2609005091
  • Open Access
  • Review

Program Graph Learning for Software Vulnerability Analysis: A Survey

  • Tong Yu 1,†,   
  • Junjie Wang 1,†,   
  • Ming Li 2,   
  • Yuhang Hu 1,   
  • Junwei Hu 1,   
  • Xiantao Cai 1,   
  • Wenbin Hu 1,3,*,   
  • Alessio Borgi 4,5

Received: 09 Jul 2026 | Revised: 29 Aug 2026 | Accepted: 01 Sep 2026 | Published: 09 Sep 2026

Abstract

Software vulnerabilities represent an enduring threat to modern cyberspace. Effective vulnerability detection increasingly relies on reasoning about complex program semantics, structural dependencies, and execution behaviors. Consequently, extracting vulnerability-relevant features from code efficiently has become a pressing research issue. In recent years, advances in graph representation learning and large language models have reframed vulnerability analysis as a graph learning problem over program entities. By building on and extending traditional methods including static analysis, dynamic analysis, symbolic execution, and fuzzing, this perspective enables more effective vulnerability detection, fine-grained localization, multi-class classification, and repair. We review recent progress in graph-driven vulnerability intelligence, structuring the survey around these tasks and then providing a structured overview of representative graph-based methods, graph-based multimodal methods, LLM-assisted methods, and vulnerability repair methods, together with widely adopted datasets, program graph construction tools, and computing frameworks. We then highlight several persistent challenges: interpretability, cross-language generalization, data quality and label noise, the lack of benchmark standardization, and agent-oriented vulnerability analysis. These challenges are often intertwined, complicating piecemeal solutions. Addressing them will be critical for developing reliable, transferable, and explainable vulnerability intelligence systems.

References 

  • 1.

    Shao, M.; Ding, Y. FVD-DPM: Fine-Grained Vulnerability Detection via Conditional Diffusion Probabilistic Models. In Proceedings of the USENIX Security Symposium, Philadelphia, PA, USA, 14–16 August 2024; pp. 7375–7392.

  • 2.

    Jayalath, R.K.; Ahmad, H.; Goel, D.; et al. Microservice Vulnerability Analysis: A Literature Review with Empirical Insights. IEEE Access 2024, 12, 155168–155204. https://doi.org/10.1109/access.2024.3481374.

  • 3.

    Liu, T.; Deng, Z.; Meng, G.; et al. Demystifying RCE Vulnerabilities in LLM-Integrated Apps. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA, 14–18 October 2024; pp. 1716–1730. https://doi.org/10.1145/3658644.3690338.

  • 4.

    Choi, D.; Seo, H.; Kim, K.; et al. Uncovering Threats in Container Systems: A Study on Misconfigured Container Components in the Wild. IEEE Access 2024, 12, 192931–192945. https://doi.org/10.1109/access.2024.3514751.

  • 5.

    Cost of a Data Breach Report 2024. Available online: https://www.ibm.com/think/insights/whats-new-2024-cost-of-a-databreach-report/ (accessed on 2 July 2026).

  • 6.

    Sun, T.; He, N.; Xiao, J.; et al. All Your Tokens Are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security 24), Philadelphia, PA, USA, 14–16 August 2024; pp. 3567–3584.

  • 7.

    Cybercrime To Cost TheWorld $10.5 Trillion Annually By 2025. Available online: https://cybersecurityventures.com/cybercrimedamages-6-trillion-by-2021/ (accessed on 2 July 2026).

  • 8.

    Gokkaya, B.; Aniello, L.; Halak, B. Software Supply Chain: Review of Attacks, Risk Assessment Strategies and Security Controls. arXiv 2023, arXiv:2305.14157.

  • 9.

    Williams, L.; Benedetti, G.; Hamer, S.; et al. Research Directions in Software Supply Chain Security. ACM Trans. Softw. Eng. Methodol. 2025, 34, 1–38. https://doi.org/10.1145/3714464.

  • 10.

    Lin, J.; Zhang, H.; Adams, B.; et al. Vulnerability Management in Linux Distributions: An Empirical Study on Debian and Fedora. Empir. Softw. Eng. 2023, 28, 47. https://doi.org/10.1007/s10664-022-10267-7.

  • 11.

    Shaon, M.S.H.; Akter, M.S. Modern Approaches to Software Vulnerability Detection: A Survey of Machine Learning, Deep Learning, and Large Language Models. Electronics 2025, 14, 4449. https://doi.org/10.3390/electronics14224449.

  • 12.

    Zhang, J.; Liu, Z.; Hu, X.; et al. Vulnerability Detection by Learning from Syntax-Based Execution Paths of Code. IEEE Trans. Softw. Eng. 2023, 49, 4196–4212. https://doi.org/10.1109/tse.2023.3286586.

  • 13.

    Deng, P.; Zhang, L.; Meng, Y.; et al. ChainFuzz: Exploiting Upstream Vulnerabilities in Open-Source Supply Chains. In Proceedings of the USENIX Security Symposium, Seattle, WA, USA, 13–15 August 2025; pp. 6199–6218.

  • 14.

    Liao, Z.; Zheng, Z.; Chen, X.; et al. SmartDagger: A Bytecode-Based Static Analysis Approach for Detecting Cross-Contract Vulnerability. In Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, Online, 18–22 July 2022; pp. 752–764. https://doi.org/10.1145/3533767.3534222.

  • 15.

    Liao, Z.; Nan, Y.; Liang, H.; et al. SmartAxe: Detecting Cross-Chain Vulnerabilities in Bridge Smart Contracts via Fine-Grained Static Analysis. Proc. ACM Softw. Eng. 2024, 1, 249–270. https://doi.org/10.1145/3643738.

  • 16.

    Torres, A.; Costa, P.; Amaral, L.; et al. Runtime Verification of Crypto APIs: An Empirical Study. IEEE Trans. Softw. Eng. 2023, 49, 4510–4525. https://doi.org/10.1109/tse.2023.3301660.

  • 17.

    Johannesmeyer, B.; Isemann, R.; Giuffrida, C.; et al. Dynamic Detection of Vulnerable DMA Race Conditions. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, Taipei, Taiwan, 13–17 October 2025; pp. 4499–4513. https://doi.org/10.1145/3719027.3765126.

  • 18.

    Ruaro, N.; Zeng, K.; Dresel, L.; et al. SyML: Guiding Symbolic Execution toward Vulnerable States through Pattern Learning. In Proceedings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses, San Sebastian, Spain, 6–8 October 2021; pp. 456–468. https://doi.org/10.1145/3471621.3471865.

  • 19.

    So, S.; Hong, S.; Oh, H. SmarTest: Effectively Hunting Vulnerable Transaction Sequences in Smart Contracts through Language Model-Guided Symbolic Execution. In Proceedings of the USENIX Security Symposium, Online, 11–13 August 2021; pp. 1361–1378.

  • 20.

    Nagy, S.; Nguyen-Tuong, A.; Hiser, J.D.; et al. Same Coverage, Less Bloat: Accelerating Binary-Only Fuzzing with Coverage-Preserving Coverage-Guided Tracing. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, Online, 15–19 November 2021; pp. 351–365. https://doi.org/10.1145/3460120.3484787.

  • 21.

    Schloegel, M.; Bars, N.; Schiller, N.; et al. SoK: Prudent Evaluation Practices for Fuzzing. In Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 19–23 May 2024; pp. 1974–1993. https://doi.org/10.1109/sp54263.2024.00137.

  • 22.

    Fioraldi, A.; Maier, D.C.; Zhang, D.; et al. LibAFL: A Framework to Build Modular and Reusable Fuzzers. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, Los Angeles, CA, USA, 7–11 November 2022; pp. 1051–1065. https://doi.org/10.1145/3548606.3560602.

  • 23.

    Wu, B.; Zou, F. Code Vulnerability Detection Based on Deep Sequence and Graph Models: A Survey. Secur. Commun. Netw. 2022, 2022, 1176898. https://doi.org/10.1155/2022/1176898.

  • 24.

    Harzevili, N.; Boaye Belle, A.; Wang, J.; et al. A Systematic Literature Review on Automated Software Vulnerability Detection Using Machine Learning. ACM Comput. Surv. 2024, 57, 1–36.

  • 25.

    Qiu, F.; Liu, Z.; Hu, X.; et al. Vulnerability Detection via Multiple-Graph-Based Code Representation. IEEE Trans. Softw. Eng. 2024, 50, 2178–2199. https://doi.org/10.1109/tse.2024.3427815.

  • 26.

    Wen, X.C.; Chen, Y.; Gao, C.; et al. Vulnerability Detection with Graph Simplification and Enhanced Graph Representation Learning. In Proceedings of the 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE), Melbourne, VIC, Australia, 14–20 May 2023; pp. 2275–2286. https://doi.org/10.1109/icse48619.2023.00191.

  • 27.

    Ghaffarian, S.M.; Shahriari, H.R. Neural Software Vulnerability Analysis Using Rich Intermediate Graph Representations of Programs. Inf. Sci. 2021, 553, 189–207.

  • 28.

    Katsadouros, E.; Patrikakis, C. A Survey on Vulnerability Prediction Using GNNs. In Proceedings of the 26th Pan-Hellenic Conference on Informatics, Athens, Greece, 25–27 November 2022; pp. 38–43. https://doi.org/10.1145/3575879.3575964.

  • 29.

    bin MohdIllzam, M.I.E.; Yong, K.S.C.; Then, P.H.H.; et al. Comparative Analysis of Graph Representation Techniques for Code Vulnerability Detection. In Proceedings of the 2023 International Conference on Engineering and Emerging Technologies (ICEET), Istanbul, Turkiye, 27–28 October 2023; pp. 1–6.

  • 30.

    Lin, C.; Xu, Y.; Fang, Y.; et al. VulEye: A Novel Graph Neural Network Vulnerability Detection Approach for PHP Application. Appl. Sci. 2023, 13, 825. https://doi.org/10.3390/app13020825.

  • 31.

    Xiao, W.; Hou, Z.; Wang, T.; et al. MSGVUL: Multi-Semantic Integration Vulnerability Detection Based on Relational Graph Convolutional Neural Networks. Inf. Softw. Technol. 2024, 170, 107442. https://doi.org/10.1016/j.infsof.2024.107442.

  • 32.

    Cheng, B.; Wang, K.; Gao, C.; et al. SliceLocator: Locating Vulnerable Statements with Graph-Based Detectors. arXiv 2024, arXiv:2401.02737.

  • 33.

    Mirsky, Y.; Macon, G.; Brown, M.; et al. VulChecker: Graph-Based Vulnerability Localization in Source Code. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 6557–6574.

  • 34.

    Cheng, B.; Zhao, S.; Wang, K.; et al. Beyond Fidelity: Explaining Vulnerability Localization of Learning-Based Detectors. ACM Trans. Softw. Eng. Methodol. 2024, 33, 127:1–127:33. https://doi.org/10.1145/3641543.

  • 35.

    Li, L.; Ding, S.H.H.; Tian, Y.; et al. VulANalyzeR: Explainable Binary Vulnerability Detection with Multi-Task Learning and Attentional Graph Convolution. ACM Trans. Priv. Secur. 2023, 26, 1–25. https://doi.org/10.1145/3585386.

  • 36.

    Mao, Q.; Li, Z.; Hu, X.; et al. Towards Explainable Vulnerability Detection with Large Language Models. IEEE Trans. Softw. Eng. 2025, 51, 2957–2971. https://doi.org/10.1109/tse.2025.3605442.

  • 37.

    Fu, M.; Tantithamthavorn, C. Linevul: A Transformer-Based Line-Level Vulnerability Prediction. In Proceedings of the 19th International Conference on Mining Software Repositories, Pittsburgh, PA, USA, 23–24 May 2022; pp. 608–620. https://doi.org/10.1145/3524842.3528452.

  • 38.

    Zhen, Z.; Zhao, X.; Zhang, J.; et al. DA-GNN: A Smart Contract Vulnerability Detection Method Based on Dual Attention Graph Neural Network. Comput. Netw. 2024, 242, 110238. https://doi.org/10.1016/j.comnet.2024.110238.

  • 39.

    Li, Y.; Shezan, F.H.; Wei, B.; et al. SoK: Towards Effective Automated Vulnerability Repair. In Proceedings of the USENIX Security 25, Seattle, WA, USA, 13–15 August 2025; pp. 4441–4462.

  • 40.

    Zhang, Q.; Fang, C.; Xie, Y.; et al. A Systematic Literature Review on Large Language Models for Automated Program Repair. ACM Trans. Softw. Eng. Methodol. 2026. https://doi.org/10.1145/3799693.

  • 41.

    Zhu, C.; Wei, R.; Chen, L.; et al. Vulnerability Localization Based on Intermediate Code Representation and Feature Fusion. Comput. J. 2024, 67, 2749–2762. https://doi.org/10.1093/comjnl/bxae041.

  • 42.

    Zhou, X.; Cao, S.; Sun, X.; et al. Large Language Model for Vulnerability Detection and Repair: Literature Review and the Road Ahead. ACM Trans. Softw. Eng. Methodol. 2025, 34, 1–31. https://doi.org/10.1145/3708522.

  • 43.

    Zhou, Y.; Liu, S.; Siow, J.; et al. Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks. Adv. Neural Inf. Process. Syst. 2019, 32, 10197–10207

  • 44.

