arXiv:2603.17974cs.SEcs.AI2026-03

自动构建可复现的漏洞数据集,提升代码库级漏洞检测效果

Toward Scalable Automated Repository-Level Datasets for Software Vulnerability Detection

  • 自动化向真实项目注入漏洞并生成可复现的漏洞利用证明
  • 构建了带精确标签的可执行漏洞数据集,支持训练与评估
  • 适用于研究漏洞检测鲁棒性的研究人员和安全工具开发者

软件漏洞数量持续增长且难以检测。尽管基于学习的漏洞检测技术有所进展,但现有基准多以函数为中心,无法反映真实的可执行、跨函数检测场景。近期的代码库级安全基准表明真实环境的重要性,但其人工构建方式限制了规模。本博士研究提出一种自动化基准生成器,能够将真实漏洞注入真实项目,并合成可复现的漏洞利用证明(PoV),从而生成用于训练和评估代码库级漏洞检测代理的精准标注数据集。此外,研究还探索了注入与检测代理之间的对抗协同演化机制,在真实约束下提升检测鲁棒性。

原文摘要 · Abstract (English)

Software vulnerabilities continue to grow in volume and remain difficult to detect in practice. Although learning-based vulnerability detection has progressed, existing benchmarks are largely function-centric and fail to capture realistic, executable, interprocedural settings. Recent repo-level security benchmarks demonstrate the importance of realistic environments, but their manual curation limits scale. This doctoral research proposes an automated benchmark generator that injects realistic vulnerabilities into real-world repositories and synthesizes reproducible proof-of-vulnerability (PoV) exploits, enabling precisely labeled datasets for training and evaluating repo-level vulnerability detection agents. We further investigate an adversarial co-evolution loop between injection and detection agents to improve robustness under realistic constraints.

漏洞检测自动化构建代码库级可复现性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。