{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,23]],"date-time":"2026-08-23T17:26:31Z","timestamp":1787505991117,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T00:00:00Z","timestamp":1670198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF","award":["1820685"],"award-info":[{"award-number":["1820685"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,12,5]]},"DOI":"10.1145\/3564625.3564655","type":"proceedings-article","created":{"date-parts":[[2022,12,2]],"date-time":"2022-12-02T20:01:29Z","timestamp":1670011289000},"page":"497-507","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":16,"title":["Compact Abstract Graphs for Detecting Code Vulnerability with GNN Models"],"prefix":"10.1145","author":[{"given":"Yu","family":"Luo","sequence":"first","affiliation":[{"name":"Division of Computing, Analytics and Mathematics, University of Missouri - Kansas City, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weifeng","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Criminal Justice, The University of Baltimore, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dianxiang","family":"Xu","sequence":"additional","affiliation":[{"name":"Division of Computing, Analytics and Mathematics, University of Missouri - Kansas City, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[\n  1\n  ]  M. Allamanis M. Brockschmidt and M. Khademi. \u201cLearning to represent programs with graphs\u201d. In: arXiv preprint arXiv:1711.00740 (2017).  [1] M. Allamanis M. Brockschmidt and M. Khademi. \u201cLearning to represent programs with graphs\u201d. In: arXiv preprint arXiv:1711.00740 (2017)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3054830"},{"key":"e_1_3_2_1_3_1","unstructured":"[\n  3\n  ]  X. Bresson and T. Laurent. \u201cResidual gated graph convnets\u201d. In: arXiv preprint arXiv:1711.07553 (2017).  [3] X. Bresson and T. Laurent. \u201cResidual gated graph convnets\u201d. In: arXiv preprint arXiv:1711.07553 (2017)."},{"key":"e_1_3_2_1_4_1","volume-title":"https:\/\/www.checkmarx.com","year":"2006","unstructured":"[ 4 ] Checkmarx. Checkmarx. https:\/\/www.checkmarx.com . 2006 . [4] Checkmarx. Checkmarx. https:\/\/www.checkmarx.com. 2006."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2009.77"},{"key":"e_1_3_2_1_6_1","first-page":"406","volume-title":"(2004)","author":"Chinchani R.","unstructured":"[ 6 ] R. Chinchani , A. Iyer , B. Jayaraman , and S Upadhyaya . \u201c ARCHERR: Runtime Environment Driven Program Safety \u201d. In: (2004) , pp. 385\u2013 406 . [6] R. Chinchani, A. Iyer, B. Jayaraman, and S Upadhyaya. \u201cARCHERR: Runtime Environment Driven Program Safety\u201d. In: (2004), pp. 385\u2013406."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"[\n  7\n  ]  M. Choi S. Jeong H. Oh and J. Choo. \u201cEnd-to-end prediction of buffer over runs from raw source code via neural memory networks\u201d. In: arXiv preprint arXiv:1703.02458 (2017).  [7] M. Choi S. Jeong H. Oh and J. Choo. \u201cEnd-to-end prediction of buffer over runs from raw source code via neural memory networks\u201d. In: arXiv preprint arXiv:1703.02458 (2017).","DOI":"10.24963\/ijcai.2017\/214"},{"key":"e_1_3_2_1_8_1","unstructured":"[\n  8\n  ]  Common Vulnerabilities and Exposures. https:\/\/cve.mitre.org.  [8] Common Vulnerabilities and Exposures. https:\/\/cve.mitre.org."},{"key":"e_1_3_2_1_9_1","unstructured":"[\n  9\n  ]  H.K. Dam T. Tran T. Pham S.W. Ng J. Grundy and A. Ghose. \u201cAutomatic feature learning for vulnerability prediction\u201d. In: arXiv preprint arXiv:1708.02368(2017).  [9] H.K. Dam T. Tran T. Pham S.W. Ng J. Grundy and A. Ghose. \u201cAutomatic feature learning for vulnerability prediction\u201d. In: arXiv preprint arXiv:1708.02368(2017)."