Software vulnerability detection method and device based on image and domain adaptation

By combining the fusion processing of code text and image features, the problem of insufficient detection accuracy in existing software vulnerability detection methods is solved, and more efficient vulnerability detection adaptability and accuracy are achieved.

CN120354419APending Publication Date: 2025-07-22NANCHANG HANGKONG UNIVERSITY
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510858968.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-25
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Existing software vulnerability detection methods have the problem of insufficient detection accuracy in the field of deep learning, especially text-based methods that are difficult to capture code structure information, while graph-based methods face difficulties in obtaining labeled data, high computing costs, and insufficient cross-domain adaptability.

Method used

Using software vulnerability detection methods based on image and domain adaptation, the software code is extracted by extracting code text features and image features, combined with bidirectional long and short-term memory network and graph construction technology, feature fusion is carried out and detection is used using a preset vulnerability detection model.

Benefits of technology

It improves the accuracy of vulnerability detection, can more accurately identify vulnerabilities in the software, adapt to code differences in different domains, and improves detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354419A_ABST
    Figure CN120354419A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the field of data processing and machine learning, and provides a software vulnerability detection method and device based on image and domain adaptation, and the method comprises the steps: obtaining a first software code of to-be-detected software; performing code text feature extraction on the first software code to obtain a first code text feature; performing code image feature extraction on the first software code to obtain a second code image feature and a third code image feature; performing feature fusion processing on the first code text feature, the second code image feature and the third code image feature to obtain a fused feature; and performing vulnerability detection on the first software code by adopting the fusion feature through the preset vulnerability detection model to obtain a vulnerability detection result, so that a more accurate vulnerability detection result can be obtained, and improvement of the accuracy of the vulnerability detection process is facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical fields of data processing and machine learning, and particularly relates to a software vulnerability detection method and device based on images and domain adaptation. Background Art

[0002] Currently, software vulnerability detection in the field of deep learning mainly includes text-based methods and graph-based methods. The text-based methods regard code as natural language processing, but it is difficult to capture code structure information, resulting in limited detection accuracy; although the graph-based methods can model complex relationships, they face difficulties in obtaining a large amount of labeled data, high costs, and time-consuming processing of graph structures. In addition, image-based methods such as VulCNN are difficult to fully retain details when converting code into images, and there are also defects such as insufficient cross-domain adaptability, resulting in inaccurate current vulnerability detection and difficulty in meeting the growing software security guarantee requirements. Summary of the Invention

[0003] An embodiment of the present application provides a software vulnerability detection method and device based on images and domain adaptation, which can obtain more accurate vulnerability detection results and is beneficial to improving the accuracy of the vulnerability detection process.

[0004] In a first aspect of an embodiment of the present application, a software vulnerability detection method based on images and domain adaptation is provided. The method includes: Obtain a first software code of the software to be detected; Extract code text features from the first software code to obtain first code text features; Extract code image features from the first software code to obtain second code image features and third code image features; Perform feature fusion processing on the first code text features, the second code image features, and the third code image features to obtain fusion features; Use the fusion features to perform vulnerability detection on the first software code through a preset vulnerability detection model to obtain a vulnerability detection result.

[0005] In a possible implementation manner, the extracting code text features from the first software code to obtain first code text features includes: Perform serialization processing on the first software code to obtain a first code token sequence; Perform context embedding processing on the first code token sequence to obtain a vector representation of each code token; Perform context-dependent relationship capture construction on the vector representation of each code token to obtain first code text features.

[0006] In a possible implementation, the extracting of code image features from the first software code to obtain second code image features and third code image features includes: Performing normalization processing on the first software code to obtain a second software code; Performing graph construction on the second software code to obtain a target program dependency graph; Performing three-channel image construction based on the target program dependency graph and the corresponding degree centrality to obtain a three-channel image of the target program dependency graph; Performing local structure feature extraction on the three-channel image to obtain second code image features; Obtaining the attention coefficient of each node in the target program dependency graph; Performing overall structure feature extraction based on the attention coefficient of each node and the corresponding initial features to obtain third code image features.

[0007] In a possible implementation, the feature fusion processing of the first code text features, second code image features, and third code image features to obtain fusion features includes: Performing feature fusion on the first code text features and the second code image features to obtain a first reference feature; Performing feature fusion on the first code text features and the third code image features to obtain a second reference feature; Performing feature fusion on the second code text features and the third code image features to obtain a third reference feature; Performing weighted fusion on the first reference feature, the second reference feature, and the third reference feature to obtain fusion features.

[0008] In a possible implementation, the loss function of the preset vulnerability detection model is represented by the following formula: ; ; ; Wherein, is the loss function of the vulnerability classifier, is the loss function of the domain classifier, is the hyperparameter for adjusting the weights of the two classifiers, is the number of source domain samples, and the source domain samples , is 's feature, is the predicted class of the vulnerability classifier; is the predicted domain label, is the actual domain label, and N is the number of target domain samples.

