TY - GEN
T1 - Multi-View Graph-Based Code Representation Learning for Vulnerability Detection
AU - Yuan, Zheng
AU - Shan, Chun
AU - Heng, Pengzhe
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Vulnerability detection is essential for ensuring software reliability and security. Existing learning-based approaches often fail to fully capture fine-grained program semantics and heterogeneous structural dependencies. In particular, directly merging different code representations into a unified graph may introduce semantic ambiguity and weaken vulnerability-specific signals. To address this issue, we propose SMGCN, a semantic-aware multi-view graph framework for vulnerability detection. SMGCN independently models abstract syntax, control flow, and data flow as separate graph views, preserving their structural characteristics. A node importance recalibration mechanism is introduced to emphasize vulnerability-relevant nodes, and an attention-based fusion module adaptively integrates multi-view representations into a unified embedding for classification. Extensive experiments on four benchmark datasets demonstrate that SMGCN consistently outperforms representative learning-based and LLM-based baselines, achieving average improvements of 7.18% in accuracy and 11.0% in F1-score. Additional analyses further validate the effectiveness of multi-view modeling and node importance calibration. These results highlight the advantage of semantic-aware multi-view graph learning for robust vulnerability detection.
AB - Vulnerability detection is essential for ensuring software reliability and security. Existing learning-based approaches often fail to fully capture fine-grained program semantics and heterogeneous structural dependencies. In particular, directly merging different code representations into a unified graph may introduce semantic ambiguity and weaken vulnerability-specific signals. To address this issue, we propose SMGCN, a semantic-aware multi-view graph framework for vulnerability detection. SMGCN independently models abstract syntax, control flow, and data flow as separate graph views, preserving their structural characteristics. A node importance recalibration mechanism is introduced to emphasize vulnerability-relevant nodes, and an attention-based fusion module adaptively integrates multi-view representations into a unified embedding for classification. Extensive experiments on four benchmark datasets demonstrate that SMGCN consistently outperforms representative learning-based and LLM-based baselines, achieving average improvements of 7.18% in accuracy and 11.0% in F1-score. Additional analyses further validate the effectiveness of multi-view modeling and node importance calibration. These results highlight the advantage of semantic-aware multi-view graph learning for robust vulnerability detection.
KW - Code Vulnerability Detection
KW - GCN
KW - Representation Learning
UR - https://www.scopus.com/pages/publications/105041626744
U2 - 10.1109/GAIIS69281.2026.11519277
DO - 10.1109/GAIIS69281.2026.11519277
M3 - Conference contribution
AN - SCOPUS:105041626744
T3 - 2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
SP - 310
EP - 316
BT - 2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2026 International Conference on Generative Artificial Intelligence and Information Security, GAIIS 2026
Y2 - 27 March 2026 through 29 March 2026
ER -