Vulnerability detection is a crucial aspect of achieving system and software security. Small and micro enterprises, lacking technical reserves and computing power, may need to entrust security companies to perform vulnerability detection. However, they may face the risk of commercial secrets, privacy, and core algorithms being leaked from the source code. This paper presents a vulnerability detection method that uses convolutional neural networks to automate the analysis of privacy-preserving code, with a focus on preserving code privacy. The experimental results indicate that the proposed method successfully removes privacy information from the code, and the modifications to the original code cause deviations from its intended functionality or even result in its failure to execute correctly. This method provides privacy preserving for the source code while only reducing the accuracy of vulnerability detection results by 2.5% compared to the original method without privacy preserving.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Privacy-Preserving Source Code Vulnerability Detection Method

  • Dongdong Zhao,
  • Zizhuo Yu,
  • Jing Zhou,
  • Jianwen Xiang

摘要

Vulnerability detection is a crucial aspect of achieving system and software security. Small and micro enterprises, lacking technical reserves and computing power, may need to entrust security companies to perform vulnerability detection. However, they may face the risk of commercial secrets, privacy, and core algorithms being leaked from the source code. This paper presents a vulnerability detection method that uses convolutional neural networks to automate the analysis of privacy-preserving code, with a focus on preserving code privacy. The experimental results indicate that the proposed method successfully removes privacy information from the code, and the modifications to the original code cause deviations from its intended functionality or even result in its failure to execute correctly. This method provides privacy preserving for the source code while only reducing the accuracy of vulnerability detection results by 2.5% compared to the original method without privacy preserving.