[0009] In the second aspect of the embodiments of the present application, a software vulnerability detection device based on image and domain adaptation is provided. The device includes: An acquisition unit, configured to acquire the first software code of the software to be detected; A first extraction unit, configured to extract code text features from the first software code to obtain first code text features; A second extraction unit, configured to extract code image features from the first software code to obtain second code image features and third code image features; A fusion unit, configured to perform feature fusion processing on the first code text features, second code image features, and third code image features to obtain fusion features; A detection unit, configured to perform vulnerability detection on the first software code by using the fusion features through a preset vulnerability detection model to obtain a vulnerability detection result.

[0010] In a possible implementation manner, the first extraction unit is specifically configured to: Perform serialization processing on the first software code to obtain a first code token sequence; Perform context embedding processing on the first code token sequence to obtain a vector representation of each code token; Perform context-dependent relationship capture construction on the vector representation of each code token to obtain first code text features.

[0011] In a possible implementation manner, the second extraction unit is specifically configured to: Perform normalization processing on the first software code to obtain a second software code; Perform graph construction on the second software code to obtain a target program dependency graph; Perform three-channel image construction on the target program dependency graph according to the target program dependency graph and the corresponding degree centrality to obtain a three-channel image of the target program dependency graph; Perform local structure feature extraction on the three-channel image to obtain second code image features; Obtain the attention coefficient of each node in the target program dependency graph; Perform overall structure feature extraction according to the attention coefficient of each node and the corresponding initial features to obtain third code image features.

[0012] In a possible implementation manner, the fusion unit is specifically configured to: Perform feature fusion on the first code text features and the second code image features to obtain a first reference feature; Perform feature fusion on the first code text features and the third code image features to obtain a second reference feature; Perform feature fusion on the second code text feature and the third code image feature to obtain a third reference feature; Perform weighted fusion on the first reference feature, the second reference feature, and the third reference feature to obtain a fusion feature.

[0013] In a possible implementation, the loss function of the preset vulnerability detection model is represented by the following formula: ; ; ; Among them, is the loss function of the vulnerability classifier, is the loss function of the domain classifier, is a hyperparameter for adjusting the weights of the two classifiers, is the number of source domain samples, and the source domain samples , is feature of, is the predicted class of the vulnerability classifier; is the predicted domain label, is the actual domain label, and N is the number of target domain samples.

[0014] The third aspect of the embodiments of the present application provides a terminal, including a processor, an input device, an output device, and a memory. The processor, the input device, the output device, and the memory are interconnected. Among them, the memory is used to store a computer program, and the computer program includes program instructions. The processor is configured to call the program instructions to execute the step instructions as in the first aspect of the embodiments of the present application.

[0015] The fourth aspect of the embodiments of the present application provides a computer-readable storage medium. Among them, the above computer-readable storage medium stores a computer program for electronic data exchange. Among them, the above computer program enables a computer to execute some or all of the steps described in the first aspect of the embodiments of the present application.

[0016] The fifth aspect of the embodiments of the present application provides a computer program product. Among them, the above computer program product includes a non-transitory computer-readable storage medium storing a computer program. The above computer program is operable to enable a computer to execute some or all of the steps described in the first aspect of the embodiments of the present application. This computer program product can be a software installation package.

[0017] Implementing the embodiments of the present application has the following beneficial effects: By obtaining the first software code of the software to be detected, extracting the code text features from the first software code to obtain the first code text features, extracting the code image features from the first software code to obtain the second code image features and the third code image features, performing feature fusion processing on the first code text features, the second code image features and the third code image features to obtain the fusion features, and using the fusion features to detect vulnerabilities in the first software code through a preset vulnerability detection model to obtain the vulnerability detection results. Therefore, it is possible to perform feature fusion by combining the text features and image features of the code to obtain the fusion features, and finally perform vulnerability detection based on the fusion features, so as to obtain more accurate vulnerability detection results, which is beneficial to improving the accuracy of the vulnerability detection process. Brief Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0019] Figure 1 This is a schematic diagram of the application environment of a software vulnerability detection method based on image and domain adaptation provided by an embodiment of the present application; Figure 2 This is a schematic flowchart of a software vulnerability detection method based on image and domain adaptation provided by an embodiment of the present application; Figure 3 This is a schematic flowchart of the learning stage of a preset vulnerability detection model provided by an embodiment of the present application; Figure 4 This is a schematic diagram of the structure of a terminal provided by an embodiment of the present application; Figure 5 This is a schematic diagram of the structure of a software vulnerability detection device based on image and domain adaptation provided by an embodiment of the present application. Detailed Description of the Embodiments

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0021] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices.

