feature matrix.
[0044] Specifically, the attention scores corresponding to the nodes of the graph are taken out, the results are sorted in descending order to obtain the indices of the nodes to be retained, and the indices of these positions are set to True to obtain the mask vector of each sub-graph node. The mask vectors of all graphs are concatenated together to obtain an updated feature matrix.
[0045] In a possible implementation, forward propagation is performed according to the following formula: ; ; ; where is the feature matrix, is the adjacency matrix, is the adjacency matrix the Laplacian matrix obtained by adding self-connection and normalizing in is the activation function, is the output of the first layer of GCN, is the output of the second layer of GCN, is the output of the graph convolutional layer, is the weight parameter matrix.
[0046] In a possible implementation, the self-attention score is calculated according to the following formula: ; where is the output of the graph convolutional layer, that is, the feature matrix of the nodes output after learning the feature matrix X, is the activation function, is the weight parameter matrix, is the attention score, is the adjacency matrix the Laplacian matrix obtained by adding self-connection and normalizing in
[0047] In a possible implementation, sorting the attention scores of the nodes in descending order and retaining a preset proportion of the nodes according to the descending order result to obtain the mask vector of the graph includes: Obtaining the mask vector of the graph according to the following formula: ; where, is the attention score, is the updated mask vector of the graph, is the index of the nodes retained after sorting the attention scores in descending order, is the proportion of the retained nodes, is the total number of nodes; Updating the feature matrix and the adjacency matrix according to the mask vector of the graph includes: Updating the feature matrix according to the following formula: ; where, is the attention score of the retained nodes, is the hyperbolic tangent function, is the updated feature matrix, is the feature matrix of the retained nodes.
[0048] Performing classification processing through the multi-layer perceptron of the output layer, and the output detection vulnerability types include: Outputting the detection vulnerability types according to the following formula: ; where, is the detection vulnerability type, is the activation function, is the feature matrix output by the pooling layer, is the weight parameter matrix.
[0049] Figure 4 FIG. is a schematic diagram of the working process of the attention pooling layer provided by the embodiment of the present invention. As Figure 4 shown, the structure on the left 1 represents the input training samples, where the circles represent the feature matrices of each node, the solid lines represent the adjacency matrix that can reflect the relationships of each node, the circles in the structure on the left 2 represent the one-dimensional attention scores, and the dotted part in the structure on the left 3 represents the nodes with relatively small corresponding attention score values, that is, the eliminated nodes; the solid line part represents the retained nodes. When the node information changes, the adjacency matrix based on the nodes is also updated correspondingly to filter out unimportant nodes. After non-linearly dynamically adjusting the attention scores of the retained nodes, multiplying them with the feature matrices of the retained nodes to obtain the updated feature matrix, as shown in the structure on the left 4. The main purpose of this step is to enhance the feature strength of the retained nodes.
[0050] The training samples of the present invention are function-level source codes of known vulnerability types. The graph neural network model trains a potential type pattern of buffer overflow vulnerabilities by learning the characteristics of different types of overflows, so as to automatically identify potential overflow vulnerabilities in each module of the FreeRTOS source code and output the judgment result of the vulnerability type or no overflow vulnerability.
[0051] In one example, the present invention selects the vulnerability types as the most common CWE-121: Stack-based Buffer Overflow, CWE-122: Heap-based Buffer Overflow, and CWE-190: Integer Overflow or Wraparound with a relatively high frequency in the vulnerabilities reported in FreeRTOS in recent years.
[0052] The training samples use the code files about CWE-119 (buffer error) in the CGD dataset of the VulDeePecker open-source project, and the required training data extracted therefrom include: 3,669 non-vulnerable codes, 1,827 heap overflow code files, 201 integer overflow code files, and 1,386 stack overflow code files.
[0053] The test samples are function-level split files of the FreeRTOS v10.0.1 source code. The known vulnerabilities and types in FreeRTOS are shown in Table 1. Table 1 is the FreeRTOS vulnerability list.
[0054] Table 1
[0055] The result output of 0, 1, 2, and 3 respectively represents "no overflow vulnerability", "heap overflow vulnerability", "stack overflow vulnerability", and "integer overflow vulnerability".
[0056] Through experiments, using the detection method of the present invention, 7 out of the 8 overflow-type vulnerabilities that have been reported in FreeRTOS are correctly identified, with a precision Pr = 77.8% and a recall Re = 87.5%.
[0057] The graph neural network detection method for FreeRTOS buffer overflow vulnerabilities provided by the present invention detects three common types of buffer overflow vulnerabilities in FreeRTOS: stack overflow, heap overflow, and integer overflow. It uses code features combined with multiple graphical representations of the FreeRTOS source code as samples, fully retaining information such as syntax semantics, control dependencies, and data dependencies in the code. In order to effectively retain the topological structure and node information of the graph feature vectors, a graph neural network is used to train the feature patterns of buffer overflow vulnerabilities in FreeRTOS, and a self-attention mechanism is introduced to highlight the features that have a greater impact on buffer overflow vulnerabilities.
[0058] The graph neural network detection method for FreeRTOS buffer overflow vulnerabilities provided by the present invention has the following technical effects: (1) High efficiency and accuracy: By combining graph neural networks for static analysis and using module-level code slicing, which is beneficial to the integrity of the graph structure representation, the present invention can effectively capture the potential patterns of buffer overflow vulnerabilities from the graph structure of the source code, and has higher accuracy and robustness than traditional methods.
[0059] (2) Automation and intelligence: By automatically generating code property graphs and using deep learning models for vulnerability detection, the present invention significantly reduces the workload of manual analysis and also avoids manual biases in traditional methods.
[0060] (3) Overflow type classification: Different from traditional binary classification methods, the present invention can classify multiple types of buffer overflow vulnerabilities, helping developers accurately locate problems and take more targeted repair measures.
[0061] As described above, the above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.< / operator> < / operator> < / operator> < / operator> < / operator> < / operator> < / operator>
Claims
1. A graph neural network detection method for FreeRTOS buffer overflow vulnerability, characterized in that: include: Get source code for known vulnerability types; Preprocessing the source code and performing function-level code segmentation to obtain multiple function codes; Use the static analysis tool Joern to construct a code property graph of the function code; the JSON text corresponding to the code property graph includes node information and edge information; Construct an adjacency matrix of the code attribute graph according to the code attribute graph, and construct a feature matrix of the node information according to the JSON text; A graph neural network model is obtained by training according to the adjacency matrix and the feature matrix to detect buffer overflow vulnerabilities.
2. The graph neural network detection method according to claim 1, characterized in that: The source code is preprocessed and divided into function-level codes to obtain multiple function codes, including: Scan and remove source code other than function definitions, output to files, and obtain function codes at the function level after segmentation; each file includes only a single function code.
3. The graph neural network detection method according to claim 1, characterized in that: The constructing the feature matrix of the node information according to the JSON text comprises: Extract and remove tags from the JSON text; Remove non-ASCII characters from the JSON text and replace each string constant; Each attribute label is classified and spliced in the order of grammatical information, data dependency, and control flow sequence to obtain the encoding sequence of node features.
4. The graph neural network detection method according to claim 3, characterized in that: The constructing the feature matrix of the node information according to the JSON text further includes: The coding sequence is trained using the Word2Vec model to obtain a feature vector of the node information.
5. The graph neural network detection method according to claim 4, characterized in that: The constructing the feature matrix of the node information according to the JSON text further includes: The feature vectors that are not within a preset length range are eliminated, and the remaining bits of the feature vectors are filled with zeros to obtain the feature matrix.
6. The graph neural network detection method according to claim 1, characterized in that: The training of the graph neural network model according to the adjacency matrix and the feature matrix includes: Construct a graph neural network model based on the input layer, embedding layer, graph convolution layer, attention pooling layer and output layer; The graph convolution layer includes a first GCN layer and a second GCN layer; the activation functions of the first GCN layer and the second GCN layer are both ReLU.
7. The graph neural network detection method according to claim 6, characterized in that: The training of the graph neural network model according to the adjacency matrix and the feature matrix includes: Importing the adjacency matrix and the feature matrix into the input layer; Compressing the adjacency matrix and the feature matrix through the embedding layer, and then transmitting the compressed adjacency matrix and feature matrix to the graph convolution layer for learning; Through the attention mechanism pooling layer, different weights are assigned to different nodes and aggregated to obtain the attention score; Arrange the attention scores of the nodes in descending order and retain a preset proportion of nodes according to the descending order results to obtain the mask vector of the graph; updating the feature matrix and the adjacency matrix according to the mask vector of the graph; The detected vulnerability type is outputted through the output layer to determine whether the detected vulnerability type is consistent with the known vulnerability type.
8. The graph neural network detection method according to claim 7, characterized in that: The step of compressing the adjacency matrix and the feature matrix through the embedding layer and then transmitting the compressed adjacency matrix and the feature matrix to the graph convolution layer for learning includes: Forward propagation is performed according to the following formula: ; ; ; in, is the feature matrix, is the adjacency matrix, is the adjacency matrix The Laplace matrix obtained by adding self-connection and normalization is is the activation function, is the output of the first layer of GCN, is the output of the second layer of GCN, is the output of the graph convolutional layer, is the weight parameter matrix.
9. The graph neural network detection method according to claim 7, characterized in that: The attention mechanism pooling layer assigns different weights to different nodes and aggregates them to obtain the attention scores including: The self-attention score is calculated according to the following formula: ; in, is the output of the graph convolutional layer, is the activation function, is the weight parameter matrix, is the attention score, is the adjacency matrix The Laplacian matrix obtained by adding self-connection and normalization.
10. The graph neural network detection method according to claim 7, characterized in that: The attention scores of the nodes are arranged in descending order and a preset proportion of nodes are retained according to the descending order result, and the mask vector of the graph is obtained, including: The mask vector of the image is obtained according to the following formula: ; in, is the attention score, is the mask vector of the updated image, is the index of the nodes retained after sorting in descending order of attention scores, is the proportion of nodes retained, is the total number of nodes; Updating the feature matrix and the adjacency matrix according to the mask vector of the graph includes: Update the feature matrix according to the following formula: ; in, is the attention score of the retained node, is the hyperbolic tangent function, is the updated feature matrix, is the feature matrix of the retained nodes.
Citation Information
Patent Citations
Source code vulnerability detection method and device and storage medium
CN115017511A
Source code vulnerability static detection and positioning method based on graph neural network
CN115935367A
Operation system code vulnerability detection method, device and equipment and medium
CN116820562A
Power monitoring system main body anomaly detection method, device, equipment and medium
CN117640342A
Android malicious software detection method based on API semantic enhancement
CN119475336A