{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,17]],"date-time":"2026-05-17T04:26:36Z","timestamp":1778991996854,"version":"3.51.4"},"reference-count":57,"publisher":"Association for Computing Machinery (ACM)","issue":"ISSTA","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2025,6,22]]},"abstract":"<jats:p>Inspired by advances in deep learning, numerous learning-based approaches for vulnerability detection have emerged, primarily operating at the function level for scalability. However, this design choice has a critical limitation: many vulnerabilities span multiple functions, causing function-level approaches to lose the semantics of called functions and fail to capture true vulnerability patterns. To address this issue, we propose VulnSC, a novel framework designed to enhance learning-based approaches by complementing inter-procedural semantics. VulnSC retrieves the source code of called functions for datasets and leverages large language models (LLMs) with well-designed prompts to generate summaries for these functions. The datasets, enhanced with these summaries, are fed into neural networks for improved vulnerability detection. VulnSC is the first general framework to integrate inter-procedural semantics into existing learning-based approaches for vulnerability detection while maintaining scalability. We evaluate VulnSC on four state-of-the-art learning-based approaches using two widely used datasets, and our experimental results demonstrate that VulnSC significantly enhances detection performance with minimal additional computational overhead.<\/jats:p>","DOI":"10.1145\/3728912","type":"journal-article","created":{"date-parts":[[2025,6,22]],"date-time":"2025-06-22T10:52:56Z","timestamp":1750589576000},"page":"825-847","source":"Crossref","is-referenced-by-count":2,"title":["Enhancing Vulnerability Detection via Inter-procedural Semantic Completion"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0360-2248","authenticated-orcid":false,"given":"Bozhi","family":"Wu","sequence":"first","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1296-8046","authenticated-orcid":false,"given":"Chengjie","family":"Liu","sequence":"additional","affiliation":[{"name":"Peking University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3453-5698","authenticated-orcid":false,"given":"Zhiming","family":"Li","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5694-608X","authenticated-orcid":false,"given":"Yushi","family":"Cao","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3545-1392","authenticated-orcid":false,"given":"Jun","family":"Sun","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9726-3434","authenticated-orcid":false,"given":"Shang-Wei","family":"Lin","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,6,22]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2022. checkmarx. https:\/\/www.checkmarx.com"},{"key":"e_1_2_1_2_1","unstructured":"2022. Codechecker. https:\/\/codechecker.readthedocs.io"},{"key":"e_1_2_1_3_1","unstructured":"2022. coverity. https:\/\/scan.coverity.com"},{"key":"e_1_2_1_4_1","unstructured":"2022. Cppcheck. https:\/\/cppcheck.sourceforge.io"},{"key":"e_1_2_1_5_1","unstructured":"2022. Flawfinder. https:\/\/dwheeler.com\/flawfinder"},{"key":"e_1_2_1_6_1","unstructured":"2022. infer. https:\/\/fbinfer.com"},{"key":"e_1_2_1_7_1","unstructured":"2022. Juliet. https:\/\/samate.nist.gov\/SARD"},{"key":"e_1_2_1_8_1","unstructured":"2023. Clang Static Analyzer. https:\/\/clang-analyzer.llvm.org"},{"key":"e_1_2_1_9_1","unstructured":"2023. CWE. https:\/\/cwe.mitre.org\/top25\/archive\/2023\/2023_top25_list.html"},{"key":"e_1_2_1_10_1","unstructured":"2024. report. https:\/\/www.imf.org\/en\/Blogs\/Articles\/2024\/04\/09\/rising-cyber-threats-pose-serious-concerns-for-financial-stability"},{"key":"e_1_2_1_11_1","unstructured":"2024. status. https:\/\/www.infosecurity-magazine.com\/news\/zeroday-surged-50-annually-google\/"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.449"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3559555"},{"key":"e_1_2_1_14_1","volume-title":"International Conference on Learning Representations.","author":"Alon Uri","year":"2018","unstructured":"Uri Alon, Shaked Brody, Omer Levy, and Eran Yahav. 2018. code2seq: Generating Sequences from Structured Representations of Code. In International Conference on Learning Representations."},{"key":"e_1_2_1_15_1","unstructured":"Authors. 