[0022] Reference to "embodiments" in this application means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments.

[0023] In order to better understand the software vulnerability detection method based on image and domain adaptation provided by the embodiment of the present application, the following first briefly introduces the scenario of applying the software vulnerability detection method based on image and domain adaptation. With the increasing role of software in daily life, software vulnerability issues have become a security risk that needs to be solved urgently. Deep learning technology has attracted widespread attention due to its outstanding performance in fields such as image recognition and natural language processing, and has gradually been applied to the field of software security to improve the effectiveness of vulnerability detection. At present, vulnerability detection methods based on deep learning are mainly divided into two categories: text-based methods and graph-based methods. The former treats the source code as plain text and uses natural language processing technology for analysis, but this method is difficult to capture the deep semantic information of the code; the latter uses complex graph neural networks to extract features, which can more deeply understand the code structure and its potential meaning, thereby achieving a higher detection accuracy. However, the graph-based method has the limitations of complex graph structure construction process and high computational cost.

[0024] In response to the above problems, this application proposes an innovative vulnerability detection method based on image representation (Vulnerability Detection Domain Adaptation). Vulnerability Detection Domain Adaptation VulDA is an improved VulCNN. Vulnerability Detection Domain Adaptation VulDA can combine the text features and image features of the code to obtain fused features, and finally perform vulnerability detection based on the fused features, which can obtain more accurate vulnerability detection results and help improve the accuracy of the vulnerability detection process.

[0025] Among them, VulCNN is an image-based vulnerability detection method aimed at achieving large-scale source code vulnerability detection. VulCNN saves the information of the code graph with node centrality, then converts it into an image, and then conducts vulnerability detection. However, there are differences between codes, and the training data (such as open-source codes, historical vulnerability samples) and the codes in actual applications often come from different domains. There may be significant differences in style, syntax, or structure between these domains, and actual projects often lack vulnerability labels. To solve the above problems, this application conducts domain adaptation representation learning considering the differences between the source code and the target code, uses the code dataset with vulnerability labels as the source code to participate in the training process of vulnerability classification, and uses the test dataset as the target code to jointly train the domain classifier with the source code.

[0026] The embodiments of this application aim to solve the problem of low accuracy in software vulnerability detection, and provide a software vulnerability detection method based on image and domain adaptation, which can combine the text features and image features of the code to perform feature fusion to obtain fusion features, and finally conduct vulnerability detection based on the fusion features, and can obtain more accurate vulnerability detection results, which is beneficial to improving the accuracy of the vulnerability detection process.

[0027] The software vulnerability detection method based on image and domain adaptation can be applied in an application environment such as Figure 1 In this application environment, the client communicates with the server through the network. Exemplarily, taking the scenario of detecting vulnerabilities in software as an example, the target user (manager or R & D personnel) can upload the first software code of the software to be detected through the client. Correspondingly, the server can obtain the first software code of the software to be detected through the client, extract the text features and image features of the first software code, then fuse the features to obtain fusion features, and then can use the preset vulnerability detection model to conduct vulnerability detection on the first software code with the fusion features, and can obtain more accurate vulnerability detection results, and feedback the vulnerability detection results to the client. Correspondingly, the client can receive the vulnerability detection results from the server and can display the vulnerability detection results on the client for the target user to query or browse. By adopting the software vulnerability detection method based on image and domain adaptation provided by this application, more accurate vulnerability detection results can be obtained, which is beneficial to improving the accuracy of the vulnerability detection process.

[0028] Among them, the client can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices. The server can be implemented by an independent server or a server cluster composed of multiple servers. The present invention will be described in detail through specific embodiments below.

[0029] Please refer to Figure 2 , Figure 2The flowchart of a software vulnerability detection method based on image and domain adaptation is provided for the embodiments of this application. As Figure 2 shown, the method includes: 201. Obtain the first software code of the software to be detected.

[0030] Among them, the software to be detected can be used to indicate the specific software program that needs to conduct vulnerability investigation. The first software code can be used to indicate the source code corresponding to the software to be detected. Optionally, the first software code can be written in a specific programming language, such as Java, Python, C++, etc., and can contain the specific instructions and logic for the software to implement various functions, which is the basic object for subsequent analysis and detection.

[0031] 202. Extract code text features from the first software code to obtain first code text features.

[0032] The first software code can be serialized, then context embedding can be performed, and finally dependency relationship capture and construction can be carried out to obtain the first code text features. When performing dependency relationship capture and construction, a pre-set bidirectional long short-term memory network (BiLSTM) model can be used for capture and construction to obtain the first code text features.

[0033] 203. Extract code image features from the first software code to obtain second code image features and third code image features.

[0034] When performing image feature extraction, first, the first software code can be normalized to obtain a second software code, and then the second software code can be used for code image feature extraction to obtain second code image features and third code image features.

