When Less is Enough: Positive and Unlabeled Learning Model for Vulnerability Detection
Wen, Xin-Cheng, Wang, Xinchen, Gao, Cuiyun, Wang, Shaohua, Liu, Yang, Gu, Zhaoquan
–arXiv.org Artificial Intelligence
Automated code vulnerability detection has gained increasing attention in recent years. The deep learning (DL)-based methods, which implicitly learn vulnerable code patterns, have proven effective in vulnerability detection. The performance of DL-based methods usually relies on the quantity and quality of labeled data. However, the current labeled data are generally automatically collected, such as crawled from human-generated commits, making it hard to ensure the quality of the labels. Prior studies have demonstrated that the non-vulnerable code (i.e., negative labels) tends to be unreliable in commonly-used datasets, while vulnerable code (i.e., positive labels) is more determined. Considering the large numbers of unlabeled data in practice, it is necessary and worth exploring to leverage the positive data and large numbers of unlabeled data for more accurate vulnerability detection. In this paper, we focus on the Positive and Unlabeled (PU) learning problem for vulnerability detection and propose a novel model named PILOT, i.e., PositIve and unlabeled Learning mOdel for vulnerability deTection. PILOT only learns from positive and unlabeled data for vulnerability detection. It mainly contains two modules: (1) A distance-aware label selection module, aiming at generating pseudo-labels for selected unlabeled data, which involves the inter-class distance prototype and progressive fine-tuning; (2) A mixed-supervision representation learning module to further alleviate the influence of noise and enhance the discrimination of representations.
arXiv.org Artificial Intelligence
Aug-21-2023
- Country:
- Oceania > Australia
- Victoria > Melbourne (0.04)
- New South Wales > Sydney (0.04)
- North America
- Mexico (0.04)
- Dominican Republic (0.04)
- United States
- Maryland > Baltimore (0.04)
- District of Columbia > Washington (0.04)
- Washington > King County
- Seattle (0.04)
- Pennsylvania > Allegheny County
- Pittsburgh (0.04)
- New York > New York County
- New York City (0.04)
- Nevada > Clark County
- Las Vegas (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- California > San Diego County
- San Diego (0.04)
- Canada
- Quebec > Montreal (0.04)
- Ontario > National Capital Region
- Ottawa (0.04)
- Europe
- Spain
- Galicia > Madrid (0.04)
- Catalonia > Barcelona Province
- Barcelona (0.04)
- France
- Hauts-de-France > Nord
- Lille (0.04)
- Auvergne-Rhône-Alpes > Lyon
- Lyon (0.04)
- Hauts-de-France > Nord
- Belgium > Flanders
- West Flanders > Bruges (0.04)
- Flemish Brabant > Leuven (0.04)
- Spain
- Asia
- South Korea > Seoul
- Seoul (0.04)
- Singapore > Central Region
- Singapore (0.04)
- Middle East
- China
- Guangdong Province > Shenzhen (0.04)
- Shanghai > Shanghai (0.04)
- Liaoning Province > Shenyang (0.04)
- Heilongjiang Province > Harbin (0.04)
- South Korea > Seoul
- Oceania > Australia
- Genre:
- Research Report > New Finding (1.00)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: