• Home
  • Search
  • Can explainability and deep-learning be used for localizing vulnerabilities in source code?
  • Cite Icon10
  • https://doi.org/10.1145/3644032.3644448Copy DOI Icon

Can explainability and deep-learning be used for localizing vulnerabilities in source code?

  • Apr 15, 2024
  • Alessandro Marchetto
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Security vulnerabilities are weaknesses of software due for instance to design flaws or implementation bugs that can be exploited and lead to potentially devastating security breaches. Traditionally, static code analysis is recognized as effective in the detection of software security vulnerabilities but at the expense of a high human effort required for checking a large number of produced false positive cases. Deep-learning methods have been recently proposed to overcome such a limitation of static code analysis and detect the vulnerable code by using vulnerability-related patterns learned from large source code datasets. However, the use of these methods for localizing the causes of the vulnerability in the source code, i.e., localize the statements that contain the bugs, has not been extensively explored.

Similar Papers
  • Conference Article
  • Citations8

Code Vulnerability Identification and Code Improvement using Advanced Machine Learning

  • Dec 01, 2019
  • Laneesha Ruggahakotuwa +2
  • Research Article
  • Citations59

Static analysis of source code security: Assessment of tools against SAMATE tests

  • Feb 13, 2013
  • Information and Software Technology
  • Gabriel Díaz +1
  • Conference Article
  • Citations2

Static Code Analysis Tool for Laravel Framework Based Web Application

  • Nov 03, 2021
  • Ranindya Paramitha +1
  • Research Article
  • Citations7

Insecurity Refactoring: Automated Injection of Vulnerabilities in Source Code

  • Jan 27, 2023
  • Computers & Security
  • Felix Schuckert +2
  • Research Article

DeepSeek-Rl Family Large Language Models in the Tasks of Identification, Classification, and Detection of Vulnerabilities from the CWE Top 25 List

  • Mar 18, 2026
  • PROGRAMMNAYA INGENERIA
  • V V Shvyrov +2
  • Conference Article
  • Citations21

Explaining Static Analysis - A Perspective

  • Nov 01, 2019
  • Marcus Nachtigall +2
  • Research Article
  • Citations5

Source Code Vulnerability Detection Based on Joint Graph and Multimodal Feature Fusion

  • Feb 28, 2025
  • Electronics
  • Dun Jin +4
  • Research Article
  • Citations3

VISION: Robust and Interpretable Code Vulnerability Detection Leveraging Counterfactual Augmentation

  • Oct 15, 2025
  • Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society
  • David Egea +2
  • Research Article
  • Citations1

JACoW : Experience with static PLC code analysis at CERN

  • Feb 20, 2018
  • CERN Bulletin
  • Christina Tsiplaki Spiliopoulou +2
  • Research Article

Security Mechanisms and Vulnerability Detection in Python Packages: A Comprehensive Review

  • Mar 16, 2026
  • International Journal of Scientific Research in Engineering and Management
  • Md Irfan Alam +3
  • PDF
  • Research Article
  • Citations1

Building and Storing in Graph Database Neo4j Abstract Symantic Graph of PHP Applications Source Code

  • Dec 28, 2020
  • NaUKMA Research Papers. Computer Science
  • Trokhym Babych +1
  • Conference Article
  • Citations16

New Tricks to Old Codes: Can AI Chatbots Replace Static Code Analysis Tools?

  • Jun 14, 2023
  • Omer Said Ozturk +4
  • Conference Article
  • Citations433

Using Machine Learning for Vulnerability Detection and Classification.

  • Jan 01, 2021
  • arXiv (Cornell University)
  • Tiago Baptista +2
  • Conference Article
  • Citations3

Empirically Examining the Quality of Source Code in Engineering Software Systems

  • May 01, 2018
  • Jens K Carter +2
  • Conference Article
  • Citations12

Automatic Identification of Vulnerable Code: Investigations with an AST-Based Neural Network

  • Jul 01, 2021
  • Garrett Partenza +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.