[0035] Specifically, a target program dependency graph is constructed according to the second software code, and then the second code image features and third code image features are obtained based on the target program dependency graph.

[0036] When performing normalization processing, specifically, it can be: (1) Delete comments: Comments are meaningless to the model, so they are deleted to prevent interference with the code feature extraction process.

[0037] (2) Rename function names and variable names: Since programmers have different coding habits, the naming of functions and variables is unique, and personalized naming hardly contains any vulnerability information and is very likely to make the model consider too many unnecessary details. Therefore, VulDA renames the user-defined function names and variable names. For example, for variable names, they are changed to VAR1, VAR2, etc.; for function names, they are changed to FUN1, FUN2, etc.

[0038] 204. Perform feature fusion processing on the first code text feature, the second code image feature, and the third code image feature to obtain a fusion feature.

[0039] Among them, pairwise feature fusion can be performed on the first code text feature, the second code image feature, and the third code image feature to obtain three reference features, and finally the three reference features are fused to obtain a fusion feature. When performing pairwise fusion as much as possible, a bidirectional multi-head cross-attention mechanism can be used for fusion processing.

[0040] 205. Use the fusion feature to perform vulnerability detection on the first software code through a preset vulnerability detection model to obtain a vulnerability detection result.

[0041] Among them, the preset vulnerability detection model includes a feature extractor, a vulnerability classifier, and a domain classifier. The feature extractor is used to extract shared discriminative features from source domain samples and target domain samples; the vulnerability classifier (Vulnerability Classifier) is a binary classifier trained only with source domain data to determine whether the code has vulnerabilities; the domain classifier (Domain Classifier) is used in the adversarial training module to determine whether the input sample comes from the source domain or the target domain.

[0042] Thus, the fusion feature can be input into the preset vulnerability detection model for vulnerability detection to obtain a vulnerability detection result.

[0043] In this example, by obtaining the first software code of the software to be detected, performing code text feature extraction on the first software code to obtain a first code text feature, performing code image feature extraction on the first software code to obtain a second code image feature and a third code image feature, performing feature fusion processing on the first code text feature, the second code image feature, and the third code image feature to obtain a fusion feature, and using the fusion feature to perform vulnerability detection on the first software code through a preset vulnerability detection model to obtain a vulnerability detection result. Therefore, it is possible to combine the text features and image features of the code to perform feature fusion to obtain a fusion feature, and finally perform vulnerability detection based on the fusion feature, which can obtain a more accurate vulnerability detection result and is beneficial to improving the accuracy of the vulnerability detection process.

[0044] In a possible implementation manner, a method for performing code text feature extraction on the first software code to obtain a first code text feature includes: A1. Serialize the first software code to obtain a first code token sequence; A2. Perform context embedding processing on the first code token sequence to obtain a vector representation of each code token; A3. Perform context-dependent capture construction on the vector representation of each code token to obtain the first code text feature.

[0045] Among them, the first software code can be tokenized and serialized to obtain the first code token sequence. The first code token sequence can be expressed as: , where C is the first code token sequence, is the i-th code token in the first code token sequence.

[0046] The BERT model can be used to perform context embedding processing on the code tokens in the first code token sequence to obtain the vector representation of each code token. Specifically, it can be characterized as: ; Among them, is the output embedding matrix, and d is the embedding dimension.

[0047] The bidirectional long short-term memory network (BiLSTM) model is adopted to further capture the context dependencies in the sequence, and finally the first code text feature of the code is obtained. The first code text feature is expressed as: ; Among them, is the first code text feature, is the feature dimension.

[0048] Thus, the text feature extraction of the first software code can be performed quickly and accurately, improving the efficiency.

[0049] In a possible implementation, a method for extracting code image features from the first software code to obtain the second code image feature and the third code image feature includes: B1. Normalize the first software code to obtain the second software code; B2. Construct a graph from the second software code to obtain the target program dependency graph; B3. Perform three-channel image construction based on the target program dependency graph and the corresponding degree centrality to obtain the three-channel image of the target program dependency graph; B4. Extract local structure features from the three-channel image to obtain the second code image feature; B5. Obtain the attention coefficient of each node in the target program dependency graph; B6. Perform overall structure feature extraction based on the attention coefficient of each node and the corresponding initial feature to obtain the third code image feature.

[0050] Among them, when performing the normalization process, specifically: (1)Delete comments: Comments are meaningless to the model, so they are deleted to prevent interference with the feature extraction process of the code.

[0051] (2)Rename function names and variable names: Since programmers have different coding habits, the naming of functions and variables is unique, and personalized naming hardly contains any vulnerability information and may even cause the model to consider too many unnecessary details. Therefore, VulDA renames the function and variable names defined by users. For example, for variable names, they are changed to VAR1, VAR2, etc.; for function names, they are changed to FUN1, FUN2, etc.