    Wang, H.; Ye, G.; Tang, Z.; et al. Combining Graph-Based Learning with Automated Data Collection for Code Vulnerability Detection. IEEE Trans. Inf. Forensics Secur. 2021, 16, 1943–1958. https://doi.org/10.1109/tifs.2020.3044773.

  • 45.

    Chakraborty, S.; Krishna, R.; Ding, Y.; et al. Deep Learning Based Vulnerability Detection: Are We There Yet? IEEE Trans. Softw. Eng. 2022, 48, 3280–3296. https://doi.org/10.1109/tse.2021.3087402.

  • 46.

    Nguyen, V.A.; Nguyen, D.Q.; Nguyen, V.; et al. ReGVD: Revisiting Graph Neural Networks for Vulnerability Detection. In Proceedings of the 2022 IEEE/ACM 44th International Conference on Software Engineering: Companion Proceedings, Pittsburgh, PA, USA, 22–24 May 2022; pp. 178–182. https://doi.org/10.1109/icse-companion55297.2022.9793807.

  • 47.

    Qian, P.; Liu, Z.; Yin, Y.; et al. Cross-Modality Mutual Learning for Enhancing Smart Contract Vulnerability Detection on Bytecode. In Proceedings of the ACM Web Conference 2023, Austin, TX, USA, 30 April–4 May 2023; pp. 2220–2229. https://doi.org/10.1145/3543507.3583367.

  • 48.

    Mikolov, T.; Sutskever, I.; Chen, K.; et al. Distributed Representations of Words and Phrases and Their Compositionality. Adv. Neural Inf. Process. Syst. 2013, 26, 3111–3119.

  • 49.

    Li, Y.; Wang, S.; Nguyen, T.N. Vulnerability Detection with Fine-Grained Interpretations. In Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Online, 23–28 August 2021; pp. 292–303. https://doi.org/10.1145/3468264.3468597.

  • 50.

    Pennington, J.; Socher, R.; Manning, C. GloVe: Global Vectors for Word Representation. In Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (EMNLP), Doha, Qatar, 25–29 October 2014; pp. 1532–1543. https://doi.org/10.3115/v1/d14-1162.

  • 51.

    Cheng, X.; Wang, H.; Hua, J.; et al. DeepWukong: Statically Detecting Software Vulnerabilities Using Deep Graph Neural Network. ACM Trans. Softw. Eng. Methodol. 2021, 30, 1–33. https://doi.org/10.1145/3436877.

  • 52.

    Le, Q.; Mikolov, T. Distributed Representations of Sentences and Documents. In Proceedings of the International Conference on Machine Learning, Beijing, China, 22–24 June 2014; pp. 1188–1196.

  • 53.

    Cao, S.; Sun, X.; Bo, L.; et al. BGNN4VD: Constructing Bidirectional Graph Neural-Network for Vulnerability Detection. Inf. Softw. Technol. 2021, 136, 106576. https://doi.org/10.1016/j.infsof.2021.106576.

  • 54.

    Hin, D.; Kan, A.; Chen, H.; et al. LineVD: Statement-Level Vulnerability Detection Using Graph Neural Networks. In Proceedings of the MSR ’22: 19th International Conference on Mining Software Repositories, Pittsburgh, PA, USA, 23–24 May 2022; pp. 596–607. https://doi.org/10.1145/3524842.3527949.

  • 55.

    Feng, Z.; Guo, D.; Tang, D.; et al. CodeBERT: A Pre-Trained Model for Programming and Natural Languages. In Proceedings of the Association for Computational Linguistics: EMNLP 2020, Online, 16–20 November 2020; pp. 1536–1547. https://doi.org/10.18653/v1/2020.findings-emnlp.139.

  • 56.

    Guo, D.; Ren, S.; Lu, S.; et al. GraphCodeBERT: Pre-Training Code Representations with Data Flow. arXiv 2020, arXiv:2009.08366.

  • 57.

    Nguyen, H.V.; Zheng, J.; Inomata, A.; et al. Code Aggregate Graph: Effective Representation for Graph Neural Networks to Detect Vulnerable Code. IEEE Access 2022, 10, 123786–123800. https://doi.org/10.1109/access.2022.3216395.

  • 58.

    Guo, W.; Fang, Y.; Huang, C.; et al. HyVulDect: A Hybrid Semantic Vulnerability Mining System Based on Graph Neural Network. Comput. Secur. 2022, 121, 102823. https://doi.org/10.1016/j.cose.2022.102823.

  • 59.

    Wen, X.C.; Gao, C.; Ye, J.; et al. Meta-Path Based Attentional Graph Learning Model for Vulnerability Detection. IEEE Trans. Softw. Eng. 2024, 50, 360–375. https://doi.org/10.1109/tse.2023.3340267.

  • 60.

    Ge, K.; Han, Q.B. Hidden Code Vulnerability Detection: A Study of the Graph-BiLSTM Algorithm. Inf. Softw. Technol. 2024, 175, 107544. https://doi.org/10.1016/j.infsof.2024.107544.

  • 61.

    Pagliardini, M.; Gupta, P.; Jaggi, M. Unsupervised Learning of Sentence Embeddings Using Compositional NGram Features. In Proceedings of the 2018 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, New Orleans, LA, USA, 1–6 June 2018; pp. 528–540. https://doi.org/10.18653/v1/n18-1049.

  • 62.

    Xiao, P.; Xiao, Q.; Zhang, X.; et al. Vulnerability Detection Based on Enhanced Graph Representation Learning. IEEE Trans. Inf. Forensics Secur. 2024, 19, 5120–5135. https://doi.org/10.1109/tifs.2024.3392536.

  • 63.

    Hao, J.; Kwon, Y.W. Enhancing Graph-Based Vulnerability Detection through Standardized Deep Learning Pipelines. In Proceedings of the 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Sanya, China, 17–21 December 2024; pp. 1231–1238. https://doi.org/10.1109/trustcom63139.2024.00174.

  • 64.

    Huang, Y.; He, M.; Wang, X.; et al. HeVulD: A Static Vulnerability Detection Method Using Heterogeneous Graph Code Representation. IEEE Trans. Inf. Forensics Secur. 2024, 19, 9129–9144. https://doi.org/10.1109/tifs.2024.3457162.

  • 65.

    Ling, M.; Tang, M.; Bian, D.; et al. A Dual Graph Neural Networks Model Using Sequence Embedding as Graph Nodes for Vulnerability Detection. Inf. Softw. Technol. 2025, 177, 107581. https://doi.org/10.1016/j.infsof.2024.107581.

  • 66.

    Shao, M.; Ding, Y.; Cao, J.; et al. GraphFVD: Property Graph-Based Fine-Grained Vulnerability Detection. Comput. Secur. 2025, 151, 104350.

  • 67.

    Sun, X.; Zhou, M.; Cao, S.; et al. HgtJIT: Just-in-Time Vulnerability Detection Based on Heterogeneous Graph Transformer. IEEE Trans. Dependable Secur. Comput. 2025, 22, 6522–6538. https://doi.org/10.1109/tdsc.2025.3586669.

  • 68.

    Lin, B.; Wang, S.; Liu, Z.; et al. CCT5: A Code-Change-Oriented Pre-Trained Model. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, San Francisco, CA, USA, 3–9 December 2023; pp. 1509–1521.

  • 69.

    Nguyen, S.; Nguyen, T.T.; Vu, T.T.; et al. Code-Centric Learning-Based Just-in-Time Vulnerability Detection. J. Syst. Softw. 2024, 214, 112014. https://doi.org/10.1016/j.jss.2024.112014.

  • 70.

    Piao, Y.; Zhang, Z.; Kong, Z. Code Vulnerability Detection Method Based on PreTrained Language Model and Gating Graph Neural Network. In Proceedings of the 2025 4th International Conference on Cloud Computing, Big Data Application and Software Engineering (CBASE), Chengdu, China, 24–26 October 2025; pp. 685–688. https://doi.org/10.1109/cbase67452.2025.11335562.

  • 71.

    Zhuang, Y.; Liu, Z.; Qian, P.; et al. Smart Contract Vulnerability Detection Using Graph Neural Network. In Proceedings of the Twenty-Ninth International Joint Conference on Artificial Intelligence, Online, 7–15 January 2021; pp. 3283–3290. https://doi.org/10.24963/ijcai.2020/454.

  • 72.

    Ni, C.; Yin, X.; Li, X.; et al. Abundant Modalities Offer More Nutrients: Multi-Modal-Based Function-Level Vulnerability Detection. ACM Trans. Softw. Eng. Methodol. 2026, 35, 33:1–33:31. https://doi.org/10.1145/3731557.

  • 73.

    Cao, X.; Wang, J.; Wu, P.; et al. VulMPFF: A Vulnerability Detection Method for Fusing Code Features in Multiple Perspectives. IET Inf. Secur. 2024, 2024, 4313185. https://doi.org/10.1049/2024/4313185.

  • 74.

    Lu, G.; Ju, X.; Chen, X.; et al. GRACE: Empowering LLM-Based Software Vulnerability Detection with Graph Structure and in-Context Learning. J. Syst. Softw. 2024, 212, 112031.

  • 75.

    Chu, H.; Zhang, P.; Dong, H.; et al. Deepfusion: Smart Contract Vulnerability Detection via Deep Learning and Data Fusion. IEEE Trans. Reliab. 2025, 74, 3544–3558.

  • 76.

    Lekssays, A.; Mouhcine, H.; Tran, K.; et al. LLMxCPG: Context-Aware Vulnerability Detection through Code Property Graph-Guided Large Language Models. In Proceedings of the USENIX Security Symposium (USENIX Security 25), Seattle, WA, USA, 13–15 August 2025; pp. 489–507.

  • 77.

    Cao, Y.; Ju, X.; Chen, X.; et al. MCL-VD: Multi-Modal Contrastive Learning with LoRA-Enhanced GraphCodeBERT for Effective Vulnerability Detection. Autom. Softw. Eng. 2025, 32, 67. https://doi.org/10.1007/s10515-025-00543-3.

  • 78.

    Liu, R.; Wang, Y.; Xu, H.; et al. Vul-LMGNNs: Fusing Language Models and Online-Distilled Graph Neural Networks for Code Vulnerability Detection. Inf. Fusion 2025, 115, 102748. https://doi.org/10.1016/j.inffus.2024.102748.

  • 79.

    Cai, W.; Chen, J.; Yu, J.; et al. A Software Vulnerability Detection Method Based on Multi-Modality with Unified Processing. Inf. Softw. Technol. 2025, 182, 107703. https://doi.org/10.1016/j.infsof.2025.107703.

  • 80.

    Li, Q.; Jiang, G.; He, P.; et al. CMF-Vul: Advancing Automated Vulnerability Detection via Contrastive Multimodal Fusion and Challenge-Driven Representation Learning. Empir. Softw. Eng. 2026, 31, 152. https://doi.org/10.1007/s10664-026-10886-4.

  • 81.

    Zhang, G.; Yao, T.; Qin, J.; et al. CodeSAGE: A Multi-Feature Fusion Vulnerability Detection Approach Using Code Attribute Graphs and Attention Mechanisms. J. Inf. Secur. Appl. 2025, 89, 103973. https://doi.org/10.1016/j.jisa.2025.103973.

  • 82.

    Hou, A.; Su, B.; Niu, W.; et al. CPGHunter: LLM-Guided Semantic Modeling for Scalable Vulnerability Detection via Taint Analysis. Empir. Softw. Eng. 2026, 31, 106. https://doi.org/10.1007/s10664-026-10842-2.

  • 83.

    Zhu, H.; Li, J.; Gao, C.; et al. Specification-Guided Vulnerability Detection with Large Language Models. arXiv 2025, arXiv:2511.04014.

  • 84.

    Du, X.; Zheng, G.; Wang, K.; et al. Vul-RAG: Enhancing LLM-Based Vulnerability Detection via Knowledge-Level RAG. ACM Trans. Softw. Eng. Methodol. 2026. https://doi.org/10.1145/3797277.

  • 85.

    Fayyazi, R.; Trueba, S.H.; Zuzak, M.; et al. ProveRAG: Provenance-Driven Vulnerability Analysis with Automated Retrieval-Augmented LLMs. IEEE Access 2025, 13, 212815–212826. https://doi.org/10.1109/access.2025.3638251.

  • 86.

    Daneshvar, S.S.; Nong, Y.; Yang, X.; et al. VulScribeR: Exploring RAG-Based Vulnerability Augmentation with LLMs. ACM Trans. Softw. Eng. Methodol. 2026, 35, 1–26.

  • 87.

    Quynh Nhu, N.D.; Minh Quan, L.; Van, T.H.; et al. RAG-SmartVuln: Enhancing Smart Contract Vulnerability Detection via Retrieval-ugmented LLMs. In Proceedings of the 2025 International Conference on Multimedia Analysis and Pattern Recognition (MAPR), Nha Trang, Vietnam, 14–15 August 2025; pp. 1–6.https://doi.org/10.1109/mapr67746.2025.11134018.

  • 88.

    Chen, Y. AutoReview: An LLM-Based Multi-Agent System for Security Issue-Oriented Code Review. In Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering, Trondheim, Norway, 23–27 June 2025; pp. 1022–1024. https://doi.org/10.1145/3696630.3728618.

  • 89.

    Widyasari, R.; Weyssow, M.; Irsan, I.C.; et al. Let the Trial Begin: A Mock-Court Approach to Vulnerability Detection Using LLM-Based Agents. arXiv 2025, arXiv:2505.10961.

  • 90.

    Jie, W.; Qiu, W.; Yang, H.; et al. Agent4Vul: Multimodal LLM Agents for Smart Contract Vulnerability Detection. Sci. China Inf. Sci. 2025, 68, 160101. https://doi.org/10.1007/s11432-024-4402-2.

  • 91.

    Ghaleb, A.; Pattabiraman, K. How Effective Are Smart Contract Analysis Tools? Evaluating Smart Contract Static Analysis Tools Using Bug Injection. In Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis, Online, 18–22 July 2020; pp. 415–427. https://doi.org/10.1145/3395363.3397385.

  • 92.

    Hu, S.; Huang, T.; ˙Ilhan, F.; et al. Large Language Model-Powered Smart Contract Vulnerability Detection: New Perspectives. In Proceedings of the 2023 5th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-SA), Atlanta, GA, USA, 1–4 November 2023; pp. 297–306. https://doi.org/10.1109/tpsisa58951.2023.00044.

  • 93.

    Liu, H.; Einstein, L.; Yang, J.; et al. SecureForge: Finding and Preventing Vulnerabilities in LLM-Generated Code via Prompt Optimization. arXiv 2026, arXiv:2605.08382.

  • 94.

    Baumann, J.; Padmakumar, V.; Li, X.; et al. SWE-Chat: Coding Agent Interactions from Real Users in the Wild. arXiv 2026, arXiv:2604.20779.

  • 95.

    Li, X.; Su, Y.; Liu, J.; et al. VULSOLVER: Vulnerability Detection via LLM-Driven Constraint Solving. arXiv 2025, arXiv:2509.00882.

  • 96.

    OWASP Foundation. OWASP Benchmark Project. Available online: https://owasp.org/www-project-benchmark/ (accessed on 2 July 2026).

  • 97.

    Sun, Y.; Wu, D.; Xue, Y.; et al. GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program Analysis. In Proceedings of the IEEE/ACM 46th International Conference on Software Engineering, Lisbon, Portugal, 14–20 April 2024; pp. 1–13. https://doi.org/10.1145/3597503.3639117.

  • 98.

    Yi, X.; Fang, Y.; Wu, D.; et al. BlockScope: Detecting and Investigating Propagated Vulnerabilities in Forked Blockchain Projects. arXiv 2022, arXiv:2208.00205.

  • 99.

    Zhang, Z.; Zhang, B.; Xu, W.; et al. Demystifying Exploitable Bugs in Smart Contracts. In Proceedings of the 2023 IEEE/ACM 45th International Conference on Software Engineering, Melbourne, VIC, Australia, 14–20 May 2023; pp. 615–627. https://doi.org/10.1109/icse48619.2023.00061.

  • 100.

    Jiang, J.; Xiong, Y.; Zhang, H.; et al. Shaping Program Repair Space with Existing Patches and Similar Code. In Proceedings of the 27th ACM SIGSOFT International Symposium on Software Testing and Analysis, Amsterdam, The Netherlands, 16–21 July 2018; pp. 298–309. https://doi.org/10.1145/3213846.3213871.

  • 101.

    Liu, K.; Koyuncu, A.; Kim, D.; et al. TBar: Revisiting Template-Based Automated Program Repair. In Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, Beijing, China, 15–19 July 2019; pp. 31–42. https://doi.org/10.1145/3293882.3330577.

  • 102.

    Koyuncu, A.; Liu, K.; Bissyand´e, T.F.; et al. FixMiner: Mining Relevant Fix Patterns for Automated Program Repair. Empir. Softw. Eng. 2020, 25, 1980–2024. https://doi.org/10.1007/s10664-019-09780-z.

  • 103.

    Wei, Y.; Bo, L.; Wu, X.; et al. VulRep: Vulnerability Repair Based on Inducing Commits and Fixing Commits. EURASIP J. Wirel. Commun. Netw. 2023, 2023, 34. https://doi.org/10.1186/s13638-023-02242-7.

  • 104.

    Dinella, E.; Dai, H.; Li, Z.; et al. Hoppity: Learning Graph Transformations to Detect and Fix Bugs in Programs. In Proceedings of the International Conference on Learning Representations, Online, 26–30 April 2020.

  • 105.

    Zhu, Q.; Sun, Z.; Xiao, Y.A.; et al. A Syntax-Guided Edit Decoder for Neural Program Repair. In Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Online, 23–28 August 2021; pp. 341–353.

  • 106.

    Wang, R.; Li, Z.; Gao, C.; et al. SPVR: Syntax-to-Prompt Vulnerability Repair Based on Large Language Models. Autom. Softw. Eng. 2026, 33, 38. https://doi.org/10.1007/s10515-025-00579-5.

  • 107.

    Chi, J.; Qu, Y.; Liu, T.; et al. Seqtrans: Automatic Vulnerability Fix via Sequence to Sequence Learning. IEEE Trans. Softw. Eng. 2023, 49, 564–585.

  • 108.

    Chen, Z.; Kommrusch, S.; Tufano, M.; et al. Sequencer: Sequence-to-Sequence Learning for End-to-End Program Repair. IEEE Trans. Softw. Eng. 2021, 47, 1943–1959.

  • 109.

    Lutellier, T.; Pham, H.V.; Pang, L.; et al. CoCoNuT: Combining Context-Aware Neural Translation Models Using Ensemble for Program Repair. In Proceedings of the 29th ACM SIGSOFT International Symposium on Software Testing and Analysis, Online, 18–22 July 2020; pp. 101–114. https://doi.org/10.1145/3395363.3397369.

  • 110.

    Chen, Z.; Kommrusch, S.; Monperrus, M. Neural Transfer Learning for Repairing Security Vulnerabilities in C Code. IEEE Trans. Softw. Eng. 2023, 49, 147–165.

  • 111.

    Fu, M.; Tantithamthavorn, C.; Le, T.; et al. Vulrepair: A T5-Based Automated Software Vulnerability Repair. In Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Singapore, 14–18 November 2022; pp. 935–947. https://doi.org/10.1145/3540250.3549098.

  • 112.

    Zhou, X.; Kim, K.; Xu, B.; et al. Out of Sight, out of Mind: Better Automatic Vulnerability Repair by Broadening Input Ranges and Sources. In Proceedings of the IEEE/ACM 46th International Conference on Software Engineering, Lisbon, Portugal, 14–20 April 2024; pp. 1071–1083. https://doi.org/10.1145/3597503.3639222.