2024. Enhancing Vulnerability Detection via Inter-procedural Semantic Completion. https:\/\/sites.google.com\/view\/vulnsc-issta"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/359588.359596"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the ACM on Programming Languages, 8, OOPSLA2","author":"Cassano Federico","year":"2024","unstructured":"Federico Cassano, John Gouwar, Francesca Lucchetti, Claire Schlesinger, Anders Freeman, Carolyn Jane Anderson, Molly Q Feldman, Michael Greenberg, Abhinav Jangda, and Arjun Guha. 2024. Knowledge transfer from high-resource to low-resource programming languages for code llms. Proceedings of the ACM on Programming Languages, 8, OOPSLA2 (2024), 677\u2013708."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3087402"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607242"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3436877"},{"key":"e_1_2_1_21_1","volume-title":"2019 24th International Conference on Engineering of Complex Computer Systems (ICECCS). 41\u201350","author":"Cheng Xiao","year":"2019","unstructured":"Xiao Cheng, Haoyu Wang, Jiayi Hua, Miao Zhang, Guoai Xu, Li Yi, and Yulei Sui. 2019. Static detection of control-flow-related vulnerabilities using graph embedding. In 2019 24th International Conference on Engineering of Complex Computer Systems (ICECCS). 41\u201350."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1017\/S1351324916000334"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"e_1_2_1_24_1","volume-title":"CodeBERT: A Pre-Trained Model for Programming and Natural Languages. Findings of the Association for Computational Linguistics: EMNLP","author":"Feng Zhangyin","year":"2020","unstructured":"Zhangyin Feng, Daya Guo, Duyu Tang, Nan Duan, Xiaocheng Feng, Ming Gong, Linjun Shou, Bing Qin, Ting Liu, and Daxin Jiang. 2020. CodeBERT: A Pre-Trained Model for Programming and Natural Languages. Findings of the Association for Computational Linguistics: EMNLP 2020."},{"key":"e_1_2_1_25_1","unstructured":"Patrick Fernandes Miltiadis Allamanis and Marc Brockschmidt. 2018. Structured neural summarization."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524842.3528452"},{"key":"e_1_2_1_27_1","unstructured":"Zeyu Gao Hao Wang Yuchen Zhou Wenyu Zhu and Chao Zhang. 2023. How far have we gone in vulnerability detection using large language models. arXiv preprint arXiv:2311.12420."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.acl-long.499"},{"key":"e_1_2_1_29_1","volume-title":"GraphCodeBERT: Pre-training Code Representations with Data Flow. In International Conference on Learning Representations.","author":"Guo Daya","year":"2020","unstructured":"Daya Guo, Shuo Ren, Shuai Lu, Zhangyin Feng, Duyu Tang, LIU Shujie, Long Zhou, Nan Duan, Alexey Svyatkovskiy, and Shengyu Fu. 2020. GraphCodeBERT: Pre-training Code Representations with Data Flow. In International Conference on Learning Representations."},{"key":"e_1_2_1_30_1","volume-title":"Vulberta: Simplified source code pre-training for vulnerability detection. In 2022 International joint conference on neural networks (IJCNN). 1\u20138.","author":"Hanif Hazim","year":"2022","unstructured":"Hazim Hanif and Sergio Maffeis. 2022. Vulberta: Simplified source code pre-training for vulnerability detection. In 2022 International joint conference on neural networks (IJCNN). 1\u20138."},{"key":"e_1_2_1_31_1","unstructured":"Avishree Khare Saikat Dutta Ziyang Li Alaia Solko-Breslin Rajeev Alur and Mayur Naik. 2023. Understanding the effectiveness of large language models in detecting security vulnerabilities. arXiv preprint arXiv:2311.16169."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468597"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence. 39","author":"Li Zhiming","year":"2025","unstructured":"Zhiming Li, Junzhe Jiang, Yushi Cao, Aixin Cui, Bozhi Wu, Bo Li, Yang Liu, and Danny Dongning Sun. 2025. Logic-Q: Improving Deep Reinforcement Learning-based Quantitative Trading via Program Sketch-based Tuning. In Proceedings of the AAAI Conference on Artificial Intelligence. 39, 18584\u201318592."},{"key":"e_1_2_1_34_1","unstructured":"Zhiming Li Yanzhou Li Tianlin Li Mengnan Du Bozhi Wu Yushi Cao Junzhe Jiang and Yang Liu. 2024. Unveiling Project-Specific Bias in Neural Code Models. In LREC\/COLING."},{"key":"e_1_2_1_35_1","volume-title":"Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering. 1\u201312","author":"Li Zhen","year":"2024","unstructured":"Zhen Li, Ning Wang, Deqing Zou, Yating Li, Ruqian Zhang, Shouhuai Xu, Chao Zhang, and Hai Jin. 2024. On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities. In Proceedings of the IEEE\/ACM 46th International Conference on Software Engineering. 