Applying Contrastive Learning to Code Vulnerability Type Classification
Chen Ji, Su Yang, Hongyu Sun, Yuqing Zhang
摘要
Vulnerability classification is a crucial task in software security analysis, essential for identifying and mitigating potential security risks. Learning-based methods often perform poorly due to the long-tail distribution of vulnerability classification datasets. Recent approaches try to address the problem but treat each CWE class in isolation, ignoring their relationships. This results in non-scalable code vector representations, causing significant performance drops when handling complex realworld vulnerabilities. We propose a hierarchical contrastive learning framework for multiclass code vulnerability type classification to bring vector representations of related CWEs closer together. To address the issue of class collapse and enhance model robustness, we mix self-supervised contrastive learning loss into our loss function. Additionally, we employ max-pooling to enable the model to handle longer vulnerability code inputs. Extensive experiments demonstrate that our proposed framework outperforms state-of-the-art methods by 2.97%-17.90% on accuracy and 0.98%-22.27% on weighted-F1, with even better performance on higher-quality datasets. We also utilize an ablation study to prove each component's contribution. These findings underscore the potential and advantages of our approach in the multi-class vulnerability classification task.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Propagation-Based Vulnerability Impact Assessment for Software Supply ChainsBonan Ruan, Zhiwei Lin, Jiahao Liu, Chuqi Zhang 等ASE 2025 · 被引用 2 次
- XSearch: Explainable Code Search via Concept-to-Code AlignmentYiming Liu, Ruofan Liu, Yun Lin, Zicong Zhang 等ISSTA 2026 · 被引用 1 次
它引用的顶会 Paper19
- Supervised Contrastive LearningPrannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna 等NeurIPS 2020 · 被引用 7,049 次
- SimCSE: Simple Contrastive Learning of Sentence EmbeddingsTianyu Gao, Xingcheng Yao, Danqi ChenEMNLP 2021 · 被引用 2,496 次
- An Empirical Study of Training Self-Supervised Vision TransformersXinlei Chen, Saining Xie, Kaiming HeICCV 2021 · 被引用 2,340 次
- GraphCodeBERT: Pre-training Code Representations with Data FlowDaya Guo, Shuo Ren, Shuai Lu, Zhangyin Feng 等ICLR 2021 · 被引用 1,644 次
- Towards Automated Dynamic Analysis for Linux-based Embedded FirmwareDaming D. Chen, Maverick Woo, David Brumley, Manuel EgeleNDSS 2016 · 被引用 428 次
相关 Paper
- Use All The Labels: A Hierarchical Multi-Label Contrastive Learning FrameworkShu Zhang, Ran Xu, Caiming Xiong, Chetan RamaiahCVPR 2022 · 被引用 71 次
- Improving Smart Contract Security with Contrastive Learning-based Vulnerability DetectionYizhou Chen, Zeyu Sun, Zhihao Gong, Dan HaoICSE 2024 · 被引用 44 次
- One-for-All Does Not Work! Enhancing Vulnerability Detection by Mixture-of-Experts (MoE)Xu Yang, Shaowei Wang, Jiayuan Zhou, Wenhan ZhuFSE 2025 · 被引用 7 次
- Subclass-balancing Contrastive Learning for Long-tailed RecognitionChengkai Hou, Jieyu Zhang, Haonan Wang, Tianyi ZhouICCV 2023 · 被引用 50 次
- Salvaging the Overlooked: Leveraging Class-Aware Contrastive Learning for Multi-Class Anomaly DetectionLei Fan, Junjie Huang, Donglin Di, Anyang Su 等ICCV 2025 · 被引用 8 次