  • 113.

    Wang, C.; Zhang, J.; Gao, J.; et al. ContractTinker: Llm-Empowered Vulnerability Repair for Real-World Smart Contracts. In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, Sacramento, CA, USA, 27 October–1 November 2024; pp. 2350–2353. https://doi.org/10.1145/3691620.3695349.

  • 114.

    Xia, C.S.; Wei, Y.; Zhang, L. Practical Program Repair in the Era of Large Pre-Trained Language Models. arXiv 2022, arXiv:2210.14179.

  • 115.

    Xia, C.S.; Zhang, L. Automated Program Repair via Conversation: Fixing 162 out of 337 Bugs for $0.42 Each Using ChatGPT. In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, Vienna, Austria, 16–20 September 2024; pp. 819–831. https://doi.org/10.1145/3650212.3680323.

  • 116.

    Wang, W.; Wang, Y.; Joty, S.; et al. Rap-Gen: Retrieval-Augmented Patch Generation with CodeT5 for Automatic Program Repair. In Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, San Francisco, CA, USA, 3–9 December 2023; pp. 146–158. https://doi.org/10.1145/3611643.3616256.

  • 117.

    Jin, M.; Shahriar, S.; Tufano, M.; et al. InferFix: End-to-End Program Repair with LLMs. In Proceedings of the ESEC/FSE’23: 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, San Francisco, CA, USA, 3–9 December 2023; pp. 1646–1656. https://doi.org/10.1145/3611643.3613892.

  • 118.

    Liu, Z.; Ma, Y.; Xu, J.; et al. Agent that Debugs: Dynamic State-Guided Vulnerability Repair. arXiv 2025, arXiv:2504.07634.

  • 119.

    Juliet C/C++ 1.3 Test Suite (SARD Test Suite #112). Available online: https://samate.nist.gov/SARD/test-suites/112 (accessed on 26 May 2026).

  • 120.

    Fan, J.; Li, Y.; Wang, S.; et al. A C/C++ Code Vulnerability Dataset with Code Changes and CVE Summaries. In Proceedings of the 17th International Conference on Mining Software Repositories, Seoul, Korea, 29–30 June 2020; pp. 508–512. https://doi.org/10.1145/3379597.3387501.

  • 121.

    Bhandari, G.; Naseer, A.; Moonen, L. CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software. In Proceedings of the 17th International Conference on Predictive Models and Data Analytics in Software Engineering, Online, 19–20 August 2021; pp. 30–39. https://doi.org/10.1145/3475960.3475985.

  • 122.

    Wang, X.; Hu, R.; Gao, C.; et al. ReposVul: A Repository-Level High-Quality Vulnerability Dataset. In Proceedings of the 2024 IEEE/ACM 46th International Conference on Software Engineering: Companion Proceedings, Lisbon, Portugal, 14–20 April 2024; pp. 472–483. https://doi.org/10.1145/3639478.3647634.

  • 123.

    Nikitopoulos, G.; Dritsa, K.; Louridas, P.; et al. CrossVul: A Cross-Language Vulnerability Dataset with Commit Data. In Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, Online, 23–27 August 2021; pp. 1565–1569. https://doi.org/10.1145/3468264.3473122.

  • 124.

    Li, Y.; Zhang, T.; Widyasari, R.; et al. CleanVul: Automatic Function-Level Vulnerability Detection in Code Commits Using LLM Heuristics. arXiv 2024, arXiv:2411.17274.

  • 125.

    Russell, R.; Kim, L.; Hamilton, L.; et al. Automated Vulnerability Detection in Source Code Using Deep Representation Learning. In Proceedings of the 2018 17th IEEE International Conference on Machine Learning and Applications (ICMLA), Orlando, FL, USA, 17–20 December 2018; pp. 757–762. https://doi.org/10.1109/icmla.2018.00120.

  • 126.

    Li, Z.; Zou, D.; Xu, S.; et al. VulDeePecker: A Deep Learning-Based System for Vulnerability Detection. arXiv 2018, arXiv:1801.01681.

  • 127.

    Ferreira, J.F.; Cruz, P.; Durieux, T.; et al. SmartBugs: A Framework to Analyze Solidity Smart Contracts. In Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering, Online, 21–25 September 2020; pp. 1349–1352. https://doi.org/10.1145/3324884.3415298.

  • 128.

    Li, Z.; Zou, D.; Xu, S.; et al. Sysevr: A Framework for Using Deep Learning to Detect Software Vulnerabilities. IEEE Trans. Dependable Secur. Comput. 2022, 19, 2244–2258. https://doi.org/10.1109/tdsc.2021.3051525.

  • 129.

    Li, Z.; Zou, D.; Xu, S.; et al. VulDeeLocator: A Deep Learning-Based Fine-Grained Vulnerability Detector. IEEE Trans. Dependable Secur. Comput. 2022, 19, 2821–2837. https://doi.org/10.1109/tdsc.2021.3076142.

  • 130.

    Chen, Y.; Ding, Z.; Alowain, L.; et al. Diversevul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, Hong Kong, China, 16–18 October 2023; pp. 654–668. https://doi.org/10.1145/3607199.3607242.

  • 131.

    Ni, C.; Shen, L.; Yang, X.; et al. MegaVul: A C/C++ Vulnerability Dataset with Comprehensive Code Representations. In Proceedings of the 21st International Conference on Mining Software Repositories, Lisbon, Portugal, 15–16 April 2024; pp. 738–742. https://doi.org/10.1145/3643991.3644886.

  • 132.

    Ding, Y.; Fu, Y.; Ibrahim, O.; et al. Vulnerability Detection with Code Language Models: How Far Are We? arXiv 2024, arXiv:2403.18624.

  • 133.

    Lu, C.; Li, T.; Dehaene, T.; et al. ICVul: A Well-Labeled C/C++ Vulnerability Dataset with Comprehensive Metadata and VCCS. In Proceedings of the 2025 IEEE/ACM 22nd International Conference on Mining Software Repositories (MSR), Ottawa, ON, Canada, 28–29 April 2025; pp. 154–158. https://doi.org/10.1109/msr66628.2025.00034.

  • 134.

    Li, Z.; Dutta, S.; Naik, M. IRIS: LLM-Assisted Static Analysis for Detecting Security Vulnerabilities. In Proceedings of the International Conference on Learning Representations, Singapore, 24–28 April 2025; pp. 35735–35758.

  • 135.

    Joern—The Bug Hunter’s Workbench. Available online: https://joern.io/ (accessed on 1 June 2026).

  • 136.

    CodeQL. Available online: https://codeql.github.com/ (accessed on 1 June 2026).

  • 137.

    Tree-Sitter. Available online: https://tree-sitter.github.io/tree-sitter/ (accessed on 1 June 2026).