},{"key":"e_1_3_2_1_10_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding","author":"Devlin J.","year":"2018","unstructured":"[ 10 ] J. Devlin , M. Chang , K. Lee , and K. Toutanova . BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding . 2018 . arXiv:1810.04805 [cs.CL]. [10] J. Devlin, M. Chang, K. Lee, and K. Toutanova. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. 2018. arXiv:1810.04805 [cs.CL]."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-017-5069-3"},{"key":"e_1_3_2_1_12_1","unstructured":"[\n  12\n  ]  Eclipse CDT. https:\/\/wiki.eclipse.org\/Getting_started_with_CDT_development.  [12] Eclipse CDT. https:\/\/wiki.eclipse.org\/Getting_started_with_CDT_development."},{"key":"e_1_3_2_1_13_1","unstructured":"[\n  13\n  ]  Eclipse JDT. https:\/\/www.eclipse.org\/jdt\/core\/.  [13] Eclipse JDT. https:\/\/www.eclipse.org\/jdt\/core\/."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"[\n  14\n  ]  Z. Feng D. Guo D. Tang N. Duan X. Feng M. Gong L. Shou B. Qin T. Liu D. Jiang etal \u201cCodebert: A pre-trained model for programming and natural languages\u201d. In: arXiv preprint arXiv:2002.08155 (2020).  [14] Z. Feng D. Guo D. Tang N. Duan X. Feng M. Gong L. Shou B. Qin T. Liu D. Jiang et al. \u201cCodebert: A pre-trained model for programming and natural languages\u201d. In: arXiv preprint arXiv:2002.08155 (2020).","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"e_1_3_2_1_15_1","unstructured":"[\n  15\n  ]  Flawfinder. Flawfinder. http:\/\/www.dwheeler.com\/flawfinder.  [15] Flawfinder. Flawfinder. http:\/\/www.dwheeler.com\/flawfinder."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3240480"},{"key":"e_1_3_2_1_17_1","volume-title":"Network and Distributed System Security Symposium.","author":"Godefroid P.","year":"2008","unstructured":"[ 17 ] P. Godefroid , M. Levin , and D. Molnar . \u201c Automated whitebox fuzz testing \u201d. In: Network and Distributed System Security Symposium. 2008 . [17] P. Godefroid, M. Levin, and D. Molnar. \u201cAutomated whitebox fuzz testing\u201d. In: Network and Distributed System Security Symposium. 2008."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ANZIIS.1994.396988"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2372225.2372230"},{"key":"e_1_3_2_1_20_1","volume-title":"International Conference on Learning Representations.","author":"Kipf Thomas N","year":"2017","unstructured":"[ 20 ] Thomas N Kipf and Max Welling . \u201c Semi-Supervised Classification with Graph Convolutional Networks \u201d. In: International Conference on Learning Representations. 2017 . [20] Thomas N Kipf and Max Welling. \u201cSemi-Supervised Classification with Graph Convolutional Networks\u201d. In: International Conference on Learning Representations. 2017."},{"key":"e_1_3_2_1_21_1","volume-title":"Sorry ma\u2019am you didn\u2019t win $43M - there was a slot machine \u2018malfunction\u2019. Ed. by Ars Technica","author":"Kravets D.","year":"2017","unstructured":"[ 21 ] D. Kravets . Sorry ma\u2019am you didn\u2019t win $43M - there was a slot machine \u2018malfunction\u2019. Ed. by Ars Technica . June 2017 . url: https:\/\/arstechnica.com\/tech-policy\/2017\/06\/sorry-maam-you-didnt-win-43m-there-was-a-slot-machine-malfunction\/. [21] D. Kravets. Sorry ma\u2019am you didn\u2019t win $43M - there was a slot machine \u2018malfunction\u2019. Ed. by Ars Technica. June 2017. url: https:\/\/arstechnica.com\/tech-policy\/2017\/06\/sorry-maam-you-didnt-win-43m-there-was-a-slot-machine-malfunction\/."},{"key":"e_1_3_2_1_22_1","volume-title":"International Conference on Learning Representations.","author":"Le T.","year":"2018","unstructured":"[ 22 ] T. Le , T. Nguyen , T. Le , D. Phung , P. Montague , O. De Vel , and L. Qu . \u201c Maximal divergence sequential autoencoder for binary software vulnerability detection \u201d. In: International Conference on Learning Representations. 2018 . [22] T. Le, T. Nguyen, T. Le, D. Phung, P. Montague, O. De Vel, and L. Qu. \u201cMaximal divergence sequential autoencoder for binary software vulnerability detection\u201d. In: International Conference on Learning Representations. 2018."},{"key":"e_1_3_2_1_23_1","volume-title":"KSII the 9th international conference on internet (ICONI) 2017 symposium.","author":"Lee Y.","year":"2017","unstructured":"[ 23 ] Y. Lee , S. Choi , C. Kim , S. Lim , and K. Park . \u201c Learning binary code with deep learning to detect software weakness \u201d. In: KSII the 9th international conference on internet (ICONI) 2017 symposium. 2017 . [23] Y. Lee, S. Choi, C. Kim, S. Lim, and K. Park. \u201cLearning binary code with deep learning to detect software weakness\u201d. In: KSII the 9th international conference on internet (ICONI) 2017 symposium. 2017."},{"key":"e_1_3_2_1_24_1","unstructured":"[\n  24\n  ]  Y. Li D. Tarlow M. Brockschmidt and R. Zemel. \u201cGated graph sequence neural networks\u201d. In: arXiv preprint arXiv:1511.05493 (2015).  [24] Y. Li D. Tarlow M. Brockschmidt and R. Zemel. \u201cGated graph sequence neural networks\u201d. In: arXiv preprint arXiv:1511.05493 (2015)."},{"key":"e_1_3_2_1_25_1","article-title":"Sysevr: A framework for using deep learning to detect software vulnerabilities","author":"Li Z.","year":"2021","unstructured":"[ 25 ] Z. Li , D. Zou , S. Xu , H. Jin , Y. Zhu , and Z. Chen . \u201c Sysevr: A framework for using deep learning to detect software vulnerabilities \u201d. In: IEEE Transactions on Dependable and Secure Computing ( 2021 ). [25] Z. Li, D. Zou, S. Xu, H. Jin, Y. Zhu, and Z. Chen. \u201cSysevr: A framework for using deep learning to detect software vulnerabilities\u201d. In: IEEE Transactions on Dependable and Secure Computing (2021).","journal-title":"IEEE Transactions on Dependable and Secure Computing ("},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23158"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3138840"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2821768"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3095196"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI52525.2021.00115"},{"key":"e_1_3_2_1_31_1","volume-title":"PREfast Analysis Tool. https:\/\/msdn.microsoft.com\/en-us\/library\/ms933794.aspx","year":"2012","unstructured":"[ 31 ] Microsoft. PREfast Analysis Tool. https:\/\/msdn.microsoft.com\/en-us\/library\/ms933794.aspx . 2012 . [31] Microsoft. PREfast Analysis Tool. https:\/\/msdn.microsoft.com\/en-us\/library\/ms933794.aspx. 2012."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SWAN.2015.7070488"},{"key":"e_1_3_2_1_33_1","unstructured":"[\n  33\n  ]  National Vulnerability Database. https:\/\/nvd.nist.gov.  [33] National Vulnerability Database. https:\/\/nvd.nist.gov."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.99"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-25159-2_49"},{"key":"e_1_3_2_1_36_1","unstructured":"[\n  36\n  ]  PyG. https:\/\/pytorch-geometric.readthedocs.io\/en\/latest\/.  [36] PyG. https:\/\/pytorch-geometric.readthedocs.io\/en\/latest\/."},{"key":"e_1_3_2_1_37_1","unstructured":"[\n  37\n  ]  Pytorch. https:\/\/pytorch.org\/.  [37] Pytorch. https:\/\/pytorch.org\/."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884877"},{"key":"e_1_3_2_1_40_1","volume-title":"NIST Software Assurance Reference Dataset Project. https:\/\/samate.nist.gov\/SRD\/testsuite.php","author":"SARD.","year":"2019","unstructured":"[ 40 ] SARD. NIST Software Assurance Reference Dataset Project. https:\/\/samate.nist.gov\/SRD\/testsuite.php . 2019 . [40] SARD. NIST Software Assurance Reference Dataset Project. https:\/\/samate.nist.gov\/SRD\/testsuite.php. 2019."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2340398"},{"key":"e_1_3_2_1_42_1","unstructured":"[\n  42\n  ]  C.D. Sestili W.S. Snavely and N.M. VanHoudnos. \u201cTowards security defect prediction with AI\u201d. In: arXiv preprint arXiv:1808.09897 (2018).  [42] C.D. Sestili W.S. Snavely and N.M. VanHoudnos. \u201cTowards security defect prediction with AI\u201d. In: arXiv preprint arXiv:1808.09897 (2018)."},{"key":"e_1_3_2_1_43_1","first-page":"29","volume-title":"Detection of malicious code by applying machine learning classifiers on static features: A state-of the-art survey\u201d. In: information security technical report 14.1 (2009)","author":"Shabtai A.","unstructured":"[ 43 ] A. Shabtai , R. Moskovitch , Y. Elovici , and C. Glezer . \u201c Detection of malicious code by applying machine learning classifiers on static features: A state-of the-art survey\u201d. In: information security technical report 14.1 (2009) , pp. 16\u2013 29 . [43] A. Shabtai, R. Moskovitch, Y. Elovici, and C. Glezer. \u201cDetection of malicious code by applying machine learning classifiers on static features: A state-of the-art survey\u201d. In: information security technical report 14.1 (2009), pp. 16\u201329."},{"key":"e_1_3_2_1_44_1","unstructured":"[\n  44\n  ]  Yunsheng Shi Zhengjie Huang Shikun Feng Hui Zhong Wenjin Wang and Yu Sun. \u201cMasked label prediction: Unified message passing model for semi supervised classification\u201d. In: arXiv preprint arXiv:2009.03509 (2020).  [44] Yunsheng Shi Zhengjie Huang Shikun Feng Hui Zhong Wenjin Wang and Yu Sun. \u201cMasked label prediction: Unified message passing model for semi supervised classification\u201d. In: arXiv preprint arXiv:2009.03509 (2020)."},{"key":"e_1_3_2_1_45_1","first-page":"16857","article-title":"Mpnet: Masked and permuted pre-training for language understanding","volume":"33","author":"Song K.","year":"2020","unstructured":"[ 45 ] K. Song , X. Tan , T. Qin , J. Lu , and T. Liu . \u201c Mpnet: Masked and permuted pre-training for language understanding \u201d. In: Advances in Neural Information Processing Systems 33 ( 2020 ), pp. 16857 \u2013 16867 . [45] K. Song, X. Tan, T. Qin, J. Lu, and T. Liu. \u201cMpnet: Masked and permuted pre-training for language understanding\u201d. In: Advances in Neural Information Processing Systems 33 (2020), pp. 16857\u201316867.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_46_1","volume-title":"International Conference on Learning Representations.","author":"Petar","year":"2018","unstructured":"[ 46 ] Petar V., Guillem C., Arantxa C., Adriana R., Pietro L., and Yoshua B . \u201c Graph Attention Networks \u201d. In: International Conference on Learning Representations. 2018 . [46] Petar V., Guillem C., Arantxa C., Adriana R., Pietro L., and Yoshua B. \u201cGraph Attention Networks\u201d. In: International Conference on Learning Representations. 2018."