Same Same But Different: Preventing Refactoring Attacks on Software Plagiarism Detection

📅 2025-10-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
AI- and algorithm-driven semantic-preserving code obfuscation—such as variable renaming and control-flow restructuring—severely undermines the robustness of existing plagiarism detection systems in programming education. Method: We propose the first scalable detection framework integrating Code Property Graphs (CPGs) with graph transformation techniques. It constructs fine-grained CPGs via static analysis, formally models common refactoring operations, and employs invertible graph transformations to achieve semantic alignment and matching between obfuscated and original code. Contribution/Results: Our approach overcomes limitations of syntax- or shallow-semantic–based methods. Evaluated on a real-world student code dataset, it significantly improves detection accuracy for both AI-generated and manually refactored obfuscated code. Notably, it demonstrates superior generalizability and robustness against functionally equivalent structural modifications—e.g., those preserving program behavior while altering syntactic or control structures.

Technology Category

Natural Language Processing: Code Generation / Program Synthesis from Natural LanguageMachine Learning: Graph-based Machine LearningComputer Vision: Adversarial Attacks & Robustness

Application Category

Graph Algorithms and Modeling for the Web: Efficient manipulation of static and dynamic Web-related graphsSemantics and Knowledge: Scalable techniques for the creation, curation, publication, maintenance, and consumption of large, Web-based, structured, reusable, knowledge graphs and ontologiesWeb Mining and Content Analysis: Robustness and generalizability of Web mining methods
📝 Abstract
Plagiarism detection in programming education faces growing challenges due to increasingly sophisticated obfuscation techniques, particularly automated refactoring-based attacks. While code plagiarism detection systems used in education practice are resilient against basic obfuscation, they struggle against structural modifications that preserve program behavior, especially caused by refactoring-based obfuscation. This paper presents a novel and extensible framework that enhances state-of-the-art detectors by leveraging code property graphs and graph transformations to counteract refactoring-based obfuscation. Our comprehensive evaluation of real-world student submissions, obfuscated using both algorithmic and AI-based obfuscation attacks, demonstrates a significant improvement in detecting plagiarized code.
Problem

Research questions and friction points this paper is trying to address.

Detecting code plagiarism against refactoring obfuscation attacks
Improving resilience to structural modifications preserving behavior
Enhancing detectors using code property graphs and transformations
Innovation

Methods, ideas, or system contributions that make the work stand out.

Leverages code property graphs for detection
Uses graph transformations to counter obfuscation
Extends existing detectors against refactoring attacks
🔎 Similar Papers
R
Robin Maisch
KASTEL – Institute of Information Security and Dependability, Karlsruhe Institute of Technology (KIT)
L
Larissa Schmid
KTH Royal Institute of Technology
T
Timur Sağlam
KASTEL – Institute of Information Security and Dependability, Karlsruhe Institute of Technology (KIT)
N
Nils Niehues
KASTEL – Institute of Information Security and Dependability, Karlsruhe Institute of Technology (KIT)