ObliVul: Alert-Conditioned Safety Obligation Modeling and Bidirectional Counterfactual Validation for Code Vulnerability Detection

📅 2026-10-08
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the proliferation of candidate alerts and false positives in static analysis caused by mismatches between semantics and program structure. It proposes an alert-driven security obligation modeling framework coupled with bidirectional counterfactual verification. The core innovation lies in rigorously aligning security obligations inferred by large language models with nodes and paths in code property graphs, constructing a security obligation graph via local evidence extraction, and introducing a bidirectional counterfactual verification mechanism to suppress redundant evidence. Integrated with the VAFI aggregation algorithm, this approach effectively distinguishes vulnerable from patched versions, significantly reducing persistent false positive rates in fixed code and empirically validating the necessity of each component.
📝 Abstract
In real-world software development, the primary challenge in vulnerability detection is often not finding suspicious code, but identifying which alerts among the large number of candidate alerts produced by static analysis truly warrant attention. Existing learning-based methods mainly identify suspicious patterns at the function or line level, making it difficult to extract complete program evidence centered on an individual alert. Although large language models can infer risk sources, dangerous operations, protection conditions, and state preconditions from local program facts, such semantic information cannot be reliably aligned with specific program nodes, dependency relations, and propagation paths, and is therefore insufficient to verify whether the corresponding safety obligations truly affect the current alert. To address this problem, we propose ObliVul, an alert-conditioned safety obligation modeling and bidirectional counterfactual validation framework for vulnerability detection. For each candidate alert, ObliVul first extracts a Local Evidence Pack (LEP) from the Code Property Graph (CPG) and uses a large language model to recover candidate safety obligations. It then aligns the safety obligations with program nodes, dependency edges, and path scopes to construct a Local Safety Obligation Graph (LSOG). Finally, VAFI aggregates complementary verified alert evidence while suppressing redundant or weaker evidence to produce a function-level vulnerability prediction. Experimental results show that ObliVul effectively distinguishes vulnerable versions from fixed versions and reduces persistent false positives on fixed code. Ablation studies further confirm the necessity of each component for safety obligation recovery, risk response validation, and function-level vulnerability inference.
Problem

Research questions and friction points this paper is trying to address.

vulnerability detection
static analysis alerts
false positives
safety obligation
code property graph
Innovation

Methods, ideas, or system contributions that make the work stand out.

Safety Obligation Modeling
Bidirectional Counterfactual Validation
Code Property Graph
Vulnerability Detection
Large Language Models
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
H
Heyang Tan
Taiyuan University of Technology, China
C
Chengxin Gao
Taiyuan University of Technology, China
X
Xin Wen
Taiyuan University of Technology, China
J
Jiaxin Li
Taiyuan University of Technology, China
Rui Cao
Rui Cao
The Hong Kong University of Science and Technology (Guangzhou)
GIScienceRemote SensingGeoAIUrban InformaticsUrban Sustainability & Resilience