arXiv:2411.16099cs.SEcs.AI2024-11被引 2

用联邦学习提升漏洞检测效果,解决数据孤岛难题。

An Empirical Study of Vulnerability Detection using Federated Learning

  • 构建VulFL框架,评估联邦学习在漏洞检测中的表现。
  • 相比独立训练,联邦学习显著提升各类漏洞的检测性能。
  • 揭示不同配置策略对联邦学习效果的影响,指导实际应用。

尽管深度学习在漏洞检测中日益流行,但其性能受限于训练数据不足。主要原因在于多数软件组织难以维护高质量的完整样本集,且出于隐私顾虑不愿共享数据,导致数据孤岛问题。联邦学习(FL)因其可在不共享数据的情况下协同训练模型,被视为解决该问题的有前景方案。然而,现有基于FL的漏洞检测方法多针对特定场景,尚不清楚:(i)FL在通用漏洞检测任务中的适应能力如何;(ii)如何为特定任务设计高性能的FL方案。本文提出VulFL,一个有效的评估框架,并基于此开展全面研究,揭示FL在应对不同类别CWE及多种数据异构性场景下的潜在能力。实验结果表明,相较于独立训练,联邦学习在所有调查的CWE类型上均显著提升常见AI模型的检测性能,尽管其表现受数据异构性限制。为进一步凸显不同FL方案的性能差异,本文系统研究了VulFL各组件配置策略的影响。研究为联邦学习在漏洞检测中的潜力提供了洞见,可指导未来FL解决方案的设计。

原文摘要 · Abstract (English)

Although Deep Learning (DL) methods becoming increasingly popular in vulnerability detection, their performance is seriously limited by insufficient training data. This is mainly because few existing software organizations can maintain a complete set of high-quality samples for DL-based vulnerability detection. Due to the concerns about privacy leakage, most of them are reluctant to share data, resulting in the data silo problem. Since enables collaboratively model training without data sharing, Federated Learning (FL) has been investigated as a promising means of addressing the data silo problem in DL-based vulnerability detection. However, since existing FL-based vulnerability detection methods focus on specific applications, it is still far unclear i) how well FL adapts to common vulnerability detection tasks and ii) how to design a high-performance FL solution for a specific vulnerability detection task. To answer these two questions, this paper first proposes VulFL, an effective evaluation framework for FL-based vulnerability detection. Then, based on VulFL, this paper conducts a comprehensive study to reveal the underlying capabilities of FL in dealing with different types of CWEs, especially when facing various data heterogeneity scenarios. Our experimental results show that, compared to independent training, FL can significantly improve the detection performance of common AI models on all investigated CWEs, though the performance of FL-based vulnerability detection is limited by heterogeneous data. To highlight the performance differences between different FL solutions for vulnerability detection, we extensively investigate the impacts of different configuration strategies for each framework component of VulFL. Our study sheds light on the potential of FL in vulnerability detection, which can be used to guide the design of FL-based solutions for vulnerability detection.

联邦学习漏洞检测数据异构AI安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。