Abstract
A persistent challenge in software vulnerability detection is the failure of many existing approaches to handle highly imbalanced datasets reliably. In practical vulnerability datasets, vulnerable functions usually account for only a small proportion of all samples, which makes model evaluation highly sensitive to feature representation, threshold selection, and class distribution. To address this issue, this study proposes a lightweight feature-based detection pipeline for function-level vulnerability detection. The implemented method combines TF-IDF lexical features with numerical code-statistical features and evaluates several conventional machine-learning classifiers under a unified experimental protocol. PrimeVul is used as the primary dataset, while DiverseVul is introduced for external cross-dataset validation. The experiments include baseline comparison, feature ablation, threshold selection, sensitivity analysis, random-seed stability testing, imbalance-handling evaluation, and cross-dataset assessment. The results show that the proposed feature-based pipeline achieves stable performance under highly imbalanced settings. On the PrimeVul test set, the best configuration achieves an accuracy of approximately 0.9697, an F1-score in the range of 0.26–0.27, and a ROC-AUC above 0.83. The external evaluation on DiverseVul further indicates that the learned feature representation retains a certain degree of cross-dataset generalization. These findings suggest that carefully designed lightweight feature representations, combined with systematic multi-metric evaluation, can provide a reproducible and interpretable baseline for practical software vulnerability detection.
References
Li, Z., Zou, D., Xu, S., Jin, H., Zhu, Y., and Chen, Z. “SySeVR: A Framework for Using Deep Learning to Detect Software Vulnerabilities,” IEEE Transactions on Dependable and Secure Computing, vol. 19, no. 4, pp. 2244–2258, 2022.
Zou, D., Wang, S., Xu, S., Li, Z., and Jin, H. “μVulDeePecker: A Deep Learning-Based System for Multiclass Vulnerability Detection,” IEEE Transactions on Dependable and Secure Computing, vol. 18, no. 5, pp. 2224–2236, 2021.
Zhou, Y., Liu, S., Siow, J., Du, X., and Liu, Y. “Devign: Effective Vulnerability Identification by Learning Comprehensive Program Semantics via Graph Neural Networks,” Advances in Neural Information Processing Systems, vol. 32, 2019.
Cheng, X., Wang, H., Hua, J., Xu, G., and Sui, Y. “DeepWukong: Statically Detecting Software Vulnerabilities Using Deep Graph Neural Network,” ACM Transactions on Software Engineering and Methodology, vol. 30, no. 3, article 33, 2021.
Nguyen, V.-A., Nguyen, D. Q., Nguyen, V., Le, T., Tran, Q. H., and Phung, D. “ReGVD: Revisiting Graph Neural Networks for Vulnerability Detection,” in Proceedings of the 2022 ACM/IEEE 44th International Conference on Software Engineering: Companion Proceedings, pp. 178–182, 2022.
Chen, Y., Ding, Z., Alowain, L., Chen, X., and Wagner, D. “DiverseVul: A New Vulnerable Source Code Dataset for Deep Learning Based Vulnerability Detection,” in Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, pp. 654–668, 2023.
Ding, Y., Fu, Y., Ibrahim, O., Sitawarin, C., Chen, X., Alomair, B., Wagner, D., Ray, B., and Chen, Y. “Vulnerability Detection with Code Language Models: How Far Are We?” in Proceedings of the IEEE/ACM 47th International Conference on Software Engineering, pp. 1729–1741, 2025.
Fu, M., and Tantithamthavorn, C. “LineVul: A Transformer-based Line-Level Vulnerability Prediction,” in Proceedings of the 2022 Mining Software Repositories Conference, pp. 608–620, 2022.
Li, Y., Wang, S., and Nguyen, T. N. “Vulnerability Detection with Fine-Grained Interpretations,” in Proceedings of the 29th ACM Joint Meeting European Software Engineering Conference and Symposium on the Foundations of Software Engineering, pp. 292–303, 2021.
Steenhoek, B., Gao, H., and Le, W. “Dataflow Analysis-Inspired Deep Learning for Efficient Vulnerability Detection,” in Proceedings of the 46th IEEE/ACM International Conference on Software Engineering, 2024.
Hanif, H., and Maffeis, S. “VulBERTa: Simplified Source Code Pre-Training for Vulnerability Detection,” in Proceedings of the 2022 International Joint Conference on Neural Networks, pp. 1–8, 2022.
Kim, S., Choi, J., Ahmed, M. E., Nepal, S., and Kim, H. “VulDeBERT: A Vulnerability Detection System Using BERT,” in Proceedings of the 2022 IEEE International Symposium on Software Reliability Engineering Workshops, pp. 69–74, 2022.
