InterGNN: Using Context for Detecting Inter-procedural Vulnerabilities
Vulnerability detection is an important activity in industrial software engineering. This is due to high security and safety demands in domains like automotive or aerospace. We observe that many machine-learning based approaches for vulnerability detection have been proposed in the last years, but that most of them only consider individual functions. However, our experience in automotive software shows that more context is required to judge about potential vulnerabilities.
This work introduces InterGNN, a graph-based model designed for vulnerability identification that leverages interprocedural information from real-world C/C++ programs. The approach constructs Code Property Graphs containing data- and control-flow relationships and uses a GNN architecture to generate node-level code embeddings. We combine that model with a label propagation mechanism that highlights vulnerable execution paths across function calls. We evaluate InterGNN on a public dataset (InterPVD) and one industry-grade dataset of embedded C code (AooB). Our experiments demonstrate that InterGNN matches state-of-the-art performance and outperforms competitive baselines, such as ReVeal, by up to 6.9% points in F1 score when interprocedural context is involved.
While these gains are promising, especially in large real-world code bases, safety-relevant systems still prioritize high recall, often guaranteed by the application of Static Application Security Testing tools. In this context, InterGNN is not meant to operate in isolation but to complement such recall-oriented analyses by improving precision and thus reducing the manual review effort in industrial vulnerability detection pipelines. These results highlight the practicality of InterGNN for real-world vulnerability detection.
Thu 19 MarDisplayed time zone: Athens change
11:00 - 12:30 | Session 4B - Vulnerability Detection and LocalizationEarly Research Achievement (ERA) Track / Research Track / Short Papers and Posters Track / Industrial Track at Megaron Beta Chair(s): Pierre van de Laar TNO-ESI | ||
11:00 15mTalk | InterGNN: Using Context for Detecting Inter-procedural Vulnerabilities Industrial Track Sebastian Sierra Bosch Research, Jochen Quante Bosch Research, Eric Bodden Heinz Nixdorf Institute at Paderborn University & Fraunhofer IEM | ||
11:15 15mTalk | VFLAGENT: A Chain-of-Thought-Guided Multi-Agent Collaboration Framework for Vulnerable Function Localization Research Track Minghe Bai Nanjing University of Posts and Telecommunications, Wei Chen Institute of Software at Chinese Academy of Sciences, Shuo Li Nankai University, China;Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences;, Jiaxin Zhu Institute of Software at Chinese Academy of Sciences | ||
11:30 15mTalk | VulCMS: A Vulnerability Detection System Based on Centrality Analysis and Multi-Scale Attention Research Track Wenjing Cai School of Cybersecurity, Northwestern Polytechnical University, Jianfei Wang School of Software, Northwestern Polytechnical University, Jianfei Wang School of Software, Northwestern Polytechnical University, Lipeng Gao School of Software, Northwestern Polytechnical University | ||
11:45 15mTalk | Towards Secure Oracle Usage: Understanding and Detecting Oracle Vulnerabilities in Smart Contracts Research Track Ziming Chen Peking University, Yue Li Peking University, Jiashuo Zhang Peking University, China, Jianbo Gao Peking University, Che Wang Peking University, China, Jiakun Hao Peking University, Anming Xie Peking University, Zhi Guan Peking University, Zhong Chen | ||
12:00 7mTalk | Synergizing LLM-Driven Semantic Reasoning with Assertion-Guided Analysis for Enhanced Vulnerability Detection Early Research Achievement (ERA) Track Ying Wang Xidian University, Jie Su Xidian University, Cheng Wen Xidian University, rong wang , Cong Tian Xidian University, Zhenhua Duan Xidian University, Shengchao Qin Xidian University Media Attached | ||
12:07 7mTalk | Toward Reliable Detection of Malicious eBPF: Construction and Validation of a Large-Scale Bytecode Dataset Short Papers and Posters Track Yujin Kwon Duksung Women’s University, Yujeong Choi Duksung Women’s University, Dohwan Ji Hanbat National University, Jinyoung Kim Sungkyunkwan University | ||
12:14 7mTalk | Towards Online Malware Detection using Process Resource Utilization Metrics Short Papers and Posters Track Themistoklis Diamantopoulos Electrical and Computer Engineering Dept, Aristotle University of Thessaloniki, Dimosthenis Natsos Aristotle University of Thessaloniki, Andreas Symeonidis Electrical and Computer Engineering Dept., Aristotle University of Thessaloniki Pre-print | ||
12:21 8mTalk | From Data Leak to Secret Misses: The Impact of Data Leakage on Secret Detection Models Short Papers and Posters Track | ||