[0052] Graph construction can be understood as a way to structurally represent software code. The software code itself is in text form, with relatively complex and non-intuitive logical relationships. Through graph construction, various elements in the code (such as functions, variables, statements, etc.) and their relationships (such as control flow relationships, data flow relationships) can be clearly presented in the form of a graph.

[0053] The target program dependency graph can be used to indicate the specific results obtained through graph construction. The target program dependency graph can fully display the internal dependency relationships of the code. It can include control flow information, that is, the order and flow control of code execution. For example, in conditional judgment statements, different code blocks are executed according to different conditions; and data flow information, such as where variables are assigned values and where they are used, that is, how data flows between different code parts.

[0054] A possible specific method for graphically constructing the second software code to obtain a target program dependency graph can be as follows: B21. Standardize the second software code to obtain the standardized second software code; B22. Use a preset program dependency graph construction method to graphically construct the second software code to obtain a reference program dependency graph. The program dependency graph includes the control flow information and data flow information in the second software code; B23. Encode the reference program dependency graph to obtain the target program dependency graph.

[0055] Since the second software code is the source code corresponding to the software to be detected, there may be inconsistencies or non-compliance with subsequent processing requirements in terms of format, coding specifications, etc. Therefore, the original second software code can be standardized, that is, the second software code is adjusted in specification, so that the second software code reaches a unified and regular state in terms of structure, syntax representation, etc., so as to more smoothly perform the operation of constructing the program dependency graph subsequently.

[0056] For example, different programmers may have different indentation habits, variable naming styles, etc. when writing code. Standardization processing can unify the indentation format of the code, organize variable names according to established naming specifications, and also standardize the comments in the code (such as unifying the format and position of comments), or remove some redundant content that does not affect the code logic but interferes with subsequent analysis. After standardization processing, the standardized second software code can be more regular in form and is more conducive to subsequent graph construction operations based on rules and algorithms.

[0057] The preset method for constructing a program dependency graph can be a set of established rules, algorithms, or combinations of tools for converting software code into a program dependency graph. Commonly, it can be by means of specialized code analysis tools (such as Joern, etc.), by parsing the syntax structure of the code, the execution order between statements, and the usage and assignment of variables, etc., and generating a program dependency graph according to specific graph construction algorithms. It can be understood that different programming languages may require adapting corresponding construction methods to deeply analyze the logical components of the code, sort out the mutual relationships between code elements, and thus accurately construct a graphical structure that can reflect the internal connections of the code.

[0058] The reference program dependency graph can be used to indicate the preliminary graphical result obtained after constructing the standardized second software code by the above preset method for constructing a program dependency graph. The reference program dependency graph can display the key information inside the second software code in the form of a graph, such as the control flow information and data flow information in the second software code.

[0059] Among them, the control flow information can reflect the execution sequence of the code and the execution path affected by control structures such as conditional judgments and loops. For example, in a code containing an "if-else" conditional judgment statement, according to the conditional judgment result, it is decided whether to execute the code block of the "if" branch or the "else" branch. The execution sequence and selection relationship based on conditions between such different code blocks are the manifestations of the control flow information in the code and can be clearly shown in the reference program dependency graph through nodes (representing elements such as code blocks) and edges (indicating the association of execution sequences).

[0060] The data flow information can focus on the flow of data in the code, mainly involving the definition and use of variables and the transfer process of data between different statements and functions. For example, if a variable is assigned a value in a certain statement and then read and participated in operations in subsequent other statements, this series of data operation trajectories of the variable is the data flow information. In the reference program dependency graph, it can also be presented by appropriate connections between nodes and edges to facilitate intuitively seeing how data flows between different parts of the code.

[0061] Coding processing can perform operations to further process the reference program dependency graph, so as to represent various types of information in the reference program dependency graph in a form that is more convenient for subsequent computer processing, analysis, and connection with other modules (such as subsequent parts related to image detection). During the coding processing, it may involve assigning corresponding numerical, vector, etc. coding representations to the nodes and edges in the graph according to specific coding rules. For example, assign a unique numerical identifier to each node, and describe the attributes of the node (such as the type of code element it represents, its position in the code, etc.) and its connection relationship with other nodes (the situation of the edges) using specific vectors.

[0062] Through the above coding processing, the reference program dependency graph originally presented intuitively in a graphical structure can be transformed into a data form that is more easily stored, transmitted, and algorithmically operated within the computer. The resulting target program dependency graph is the program dependency graph optimized through coding processing and can be used for subsequent operations such as calculating node importance parameters.

[0063] The degree centrality of the nodes in the target program dependency graph can be calculated. Specifically, a general degree centrality calculation method can be used for the calculation. After determining the target program dependency graph, then vectorize the nodes. This application uses the Sent2vec model for embedding. It is an unsupervised model used to map a sentence to a fixed-length vector. This application needs to use an image to represent the target program dependency graph (PDG). Therefore, regard the PDG as a network and perform centrality analysis on it to measure the importance of the nodes, that is, the importance of the code lines. In the target program dependency graph, each node corresponds to a certain line of code, and the edges include control dependency edges and data dependency edges.

[0064] Degree centrality refers to the number of connecting edges a node has, that is, the degree of the node. A node with a high degree centrality usually means it has more direct connections in the network; Closeness centrality measures the reciprocal of the average distance from a node to all other nodes. Specifically, it is defined as the sum of the number of steps or weights of the shortest paths; Katz centrality not only considers the direct connections of the nodes but also considers the nodes connected through indirect paths.

[0065] Multiply each node by its corresponding three centralities to obtain the three channels of the image, that is, a three-channel image. The three-channel image can be expressed as: ; where I is the three-channel image, PDG is the target program dependency graph, and GraphToImage() is the algorithm for converting the graph structure into an image structure.

[0066] Local feature extraction can be performed using the CNN local feature extraction model to obtain the second code image feature. The second code image feature can be expressed as: ; where is the second code image feature, is the feature dimension.

[0067] Therefore, centrality and CNN can be used to extract local structural features, and finally the second code image feature is obtained, improving the accuracy when obtaining the second code image feature.

[0068] The overall structural feature extraction can be combined with the attention coefficient of the node and the initial feature to obtain the third code image feature, specifically: Let represent the target program dependency graph, where is the node set, is the edge set.

[0069] The update of each node is determined by the attention mechanism: ; ; where is the initial feature of node i, represents the neighbor set of node i, is the learnable transformation matrix, is the attention coefficient, is the attention vector, represents vector concatenation, is the activation function. Finally, the overall structural feature is obtained through GAT: ; where is the third code image feature, is the feature dimension, and GAT() is the graph attention network.

[0070] In a possible implementation, a method for performing feature fusion processing on the first code text feature, the second code image feature, and the third code image feature to obtain a fusion feature includes: C1. Perform feature fusion on the first code text feature and the second code image feature to obtain a first reference feature; C2. Perform feature fusion on the first code text feature and the third code image feature to obtain a second reference feature; C3. Perform feature fusion on the second code text feature and the third code image feature to obtain a third reference feature; C4. Perform weighted fusion on the first reference feature, the second reference feature, and the third reference feature to obtain a fused feature.

[0071] Among them, for any two of the first code text feature, the second code image feature, and the third code image feature and , use the multi-head attention mechanism to calculate the cross-fused feature. Let the query, key, and value pass through linear transformations respectively: , , , then the attention output is: ; where is the dimension of the Key vector. The multi-head attention is obtained by concatenating H parallel attention heads: , where is a learnable matrix.

[0072] The bidirectional structure then performs calculations with and as the query and key-value swapped respectively, and the resulting bidirectional attention result can be expressed as: , .

[0073] Thus, the feature of the text focusing on the image information and the feature of the image focusing on the text information are obtained. Then, use the weighted average strategy to fuse the features to obtain : ; where is a learnable parameter. Similarly, and can be obtained. Finally, the feature fusing all modal information is obtained: ; where is the fused feature, and are learnable parameters.

[0074] Thus, the accuracy in determining the fused feature can be improved.

[0075] In a possible implementation, the loss function of the preset vulnerability detection model is characterized by the following formula: ; ; ; where, is the loss function of the vulnerability classifier, is the loss function of the domain classifier, is the hyperparameter for adjusting the weights of the two classifiers, is the number of source domain samples, and the source domain samples , is feature of ; the predicted class of the vulnerability classifier is the predicted domain label, is the actual domain label, and N is the number of target domain samples.

[0076] Specifically, as Figure 3 shown, a gradient reversal layer (Gradient Reversal Layer, GRL) and a domain classifier (Domain Classifier) are introduced into the preset vulnerability detection model. By adversarial training, the distribution difference between the source domain and the target domain is minimized, thereby improving the vulnerability detection ability of the model on the target domain, the gradient reversal layer.

[0077] The preset vulnerability detection model includes three main modules, which are specifically as follows: Feature Extractor (not shown in Figure 3 ): Extract shared discriminative features from source domain and target domain samples; Vulnerability Classifier: A binary classifier trained only with source domain data to determine whether the code has vulnerabilities; Domain Classifier: An adversarial training module to determine whether the input sample comes from the source domain or the target domain.

[0078] For the source domain sample , the vulnerability prediction is output through the vulnerability classifier: ; where is feature of , and is the predicted class. Using the cross-entropy loss function, the loss function is: ; where

[0079] Let the label of the source domain sample be , and the label of the target domain sample be . The feature after passing through the GRL is input into the domain classifier, and the predicted domain label is: ; the corresponding loss function is ; The entire network is trained in a jointly optimized manner, and the total loss function is as follows: ; where is a hyperparameter for adjusting the weights of the two classifiers.