Cheng, X., Zhang, G., Wang, H., and Sui, Y. “Path-sensitive Code Embedding via Contrastive Learning for Software Vulnerability Detection,” in Proceedings of the 31st ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 519–531, 2022
Wang, R., Xu, S., Tian, Y., Ji, X., Sun, X., Zhu, D., and Jiang, S. “SCL-CVD: Supervised Contrastive Learning for Code Vulnerability Detection via GraphCodeBERT,” Computers & Security, vol. 145, pp. 103994, 2024.
Tang, W., Tang, M., Ban, M., Zhao, Z., and Feng, M. “CSGVD: A Deep Learning Approach Combining Sequence and Graph Embedding for Source Code Vulnerability Detection,” Journal of Systems and Software, vol. 199, pp. 111623, 2023.
Guo, W., Fang, Y., Huang, C., Ou, H., Lin, C., and Guo, Y. “HyVulDect: A Hybrid Semantic Vulnerability Mining System Based on Graph Neural Network,” Computers & Security, vol. 121, pp. 102823, 2022.
Wang, J., Xiao, H., Zhong, S., and Xiao, Y. “DeepVulSeeker: A Novel Vulnerability Identification Framework via Code Graph Structure and Pre-Training Mechanism,” Future Generation Computer Systems, vol. 148, pp. 15–26, 2023.
Zhao, Q., Huang, C., and Dai, L. “VULDEFF: Vulnerability Detection Method Based on Function Fingerprints and Code Differences,” Knowledge-Based Systems, vol. 260, pp. 110139, 2023.
Zheng, W., Su, X., Wei, H., and Tao, W. “SVulDetector: Vulnerability Detection Based on Similarity Using Tree-Based Attention and Weighted Graph Embedding Mechanisms,” Computers & Security, vol. 144, pp. 103930, 2024.
Ge, K., and Han, Q.-B. “Hidden Code Vulnerability Detection: A Study of the Graph-BiLSTM Algorithm,” Information and Software Technology, vol. 175, p. 107544, 2024.
Xu, C. D., Luong, T. T., and Thanh, M. C. “Optimising Source Code Vulnerability Detection Using Deep Learning and Deep Graph Network,” Connection Science, vol. 37, no. 1, article 2447373, 2025.
Jin, D., He, C., Zou, Q., Qin, Y., and Wang, B. “Source Code Vulnerability Detection Based on Joint Graph and Multimodal Feature Fusion,” Electronics, vol. 14, no. 5, pp. 975, 2025.
Zou, Z., Jiang, T., Wang, Y., Xue, T., Zhang, N., and Luan, J. “Code Vulnerability Detection Based on Augmented Program Dependency Graph and Optimized CodeBERT,” Scientific Reports, vol. 15, article 39301, 2025.
Guo, Y., Bettaieb, S., and Casino, F. “A Comprehensive Analysis on Software Vulnerability Detection Datasets: Trends, Challenges, and Road Ahead,” International Journal of Information Security, vol. 23, pp. 3311–3327, 2024.
Chen, L., Wei, Q., Du, J., Wang, Y., and Jiang, Z. “Survey of Source Code Vulnerability Analysis Based on Deep Learning,” Computers & Security, vol. 148, pp. 104098, 2025.
Anand, A., Bhatt, N., Kaur, J., and Tamura, Y. “Time Lag-Based Modelling for Software Vulnerability Exploitation Process,” Journal of Cyber Security and Mobility, vol. 10, no. 4, pp. 663–678, 2021.
Somesha, M., and Pais, A. R. “Classification of Phishing Email Using Word Embedding and Machine Learning Techniques,” Journal of Cyber Security and Mobility, vol. 11, no. 3, pp. 279–320, 2022.
Doynikova, E., Fedorchenko, A., and Kotenko, I. “A Semantic Model for Security Evaluation of Information Systems,” Journal of Cyber Security and Mobility, vol. 9, no. 2, pp. 301–330, 2020.
Kotenko, I., and Chechulin, A. “Fast Network Attack Modeling and Security Evaluation based on Attack Graphs,” Journal of Cyber Security and Mobility, vol. 3, no. 1, pp. 27–46, 2014.
Suárez, G. P., Gallos, L. K., and Fefferman, N. H. “A Case Study in Tailoring a Bio-Inspired Cyber-Security Algorithm: Designing Anomaly Detection for Multilayer Networks,” Journal of Cyber Security and Mobility, vol. 8, no. 1, pp. 113–132, 2018.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Copyright (c) 2026 Journal of Cyber Security and Mobility