  • 138.

    ANTLR: ANother Tool for Language Recognition. Available online: https://www.antlr.org/ (accessed on 1 June 2026).

  • 139.

    The LLVM Compiler Infrastructure. Available online: https://llvm.org/ (accessed on 1 June 2026).

  • 140.

    Frama-C: Framework for Modular Analysis of C Programs. Available online: https://frama-c.com/ (accessed on 1 June 2026).

  • 141.

    Available online: https://wala.github.io/ (accessed on 1 June 2026).

  • 142.

    Soot—A Framework for Analyzing and Transforming Java and Android Applications. Available online: https://sootoss.github.io/soot/ (accessed on 1 June 2026).

  • 143.

    Feist, J.; Grieco, G.; Groce, A. Slither: A Static Analysis Framework for Smart Contracts. In Proceedings of the 2019 IEEE/ACM 2nd International Workshop on Emerging Trends in Software Engineering for Blockchain (WETSEB), Montreal, QC, Canada, 27 May 2019; pp. 8–15. https://doi.org/10.1109/wetseb.2019.00008.

  • 144.

    Paszke, A.; Gross, S.; Massa, F.; et al. PyTorch: An Imperative Style, High-Performance Deep Learning Library. In Proceedings of the Advances in Neural Information Processing Systems, Vancouver, BC, Canada, 8–14 December 2019.

  • 145.

    Fey, M.; Lenssen, J.E. Fast Graph Representation Learning with PyTorch Geometric. arXiv 2019, arXiv:1903.02428.

  • 146.

    Wang, M.; Zheng, D.; Ye, Z.; et al. Deep Graph Library: A Graph-Centric, Highly-Performant Package for Graph Neural Networks. arXiv 2019, arXiv:1909.01315.

  • 147.

    Hagberg, A.; Swart, P.J.; Schult, D.A. et al. Exploring Network Structure, Dynamics, and Function Using NetworkX. In Proceedings of the 7th Python in Science Conference (SciPy 2008), Pasadena, CA, USA, August 19–24, 2008 ; pp. 11–15.

  • 148.

    Hu, J.; Qian, S.; Fang, Q.; et al. Efficient Graph Deep Learning in Tensorflow with tf geometric. In Proceedings of the 29th ACM International Conference on Multimedia, Chengdu, China, 20–24 October 2021; pp. 3775–3778. https://doi.org/10.1145/3474085.3478322.

  • 149.

    Ma, Y.; Yu, D.; Wu, T.; et al. PaddlePaddle: An Open-Source Deep Learning Platform from Industrial Practice. Front. Data Comput. 2019, 1, 105–115. https://doi.org/10.11871/jfdc.issn.2096.742x.2019.01.011.

  • 150.

    Cen, Y.; Hou, Z.;Wang, Y.; et al. CogDL: A Comprehensive Library for Graph Deep Learning. In Proceedings of the ACM Web Conference 2023, Austin, TX, USA, 30 April–4 May 2023; pp. 747–758. https://doi.org/10.1145/3543507.3583472.

  • 151.

    Liu, M.; Luo, Y.; Wang, L.; et al. DIG: A Turnkey Library for Diving into Graph Deep Learning Research. J. Mach. Learn. Res. 2021, 22, 1–9.

  • 152.

    Yang, H. AliGraph: A Comprehensive Graph Neural Network Platform. In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, Anchorage, AK, USA, 4–8 August 2019; pp. 3165–3166. https://doi.org/10.1145/3292500.3340404.

  • 153.

    Euler: A Distributed Graph Deep Learning Framework. Available online: https://github.com/alibaba/euler (accessed on 6 June 2026).

  • 154.

    Jia, Z.; Lin, S.; Gao, M.; et al. Improving the Accuracy, Scalability, and Performance of Graph Neural Networks with Roc. Proc. Mach. Learn. Syst. 2020, 2, 187–198.

  • 155.

    Fan,W.; He, T.; Lai, L.; et al. GraphScope. Proc. VLDB Endow. 2021, 14, 2879–2892. https://doi.org/10.14778/3476311.3476369.

  • 156.

    Pan, Z.; Wu, T.; Zhao, Q.; et al. GeaFlow: A Graph Extended and Accelerated Dataflow System. Proc. ACM Manag. Data 2023, 1, 1–27. https://doi.org/10.1145/3589771.

  • 157.

    Fender, A.; Rees, B.; Eaton, J. RAPIDS cuGraph. In Massive Graph Analytics; Chapman and Hall/CRC: Boca Raton, FL, USA, 2022; pp. 483–493. https://doi.org/10.1201/9781003033707-22.

  • 158.

    Zhu, Z.; Xu, S.; Tang, J.; et al. GraphVite: A High-Performance CPU-GPU Hybrid System for Node Embedding. In Proceedings of the WWW’19: The Web Conference, San Francisco, CA, USA, 13–17 May 2019; pp. 2494–2504. https://doi.org/10.1145/3308558.3313508.

  • 159.

    Wolf, T.; Debut, L.; Sanh, V.; et al. Transformers: State-of-the-Art Natural Language Processing. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing: System Demonstrations, Online, 16–20 November 2020; pp. 38–45. https://doi.org/10.18653/v1/2020.emnlp-demos.6.

  • 160.

    Pfeiffer, J.; Ruckle, A.; Poth, C.; et al. Adapterhub: A Framework for Adapting Transformers. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing: System Demonstrations, Online, 16–20 November 2020; pp. 46–54. https://doi.org/10.18653/v1/2020.emnlp-demos.7.

  • 161.

    Gugger, S.; Debut, L.; Wolf, T.; et al. Accelerate: Training and Inference at Scale Made Simple, Efficient and Adaptable. Available online: https://github.com/huggingface/accelerate (accessed on 2 July 2026).

  • 162.

    Ott, M.; Edunov, S.; Baevski, A.; et al. Fairseq: A Fast, Extensible Toolkit for Sequence Modeling. In Proceedings of the NAACL-HLT 2019: Demonstrations, Minneapolis, MN, USA, 2–7 June 2019. https://doi.org/10.18653/v1/n19-4009.

  • 163.

    Klein, G.; Kim, Y.; Deng, Y.; et al. OpenNMT: Open-Source Toolkit for Neural Machine Translation. In Proceedings of the ACL 2017, System Demonstrations, Vancouver, BC, Canada, 30 July–4 August 2017; pp. 67–72. https://doi.org/10.18653/v1/p17-4012.

  • 164.

    Vaswani, A.; Bengio, S.; Brevdo, E.; et al. Tensor2Tensor for Neural Machine Translation. In Proceedings of the 13th Conference of the Association for Machine Translation in the Americas (Volume 1: Research Track), Boston, MA, USA, 17–21 March 2018; pp. 193–199.