[0080] Consistent with the above embodiments, please refer to Figure 4 , Figure 4 which is a schematic structural diagram of a terminal provided by an embodiment of the present application. As shown in Figure 4 , it includes a processor, an input device, an output device, and a memory. The processor, the input device, the output device, and the memory are interconnected. Among them, the memory is used to store a computer program, and the computer program includes program instructions. The processor is configured to call the program instructions, and the above program includes instructions for performing the following steps; Obtain the first software code of the software to be detected; Extract the code text features of the first software code to obtain the first code text features; Extract the code image features of the first software code to obtain the second code image features and the third code image features; Perform feature fusion processing on the first code text features, the second code image features, and the third code image features to obtain fusion features; Use the fusion features to detect vulnerabilities in the first software code through a preset vulnerability detection model to obtain a vulnerability detection result.

[0081] The above mainly introduces the solution of the embodiment of the present application from the perspective of the execution process of the method side. It can be understood that in order for the terminal to implement the above functions, it includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments provided in this article, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0082] The embodiment of the present application can divide the functions of the terminal according to the above method examples. For example, each function unit can be divided corresponding to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of a software function unit. It should be noted that the division of units in the embodiment of the present application is illustrative, only a logical function division, and there can be other division methods in actual implementation.

[0083] For those consistent with the above, please refer to Figure 5 , Figure 5 This application embodiment provides a structural schematic diagram of a software vulnerability detection device based on image and domain adaptation. As Figure 5 shown, the device includes: An acquisition unit 501, configured to acquire a first software code of the software to be detected; A first extraction unit 502, configured to extract code text features from the first software code to obtain first code text features; A second extraction unit 503, configured to extract code image features from the first software code to obtain second code image features and third code image features; A fusion unit 504, configured to perform feature fusion processing on the first code text features, second code image features, and third code image features to obtain fusion features; A detection unit 505, configured to perform vulnerability detection on the first software code by using the fusion features through a preset vulnerability detection model to obtain a vulnerability detection result.

[0084] In a possible implementation manner, the first extraction unit 502 is specifically configured to: Perform serialization processing on the first software code to obtain a first code token sequence; Perform context embedding processing on the first code token sequence to obtain a vector representation of each code token; Perform context-dependent relationship capture construction on the vector representation of each code token to obtain first code text features.

[0085] In a possible implementation manner, the second extraction unit 503 is specifically configured to: Perform normalization processing on the first software code to obtain a second software code; Perform graph construction on the second software code to obtain a target program dependency graph; Perform three-channel image construction on the target program dependency graph according to the target program dependency graph and the corresponding degree centrality to obtain a three-channel image of the target program dependency graph; Perform local structure feature extraction on the three-channel image to obtain second code image features; Obtain the attention coefficient of each node in the target program dependency graph; Perform overall structure feature extraction according to the attention coefficient of each node and the corresponding initial features to obtain third code image features.

[0086] In a possible implementation manner, the fusion unit 504 is specifically configured to: Perform feature fusion on the first code text feature and the second code image feature to obtain a first reference feature; Perform feature fusion on the first code text feature and the third code image feature to obtain a second reference feature; Perform feature fusion on the second code text feature and the third code image feature to obtain a third reference feature; Perform weighted fusion on the first reference feature, the second reference feature, and the third reference feature to obtain a fused feature.

[0087] In a possible implementation manner, the loss function of the preset vulnerability detection model is represented by the following formula: ; ; ; wherein, is the loss function of the vulnerability classifier, is the loss function of the domain classifier, is a hyperparameter for adjusting the weights of the two classifiers, is the number of source domain samples, and the source domain samples , is feature of, is the predicted class of the vulnerability classifier; is the predicted domain label, is the actual domain label, and N is the number of target domain samples.

[0088] The embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute some or all of the steps of any one of the software vulnerability detection methods based on image and domain adaptation recorded in the above method embodiments.

[0089] The embodiment of the present application also provides a computer program product, the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program enables a computer to execute some or all of the steps of any one of the software vulnerability detection methods based on image and domain adaptation recorded in the above method embodiments.

[0090] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0091] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0092] In several embodiments provided by this application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling, direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.

[0093] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0094] In addition, in each embodiment of the application, the various functional units can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software program modules.

[0095] If the integrated unit is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned memory includes various media that can store program codes, such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), external hard drives, magnetic disks, or optical discs.

[0096] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory can include: flash drives, read-only memories, random access memories, magnetic disks, or optical discs, etc.

