Skip to content

FiCoVuL: A Framework for Fine-grained and Cross-function Code Vulnerability Detection

Sep 2026 · ACM Transactions on Software Engineering and Methodology · 0 citations · 71 references

TL;DR

FiCoVuL is presented, a framework for analyzing interconnected functions and providing fine-grained guidance for vulnerability fixing that significantly outperforms other methods in both vulnerability detection and localization.

Abstract

Detecting vulnerabilities in software development is crucial yet challenging. Deep learning-based approaches have shown promise in automatically learning features for vulnerable function detection. In practice, human analysts need to correlate the behavioral logic of multiple functions to confirm the occurrence of vulnerabilities. However, existing works fail to consider the contextual information across functions. Furthermore, human analysts expect models to provide finer-grained explanations to assist in the fixing process. In this paper, we present FiCoVuL, a framework for analyzing interconnected functions and providing fine-grained guidance for vulnerability fixing. FiCoVuL utilizes Function Fusion to extract function definitions and their call relationships from a project, and synthesize multiple functions into one for joint analysis. It models code as a multi-relational graph, capturing rich syntactic and semantic relationships between code statements. A multi-relational graph attention network is leveraged to perform message passing between nodes and edge relationships, generating graph-level and node-level representations. These representations are utilized for vulnerability function prediction and code line ranking, assisting in vulnerability fixing. We evaluate FiCoVuL on a public vulnerability dataset and a self-constructed cross-function one, and compare it with five existing detection models. Experimental results show that FiCoVuL significantly outperforms other methods in both vulnerability detection and localization.

View source

Similar papers

Preprint Sep 2026

SEMA-GUARD: Semantic and Graph-Based Vulnerability Detection in Assembly Code

This article presents SEMA-GUARD, a framework that uses semantic analysis and graph neural networks to identify flaws in assembly code, and results imply that including semantic information in graph-based models may be a successful method for identifying vulnerabilities in compiled code.

H. Dursunoglu, Kaan Sulkalar · 0 citations
Review Open access Sep 2026

Program Graph Learning for Software Vulnerability Analysis: A Survey

Software vulnerabilities represent an enduring threat to modern cyberspace. Effective vulnerability detection increasingly relies on reasoning about complex program semantics, structural dependencies, and execution behaviors. Consequently, extracting vulnerability-relevant features from code efficiently has become a pr...

Jun-Jie Wang, Tong Yu, Ming Li et al. · 0 citations
Sep 2026

HSF-Vul: hierarchical semantic fusion for vulnerability detection

HSF-Vul is proposed, a novel approach for software vulnerability detection and localization based on hierarchical semantic fusion that frame vulnerability detection as a binary classification task and extend it to line-level localization by analyzing the contribution of individual code lines.

Hong-Tao Wang, Xin Yang, Xiao-Feng Liu et al. · 0 citations
Sep 2026

A Unified Framework for Function-Level Vulnerability Detection and Explanation in Smart Contracts

A unified framework combining a novel Hierarchical Cross-Attention Subgraph Neural Network for detection with Large Language Models for explanation form a comprehensive framework that significantly enhances both the technical accuracy and operational usability of smart contract analysis.

Ngoc Minh Nguyen, Le-Minh Nguyen · 0 citations
Conference Aug 2026

An Empirical Study on the Transferability of Transformer-Based Models for Software Vulnerability Detection

Despite the dominance of Transformer-based models in software vulnerability detection, the extent to which their learned security logic generalizes across different programming languages remains a critical open question. To address this, we propose a comprehensive evaluation framework organized into three phases spanni...

Nhien Huu Dinh, Chau The, Thai Hung Van et al. · 0 citations
Book Open access Oct 2026

Bridging Call Boundaries: Inter-procedural Semantic Completion for Graph-Based Vulnerability Detection

Deep learning-based vulnerability detection approaches are limited when vulnerabilities involve multiple functions, where the security effect of a function depends on the behavior of invoked functions. As a result, function-level models may miss key vulnerability-related information across call boundaries. To address t...

Rui-Guo Hu, Dong-Qi Wang, Shu-Jin Yang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.