1\u201312."},{"key":"e_1_2_1_36_1","article-title":"Sysevr: A framework for using deep learning to detect software vulnerabilities","author":"Li Zhen","year":"2021","unstructured":"Zhen Li, Deqing Zou, Shouhuai Xu, Hai Jin, Yawei Zhu, and Zhaoxuan Chen. 2021. Sysevr: A framework for using deep learning to detect software vulnerabilities. IEEE Transactions on Dependable and Secure Computing.","journal-title":"IEEE Transactions on Dependable and Secure Computing."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23158"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the Ninth International Conference on Learning Representations: ICLR. 4\u20138.","author":"Shangqing LIU","year":"2021","unstructured":"Shangqing LIU, Yu CHEN, Xiaofei XIE, Jingkai SIOW, and Yang LIU. 2021. Retrieval-augmented generation for code summarization via hybrid GNN.(2021). In Proceedings of the Ninth International Conference on Learning Representations: ICLR. 4\u20138."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2024.112031"},{"key":"e_1_2_1_40_1","volume-title":"International Conference on Information Security and Cryptology. 92\u2013109","author":"Ming Jiang","year":"2012","unstructured":"Jiang Ming, Meng Pan, and Debin Gao. 2012. iBinHunt: Binary hunting with inter-procedural control flow. In International Conference on Information Security and Cryptology. 92\u2013109."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/567532.567556"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639187"},{"key":"e_1_2_1_43_1","unstructured":"Flemming Nielson Hanne R Nielson and Chris Hankin. 2015. Principles of program analysis. springer."},{"key":"e_1_2_1_44_1","volume-title":"Static Analysis: 11th International Symposium, SAS 2004, Verona, Italy, August 26-28, 2004. Proceedings 11","author":"Nystrom Erik M","year":"2004","unstructured":"Erik M Nystrom, Hong-Seok Kim, and Wen-Mei W Hwu. 2004. Bottom-up and top-down context-sensitive summary-based pointer analysis. In Static Analysis: 11th International Symposium, SAS 2004, Verona, Italy, August 26-28, 2004. Proceedings 11. 165\u2013180."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_2_1_46_1","unstructured":"M Pnueli and Micha Sharir. 1981. Two approaches to interprocedural data flow analysis. Program flow analysis: theory and applications 189\u2013234."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/223428.207112"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2259016.2259050"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133255.1134027"},{"key":"e_1_2_1_51_1","unstructured":"Yuqiang Sun Daoyuan Wu Yue Xue Han Liu Wei Ma Lyuye Zhang Yang Liu and Yingjiu Li. 2024. Llm4vuln: A unified evaluation framework for decoupling and enhancing llms\u2019 vulnerability reasoning. arXiv preprint arXiv:2401.16185."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/223428.207111"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3192631"},{"key":"e_1_2_1_54_1","volume-title":"Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 1371\u20131383","author":"Wu Bozhi","year":"2023","unstructured":"Bozhi Wu, Shangqing Liu, Yang Xiao, Zhiming Li, Jun Sun, and Shang-Wei Lin. 2023. Learning Program Semantics for Vulnerability Detection via Vulnerability-Specific Inter-procedural Slicing. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 1371\u20131383."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380383"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00020"},{"key":"e_1_2_1_57_1","volume-title":"Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in neural information processing systems, 32","author":"Zhou Yaqin","year":"2019","unstructured":"Yaqin Zhou, Shangqing Liu, Jingkai Siow, Xiaoning Du, and Yang Liu. 2019. Devign: Effective vulnerability identification by learning comprehensive program semantics via graph neural networks. Advances in neural information processing systems, 32 (2019)."}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3728912","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T16:55:30Z","timestamp":1752684930000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3728912"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,22]]},"references-count":57,"journal-issue":{"issue":"ISSTA","published-print":{"date-parts":[[2025,6,22]]}},"alternative-id":["10.1145\/3728912"],"URL":"https:\/\/doi.org\/10.1145\/3728912","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,22]]}}}