  • 165.

    Junczys-Dowmunt, M.; Grundkiewicz, R.; Dwojak, T.; et al. Marian: Fast Neural Machine Translation in C++. In Proceedings of the ACL 2018, System Demonstrations, Melbourne, Australia, 15–20 July 2018; pp. 116–121. https://doi.org/10.18653/v1/p18-4020.

  • 166.

    Hieber, F.; Denkowski, M.; Domhan, T.; et al. Sockeye 3: Fast Neural Machine Translation with PyTorch. arXiv 2022, arXiv:2207.05851.

  • 167.

    Shoeybi, M.; Patwary, M.; Puri, R.; et al. Megatron-LM: Training Multi-Billion Parameter Language Models Using Model Parallelism. arXiv 2019, arXiv:1909.08053.

  • 168.

    Rasley, J.; Rajbhandari, S.; Ruwase, O.; et al. Deepspeed: System Optimizations Enable Training Deep Learning Models with over 100 Billion Parameters. In Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, Virtual Event, CA, USA, 23–27 August 2020; pp. 3505–3506. https://doi.org/10.1145/3394486.3406703.

  • 169.

    Li, S.; Liu, H.; Bian, Z.; et al. Colossal-Ai: A Unified Deep Learning System for Large-Scale Parallel Training. In Proceedings of the 52nd International Conference on Parallel Processing, Salt Lake City, UT, USA, 7–10 August 2023; pp. 766–775. https://doi.org/10.1145/3605573.3605613.

  • 170.

    Kwon,W.; Li, Z.; Zhuang, S.; et al. Efficient Memory Management for Large Language Model Serving with PagedAttention. In Proceedings of the 29th ACM Symposium on Operating Systems Principles, Koblenz, Germany, 23–26 October 2023; pp. 611–626. https://doi.org/10.1145/3600006.3613165.

  • 171.

    Zheng, L.; Yin, L.; Xie, Z.; et al. SGLang: Efficient Execution of Structured Language Model Programs. Adv. Neural Inf. Process. Syst. 2024, 37, 62557–62583. https://doi.org/10.52202/079017-2000.

  • 172.

    Aminabadi, R.Y.; Rajbhandari, S.; Awan, A.A.; et al. Deepspeed-Inference: Enabling Efficient Inference of Transformer Models at Unprecedented Scale. In Proceedings of the SC22: International Conference for High Performance Computing, Networking, Storage and Analysis, Dallas, TX, USA, 13–18 November 2022; pp. 1–15. https://doi.org/10.1109/sc41404.2022.00051.

  • 173.

    Agrawal, A.; Kedia, N.; Panwar, A.; et al. Taming Throughput-Latency Tradeoff in LLM Inference with Sarathi-Serve. In Proceedings of the 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24), Santa Clara, CA, USA, 10–12 July 2024; pp. 117–134.

  • 174.

    Ruan, C.F.; Qin, Y.; Parthasarathy, A.R.; et al. WebLLM: A High-Performance in-Browser LLM Inference Engine. arXiv 2024, arXiv:2412.15803.

  • 175.

    Zheng, L.; Chiang, W.L.; Sheng, Y.; et al. Judging Llm-as-a-Judge with Mt-Bench and Chatbot Arena. Adv. Neural Inf. Process. Syst. 2023, 36, 46595–46623. https://doi.org/10.52202/075280-2020.

  • 176.

    The Open Agent Engineering Ecosystem. Available online: https://docs.langchain.com/ (accessed on 4 June 2026).

  • 177.

    Welcome to LlamaIndex.Available online: https://docs.llamaindex.ai/ (accessed on 4 June 2026).

  • 178.

    Open-Source AI Orchestration forProduction-Grade Agents.Available online: https://haystack.deepset.ai/ (accessed on 4 June 2026).

  • 179.

    Khattab, O.; Singhvi, A.; Maheshwari, P.; et al. DSPy: Compiling Declarative Language Model Calls into Self-Improving Pipelines. arXiv 2023, arXiv:2310.03714.

  • 180.

    Build a Superior Context Layer for AI Agents. Available online: https://ragflow.io/ (accessed on 4 June 2026).

  • 181.

    Wang, J.; Yi, X.; Guo, R.; et al. Milvus: A Purpose-Built Vector Data Management System. In Proceedings of the 2021 International Conference on Management of Data, Online, 20–25 June 2021; pp. 2614–2627. https://doi.org/10.1145/3448016.3457550.

  • 182.

    Edge, D.; Trinh, H.; Cheng, N.; et al. From Local to Global: A Graph RAG Approach to Query-Focused Summarization. arXiv 2024, arXiv:2404.16130.

  • 183.

    Guo, Z.; Xia, L.; Yu, Y.; et al. LightRAG: Simple and Fast Retrieval-Augmented Generation. arXiv 2024, arXiv:2410.05779.

  • 184.

    Es, S.; James, J.; Espinosa Anke, L.; et al. Ragas: Automated Evaluation of Retrieval Augmented Generation. In Proceedings of the 18th Conference of the European Chapter of the Association for Computational Linguistics: System Demonstrations, St. Julians, Malta, 21–22 March 2024; pp. 150–158. https://doi.org/10.18653/v1/2024.eacl-demo.16.

  • 185.

    Ru, D.; Qiu, L.; Hu, X.; et al. RAGChecker: A Fine-Grained Framework for Diagnosing Retrieval-Augmented Generation. Adv. Neural Inf. Process. Syst. 2024, 37, 21999–22027. https://doi.org/10.52202/079017-0692.

  • 186.

    Guo, Y.; Bettaieb, S.; Casino, F. A Comprehensive Analysis on Software Vulnerability Detection Datasets: Trends, Challenges, and Road Ahead. Int. J. Inf. Secur. 2024, 23, 3311–3327. https://doi.org/10.1007/s10207-024-00888-y.

  • 187.

    Perry, N.; Srivastava, M.; Kumar, D.; et al. Do Users Write More Insecure Code with Ai Assistants? In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Copenhagen, Denmark, 26–30 November 2023; pp. 2785–2799. https://doi.org/10.1145/3576915.3623157.

  • 188.

    Pearce, H.; Ahmad, B.; Tan, B.; et al. Asleep at the Keyboard? Assessing the Security of Github Copilot’s Code Contributions. Commun. ACM 2025, 68, 96–105. https://doi.org/10.1145/3610721.

Share this article:
How to Cite
Yu, T.; Wang, J.; Li, M.; Hu, Y.; Hu, J.; Cai, X.; Hu, W.; Borgi, A. Program Graph Learning for Software Vulnerability Analysis: A Survey. Transactions on Graph Intelligence and Network Applications 2026.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.