Bridging Call Boundaries: Inter-procedural Semantic Completion for Graph-Based Vulnerability Detection
Abstract
Deep learning-based vulnerability detection approaches are limited when vulnerabilities involve multiple functions, where the security effect of a function depends on the behavior of invoked functions. As a result, function-level models may miss key vulnerability-related information across call boundaries. To address this issue, we propose VulSCG, a graph-based vulnerability detection framework with inter-procedural semantic completion. VulSCG first retrieves callee implementations from the corresponding project version and uses LLMs to generate structured summaries of their input, output and security-relevant behaviors. The generated summaries are injected into the caller Code Property Graph as SummaryNodes, allowing inter-procedural security semantics to participate in graph learning without expanding the full callee graph. Experiments on Devign show that VulSCG outperforms representative learning-based vulnerability detection baselines. In particular, VulSCG achieves the best F1 score on the dataset, with a F1 improvement of 4.25% over the strongest baseline. These results indicate that VulSCG improves detection effectiveness while maintaining scalability, since it complements inter-procedural semantics through compact SummaryNodes rather than full callee graph expansion.