Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
cs.SE, cs.AI, cs.CR
Submitted: 2026-01-05
Updated: 2026-09-13
Comments: Accepted to the 29th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2026)
License: http://creativecommons.org/licenses/by/4.0/
The gist: Software vulnerability detection can be formulated as a binary classification problem that determines whether a given code snippet contains security defects.
Terminology
Abstract
Software vulnerability detection can be formulated as a binary classification problem that determines whether a given code snippet contains security defects. Existing multimodal methods typically fuse Natural Code Sequence (NCS) representations extracted by pretrained models with Code Property Graph (CPG) representations extracted by graph neural networks, under the implicit assumption that introducing an additional modality necessarily yields information gain. Through empirical analysis, we demonstrate the limitations of this assumption: pretrained models already encode substantial structural information implicitly, leading to strong overlap between the two modalities; moreover, graph encoders are generally less effective than pretrained language models in feature extraction. As a result, naive fusion not only struggles to obtain complementary signals but can also dilute effective discriminative cues due to noise propagation. To address these challenges, we propose a task-conditioned complementary fusion strategy that uses Fisher information to quantify task relevance, transforming cross-modal interaction from full-spectrum matching into selective fusion within a task-sensitive subspace. Our theoretical analysis shows that, under an isotropic perturbation assumption, this strategy significantly tightens the upper bound on the output error. Based on this insight, we design the TaCCS-DFA framework, which combines online low-rank Fisher subspace estimation with an adaptive gating mechanism to enable efficient task-oriented fusion. Experiments on the BigVul, Devign, and ReVeal benchmarks demonstrate that TaCCS-DFA delivers up to a 6.3-point gain in F1 score with only a 3.4% increase in inference latency, while maintaining low calibration error.
Sources
- Deep Learning based Vulnerability Detection: Are We There Yet?
- Vulnerability Detection with Code Language Models: How Far Are We?
- GraphCodeBERT: Pre-training Code Representations with Data Flow
- Representation Learning with Contrastive Predictive Coding
- Propagation-Based Vulnerability Impact Assessment for Software Supply Chains
- CodeT5: Identifier-aware Unified Pre-trained Encoder-Decoder Models for Code Understanding and Generation
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties