[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-128251-en":3,"doc-seo-128251-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},128251,2336475104957,"Seraphina","https://ap-avatar.wpscdn.com/avatar/22000c4c6bd8a5076e1?x-image-process=image/resize,m_fixed,w_180,h_180&k=1787554080175789136",8,"Research & Report","Understanding and Enhancing the Efficiency and Efficacy of Machine Learning–Assisted Software Vulnerability Detection","Software security is essential as modern society relies heavily on software. Traditional secure coding and automated analysis tools remain vulnerable to developer mistakes, insider threats, and tool limitations such as static analysis false positives and dynamic analysis cost. Machine Learning–Assisted Software Vulnerability Detection (MLAVD) has improved automated security, yet current large attention/graph models often generalize poorly. This dissertation systematically evaluates datasets, architectures, and resource-efficient modeling, introducing Wild C and VulMixer to improve accuracy and generalization efficiently.","Wright State University  \nCORE Scholar  \n\n| Browse all Theses and Dissertations | Theses and Dissertations |\n| --- | --- |\n| 2023\u003Cbr>Understanding and Enhancing the Efficiency and Efficacy of Machine Learning-Assisted Software Vulnerability Detection\u003Cbr>Daniel J. Grahn\u003Cbr>Wright State University\u003Cbr>Follow this and additional works at: [https://corescholar.libraries.wright.edu/etd_all](https://corescholar.libraries.wright.edu/etd_all)\u003Cbr> Part of the Computer Engineering Commons, and the Computer Sciences Commons |  |\n\nRepository Citation  \nGrahn, Daniel J., \"Understanding and Enhancing the Efficiency and Efficacy of Machine Learning-Assisted Software Vulnerability Detection\" (2023) . Browse all Theses and Dissertations. 2908.  \n[https://corescholar.libraries.wright.edu/etd_all/2908](https://corescholar.libraries.wright.edu/etd_all/2908)  \nThis Dissertation is brought to you for free and open access by the Theses and Dissertations at CORE Scholar. It has been accepted for inclusion in Browse all Theses and Dissertations by an authorized administrator of CORE Scholar. For more information, please contact [library-corescholar@wright.edu](library-corescholar@wright.edu).  \nUNDERSTANDING AND ENHANCING THE EFFICIENCY AND EFFICACY OF MACHINE LEARNING–ASSISTED SOFTWARE VULNERABILITY DETECTION  \nA dissertation submitted in partial fulfillment of the requirements for the degree of Doctor of Philosophy  \nby  \nDANIEL J. GRAHN  \nM.S., University of Southern California, 2018  \nB.S., Cedarville University, 2013  \n2023  \nWright State University  \nWright State University  \nCOLLEGE OF GRADUATE PROGRAMS AND HONORS STUDIES  \nDecember 12, 2023  \nI HEREBY RECOMMEND THAT THE DISSERTATION PREPARED UNDER MY SUPERVISION BY Daniel J. Grahn ENTITLED Understanding and Enhancing the Efficiency and Efficacy of Machine Learning–Assisted Software Vulnerability Detection BE ACCEPTED IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF Doctor of Philosophy.  \n\n| Junjie Zhang, Ph.D.\u003Cbr>Dissertation Director |\n| --- |\n| Thomas Wischgoll, Ph.D. Interim Chair, Department of Computer Science and Engineering |\n\nShu Schiller, Ph.D. Interim Dean, College of  \nGraduate Programs & Honors Studies  \nCommittee on  \nFinal Examination  \n\n| Lingwei Chen, Ph.D.\u003Cbr>Co-Dissertation Director |\n| --- |\n| Krishnaprasad Thirunarayan, Ph.D. |\n| Tanvi Banerjee, Ph.D. |\n\nPhu Phung, Ph.D.  \nABSTRACT  \nGrahn, Daniel J. Ph.D., Department of Computer Science & Engineering, Wright State University, 2023 . Understanding and Enhancing the Efficiency and Efficacy of Machine Learning–Assisted Software Vulnerability Detection.  \nAs our world has become dependent upon software for nearly every aspect of modern society, software security has followed as an essential feature. The first line of defense against vulnerabilities is secure coding. While today’s programmers are carefully taught secure coding best practices, they can make mistakes or intentionally introduce vulnerable code. The traditional backstop to human errors and insider threats is the adoption of automated security analysis tools. These analysis tools have limitations. Static analysis suffers from high false positive rates that may cause annoyance and complacency among developers. Dynamic analysis can be difficult to set up and very computationally expensive. As a result of these shortcomings, researchers have turned to Machine Learning as a way to improve the performance of automated security analysis tools. Recent Machine Learning–Assisted Software Vulnerability Detection (MLAVD) research has focused on large-scale models with hundreds of millions of parameters powered by expensive attention-or graph-based architectures. Despite increased model capacity, current models have limited accuracy and struggle to generalize to unseen data.  \nThis dissertation presents systematic research to understand and enhance the efficiency and efficacy of MLAVD models. First, we explore 7 C/C++ datasets and evaluate their suitability for the ","cbCaittOY0elqwOd","https://ap.wps.com/l/cbCaittOY0elqwOd","pdf",1695266,4,1,149,"English","en",105,"# Chapter 1: Introduction\n## Automated Vulnerability Detection\n## Applications of Machine Learning\n## Contributions\n# Chapter 2: An Analysis of C/C++ Datasets for Machine Learning–Assisted Software Vulnerability Detection\n## Abstract","[{\"question\":\"Why are traditional automated security analysis tools insufficient for vulnerability detection?\",\"answer\":\"Static analysis can produce high false positives, causing annoyance and complacency. Dynamic analysis is often hard to set up and can be highly computationally expensive.\"},{\"question\":\"What did the dissertation find about existing C/C++ datasets used for MLAVD?\",\"answer\":\"The evaluated datasets are not representative of typical C/C++ code in file length, token frequency, vocabulary, and other properties. They also contain duplication, including Juliet’s susceptible pre-split augmentations that may enable data leakage.\"},{\"question\":\"How does VulMixer improve resource efficiency and model effectiveness?\",\"answer\":\"VulMixer is a resource-efficient architecture inspired by how the human brain processes code. Experiments show it improves state-of-the-art generalization while using only 0.2% of the baseline’s parameters.\"}]","Understanding and Enhancing the Efficiency and Efficacy of Machine Learning–Assisted Software Vulnerability Detection | PDF",1785946231,375,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"understanding-and-enhancing-the-efficiency-and-efficacy-of-machine-learningassisted-software-vulnerability-detection","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":20},"https://docshare.wps.com/document/understanding-and-enhancing-the-efficiency-and-efficacy-of-machine-learningassisted-software-vulnerability-detection/128251/",{"url":53,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-25","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why are traditional automated security analysis tools insufficient for vulnerability detection?","Question",{"text":76,"@type":77},"Static analysis can produce high false positives, causing annoyance and complacency. Dynamic analysis is often hard to set up and can be highly computationally expensive.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What did the dissertation find about existing C/C++ datasets used for MLAVD?",{"text":81,"@type":77},"The evaluated datasets are not representative of typical C/C++ code in file length, token frequency, vocabulary, and other properties. They also contain duplication, including Juliet’s susceptible pre-split augmentations that may enable data leakage.",{"name":83,"@type":74,"acceptedAnswer":84},"How does VulMixer improve resource efficiency and model effectiveness?",{"text":85,"@type":77},"VulMixer is a resource-efficient architecture inspired by how the human brain processes code. Experiments show it improves state-of-the-art generalization while using only 0.2% of the baseline’s parameters.","https://schema.org",{"og:url":53,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]