Skip to content
Conference

A GNN-based vulnerability explanation method with learnable edge-type weights

Aug 2026 · International Conference on Industrial IoT, Big Data, and Smart Cities · Vol 14325, pp. 143251L - 143251L-7 · 0 citations · 16 references
Engineering

Abstract

With the in-depth advancement of hardware-software integration in smart cities and industrial systems, cybersecurity vulnerability threats have become increasingly severe. Graph Neural Network (GNN)-based vulnerability detection technologies have been widely adopted due to their efficient modeling capabilities for code semantics and structures. However, the “black-box” nature of their prediction process severely restricts their practical deployment. Existing general-purpose GNN explanation methods fail to consider the differential impacts of edge types in code graphs on vulnerability formation in vulnerability explanation scenarios, leading to disconnection from the requirements of vulnerability explanation. To address this issue, this paper proposes a vulnerability explanation method integrating learnable edge-type weights, denoted as GE4Vul. This method introduces learnable edge-type weights and L2 regularization constraints, and generates fine-grained explanations pointing to vulnerable code lines through weighted edge mask calculation and node importance ranking. Experiments on three real-world open-source project datasets (FFmpeg, ImageMagick, and radare2) demonstrate that GE4Vul achieves superior explanation accuracy compared to GNNExplainer and PGExplainer, providing targeted technical support for subsequent vulnerability cause analysis and remediation.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.