[0097] The above has introduced the embodiments of this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A software vulnerability detection method based on image and domain adaptation, characterized in that The method includes: Obtaining the first software code of the software to be detected; Performing code text feature extraction on the first software code to obtain first code text features; Performing code image feature extraction on the first software code to obtain second code image features and third code image features; Performing feature fusion processing on the first code text features, second code image features, and third code image features to obtain fusion features; Using the fusion features to perform vulnerability detection on the first software code through a preset vulnerability detection model to obtain a vulnerability detection result.

2. The software vulnerability detection method based on image and domain adaptation according to claim 1, characterized in that The performing code text feature extraction on the first software code to obtain first code text features includes: Performing serialization processing on the first software code to obtain a first code token sequence; Performing context embedding processing on the first code token sequence to obtain a vector representation of each code token; Performing context-dependent relationship capture construction on the vector representation of each code token to obtain first code text features.

3. The software vulnerability detection method based on image and domain adaptation according to claim 2, wherein The performing code image feature extraction on the first software code to obtain second code image features and third code image features includes: Performing normalization processing on the first software code to obtain a second software code; Performing graph construction on the second software code to obtain a target program dependency graph; Performing three-channel image construction based on the target program dependency graph and the corresponding degree centrality to obtain a three-channel image of the target program dependency graph; Performing local structure feature extraction on the three-channel image to obtain second code image features; Obtaining the attention coefficient of each node in the target program dependency graph; Performing overall structure feature extraction based on the attention coefficient of each node and the corresponding initial features to obtain third code image features.

4. The software vulnerability detection method based on image and domain adaptation according to claim 2 or 3, characterized in that, The performing feature fusion processing on the first code text features, second code image features, and third code image features to obtain fusion features includes: Performing feature fusion on the first code text features and second code image features to obtain a first reference feature; Performing feature fusion on the first code text features and third code image features to obtain a second reference feature; Performing feature fusion on the second code text features and third code image features to obtain a third reference feature; Performing weighted fusion on the first reference feature, second reference feature, and third reference feature to obtain fusion features.

5. The software vulnerability detection method based on image and domain adaptation according to claim 4, wherein The loss function of the preset vulnerability detection model is represented by the following formula: ; ; ; Among them, is the loss function of the vulnerability classifier, is the loss function of the domain classifier, is the hyperparameter for adjusting the weights of the two classifiers, is the number of source domain samples, and the source domain samples , is the predicted class of the vulnerability classifier; is the predicted domain label, is the actual domain label, and N is the number of target domain samples.

6. A software vulnerability detection device based on image and domain adaptation, characterized in that, The apparatus includes: An obtaining unit, configured to obtain the first software code of the software to be detected; A first extraction unit, configured to perform code text feature extraction on the first software code to obtain first code text features; A second extraction unit, configured to perform code image feature extraction on the first software code to obtain second code image features and third code image features; A fusion unit, configured to perform feature fusion processing on the first code text features, second code image features, and third code image features to obtain fusion features; A detection unit, configured to perform vulnerability detection on the first software code through a preset vulnerability detection model using the fusion features to obtain a vulnerability detection result.

7. The software vulnerability detection device based on image and domain adaptation according to claim 6, wherein The first extraction unit is specifically configured to: Serialize the first software code to obtain a first code token sequence; Perform context embedding processing on the first code token sequence to obtain a vector representation of each code token; Perform context dependency capture construction on the vector representation of each code token to obtain first code text features.

8. The software vulnerability detection device based on image and domain adaptation according to claim 7, wherein, The second extraction unit is specifically configured to: Normalize the first software code to obtain a second software code; Perform graph construction on the second software code to obtain a target program dependency graph; Perform three-channel image construction based on the target program dependency graph and the corresponding degree centrality to obtain a three-channel image of the target program dependency graph; Extract local structure features from the three-channel image to obtain second code image features; Obtain the attention coefficient of each node in the target program dependency graph; Extract overall structure features based on the attention coefficient of each node and the corresponding initial features to obtain third code image features.

9. A terminal, characterized in that, Comprising a processor, an input device, an output device, and a memory, the processor, the input device, the output device, and the memory are interconnected, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is configured to call the program instructions to execute the software vulnerability detection method based on image and domain adaptation according to any one of claims 1-6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to execute the software vulnerability detection method based on image and domain adaptation according to any one of claims 1-6.

Citation Information

Patent Citations

  • Software vulnerability detection method and system based on deep learning

    CN117056919A

  • Vulnerability code detection method based on multi-dimensional feature extraction

    CN117454387A

  • Industrial protocol software source code vulnerability detection and positioning method based on association diagram

    CN117744085A

  • Multi-modal feature fusion Android malicious software detection method based on attention mechanism

    CN118194288A

  • Method for automatically detecting software vulnerabilities by using feature fusion based on deep learning

    CN118364471A