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00275"},{"key":"e_1_3_2_1_48_1","first-page":"1943","article-title":"Combining Graph-based Learning with Automated Data Collection for Code Vulnerability Detection","volume":"16","author":"Wang H.","year":"2020","unstructured":"[ 48 ] H. Wang , G. Ye , Z. Tang , S.H. Tan , S. Huang , D. Fang , Y. Feng , L. Bian , and Z. Wang . \u201c Combining Graph-based Learning with Automated Data Collection for Code Vulnerability Detection \u201d. In: IEEE TIFS 16 ( 2020 ), pp. 1943 \u2013 1958 . [48] H. Wang, G. Ye, Z. Tang, S.H. Tan, S. Huang, D. Fang, Y. Feng, L. Bian, and Z. Wang. \u201cCombining Graph-based Learning with Automated Data Collection for Code Vulnerability Detection\u201d. In: IEEE TIFS 16 (2020), pp. 1943\u20131958.","journal-title":"IEEE TIFS"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884804"},{"key":"e_1_3_2_1_50_1","volume-title":"Network & Distributed System Security Symposium (NDSS2009)","author":"Wang T.","year":"2009","unstructured":"[ 50 ] T. Wang , T. Wei , Z. Lin , and W. Zou . \u201c IntScope: Automatically Detecting Integer Overflow Vulnerability In X86 Binary Using Symbolic Execution \u201d. In: Network & Distributed System Security Symposium (NDSS2009) . 2009 . [50] T. Wang, T. Wei, Z. Lin, and W. Zou. \u201cIntScope: Automatically Detecting Integer Overflow Vulnerability In X86 Binary Using Symbolic Execution\u201d. In: Network & Distributed System Security Symposium (NDSS2009). 2009."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-4380-9_16"},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of Chaos Communication Congress","author":"Wojtczuk R.","year":"2005","unstructured":"[ 52 ] R. Wojtczuk . \u201c UQBTng: a tool capable of automatically nding integer overows in Win32 binaries \u201d. In: Proceedings of Chaos Communication Congress ( 2005 ). [52] R. Wojtczuk. \u201cUQBTng: a tool capable of automatically nding integer overows in Win32 binaries\u201d. In: Proceedings of Chaos Communication Congress (2005)."},{"key":"e_1_3_2_1_53_1","first-page":"13","volume-title":"Proceedings of the 5th USENIX conference on Offensive technologies.","author":"Yamaguchi F.","year":"2011","unstructured":"[ 53 ] F. Yamaguchi , F. Lindner , and K. Rieck . \u201c Vulnerability extrapolation: Assisted discovery of vulnerabilities using machine learning \u201d. In: Proceedings of the 5th USENIX conference on Offensive technologies. 2011 , pp. 13\u2013 13 . [53] F. Yamaguchi, F. Lindner, and K. Rieck. \u201cVulnerability extrapolation: Assisted discovery of vulnerabilities using machine learning\u201d. In: Proceedings of the 5th USENIX conference on Offensive technologies. 2011, pp. 13\u201313."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236068"},{"key":"e_1_3_2_1_55_1","volume-title":"Advances in neural information processing systems 32","author":"Zhou Y.","year":"2019","unstructured":"[ 55 ] Y. Zhou , S. Liu , J. Siow , X. Du , and Y. Liu . \u201c Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks \u201d. In: Advances in neural information processing systems 32 ( 2019 ). [55] Y. Zhou, S. Liu, J. Siow, X. Du, and Y. Liu. \u201cDevign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks\u201d. In: Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2942930"}],"event":{"name":"ACSAC: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC"},"container-title":["Proceedings of the 38th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564655","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3564655","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3564655","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T14:09:12Z","timestamp":1750169352000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3564655"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,5]]},"references-count":56,"alternative-id":["10.1145\/3564625.3564655","10.1145\/3564625"],"URL":"https:\/\/doi.org\/10.1145\/3564625.3564655","relation":{},"subject":[],"published":{"date-parts":[[2022,12,5]]},"assertion":[{"value":"2022-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}